Skip to content

Commit 380d724

Browse files
Sync Collecting Fix Commits: Fri May 22 21:05:44 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent a647155 commit 380d724

3 files changed

Lines changed: 76 additions & 28 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 60 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,57 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-8GW3-RXH4-V6JX": {
5+
"2c4e7ac2ff804151a5103a960372da225bac0cdd": "Improve GHSA-8gw3-rxh4-v6jx",
6+
"fc0a4eb031620c7823aaf0ce6249b5ee33ded9e7": "Publish GHSA-8gw3-rxh4-v6jx"
7+
},
8+
"GHSA-45VW-WH46-2VX8": {
9+
"e9a7260ef64bc2c60d8154aae4eb007d2df7d5e0": "Improve GHSA-45vw-wh46-2vx8"
10+
},
11+
"GHSA-97R5-PG8X-P63P": {
12+
"c46bcf61f9d19576a81e7bc7b30d1615109eae29": "Publish GHSA-97r5-pg8x-p63p"
13+
},
14+
"GHSA-7M8F-HGJQ-8GC9": {
15+
"3e8c53cab1404c642d3ffbace55362eba7c3460e": "Publish Advisories\n\nGHSA-7m8f-hgjq-8gc9\nGHSA-q8mj-m7cp-5q26\nGHSA-qqqm-5547-774x"
16+
},
17+
"GHSA-Q8MJ-M7CP-5Q26": {
18+
"3e8c53cab1404c642d3ffbace55362eba7c3460e": "Publish Advisories\n\nGHSA-7m8f-hgjq-8gc9\nGHSA-q8mj-m7cp-5q26\nGHSA-qqqm-5547-774x"
19+
},
20+
"GHSA-QQQM-5547-774X": {
21+
"3e8c53cab1404c642d3ffbace55362eba7c3460e": "Publish Advisories\n\nGHSA-7m8f-hgjq-8gc9\nGHSA-q8mj-m7cp-5q26\nGHSA-qqqm-5547-774x"
22+
},
23+
"GHSA-P93R-85WP-75V3": {
24+
"3f2de86f4ef150374715e71bc2a93b98c26795b0": "Improve GHSA-p93r-85wp-75v3"
25+
},
26+
"GHSA-RMX9-2PP3-XHCR": {
27+
"104646a2efbcb50979fc2c592e51b0c81ed5a717": "Publish GHSA-rmx9-2pp3-xhcr",
28+
"ea04f6a00d4b540a08d9cf07df1824d59f18a0a5": "Merge pull request #7600 from waveywaves/fix-GHSA-rmx9-2pp3-xhcr-multi-branch-patches",
29+
"74b714ba1a7377b8a381c07e772723e7ebcaac3d": "[GHSA-rmx9-2pp3-xhcr] Add multi-branch patch ranges for Tekton Pipelines\n\nVerificationPolicy regex pattern bypass via substring matching (CVE-2026-25542) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-rmx9-2pp3-xhcr",
30+
"66301f90688f679bad9138077a699ee5852aeed8": "Publish GHSA-rmx9-2pp3-xhcr"
31+
},
32+
"GHSA-2F54-V4HM-FX73": {
33+
"dccccff5ee97f223e6166d0b6051fe6d950c57bc": "Publish Advisories\n\nGHSA-2f54-v4hm-fx73\nGHSA-2f54-v4hm-fx73",
34+
"0a2e13bc7275a8017e4cf8c26ca4915d9b6b7c07": "Publish Advisories\n\nGHSA-2f54-v4hm-fx73\nGHSA-5cq6-9f97-wjwx\nGHSA-6275-mpwc-pq3g\nGHSA-8r2w-8p2v-h4g4\nGHSA-r2q3-hjc8-7x6q\nGHSA-x5pc-h62r-4rgx"
35+
},
36+
"GHSA-M2CX-GPQF-QF74": {
37+
"26428264c6c67b2fdaebb1f43ac0009f80f0ccb8": "Publish GHSA-m2cx-gpqf-qf74",
38+
"ed131946f405d5e3c7517f81e5d81400887798ac": "Merge pull request #7599 from waveywaves/fix-GHSA-m2cx-gpqf-qf74-multi-branch-patches",
39+
"7a4bc5f514a245316592d726d5f7c3a37d034468": "[GHSA-m2cx-gpqf-qf74] Add multi-branch patch ranges for Tekton Pipelines\n\nHTTP Resolver Unbounded Response Body Read Enables Denial of Service (CVE-2026-40924) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-m2cx-gpqf-qf74",
40+
"7b976f00ab9ebafbc3ae6e2d31875747708f4c4b": "Publish Advisories\n\nGHSA-m2cx-gpqf-qf74\nGHSA-rx35-6rhx-7858"
41+
},
42+
"GHSA-7G5W-PQ96-8C5W": {
43+
"f33d4a8e510a50d14976db6e434ed6612813ed67": "Improve GHSA-7g5w-pq96-8c5w",
44+
"0a10426772b30d03881d8a4f222c7a2c7d15ca5d": "Publish Advisories\n\nGHSA-7g5w-pq96-8c5w\nGHSA-9f4q-q82q-4359"
45+
},
46+
"GHSA-RX35-6RHX-7858": {
47+
"863de69fa88b40c7044fd5dfd253366ced146d5e": "Publish Advisories\n\nGHSA-rx35-6rhx-7858\nGHSA-jwvv-qr7q-cv8j",
48+
"970befe3453304c8cd630483840a3d2c0395a889": "Merge pull request #7598 from waveywaves/fix-GHSA-rx35-6rhx-7858-multi-branch-patches",
49+
"365aee4f1ae371c92bc4f5d05721a7059a8689c7": "[GHSA-rx35-6rhx-7858] Add multi-branch patch ranges for Tekton Pipelines\n\nVolumeMount path restriction bypass via missing filepath.Clean (CVE-2026-40923) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-rx35-6rhx-7858",
50+
"7b976f00ab9ebafbc3ae6e2d31875747708f4c4b": "Publish Advisories\n\nGHSA-m2cx-gpqf-qf74\nGHSA-rx35-6rhx-7858"
51+
},
52+
"GHSA-JWVV-QR7Q-CV8J": {
53+
"863de69fa88b40c7044fd5dfd253366ced146d5e": "Publish Advisories\n\nGHSA-rx35-6rhx-7858\nGHSA-jwvv-qr7q-cv8j"
54+
},
455
"GHSA-97JF-46M3-8953": {
556
"9f007d9399e2189b0f7b7fff16918f9696f19f2b": "Improve GHSA-97jf-46m3-8953"
657
},
@@ -1825,9 +1876,6 @@
18251876
"GHSA-H2X2-Q2MC-24GW": {
18261877
"5de51d950118d21f7b0076daed40833d60914858": "Publish GHSA-h2x2-q2mc-24gw"
18271878
},
1828-
"GHSA-7G5W-PQ96-8C5W": {
1829-
"0a10426772b30d03881d8a4f222c7a2c7d15ca5d": "Publish Advisories\n\nGHSA-7g5w-pq96-8c5w\nGHSA-9f4q-q82q-4359"
1830-
},
18311879
"GHSA-9F4Q-Q82Q-4359": {
18321880
"0a10426772b30d03881d8a4f222c7a2c7d15ca5d": "Publish Advisories\n\nGHSA-7g5w-pq96-8c5w\nGHSA-9f4q-q82q-4359"
18331881
},
@@ -2237,9 +2285,6 @@
22372285
"54a9b5fd7fcc42ced3758a340ff34669f5ebb0b2": "Publish Advisories\n\nGHSA-j4vj-fpx3-v8rx\nGHSA-4fcc-vrwx-v754\nGHSA-5cq6-9f97-wjwx\nGHSA-r2q3-hjc8-7x6q\nGHSA-wxv8-w48j-r2f4",
22382286
"cb4688f90ef177beaf004338dfde7b13e3354fc4": "Publish Advisories\n\nGHSA-9mrx-mqmg-gwj9\nGHSA-2p5v-p767-wqv5\nGHSA-frh9-7wfp-w73p\nGHSA-cm99-m826-vgg7\nGHSA-j666-j6hj-fpc7\nGHSA-xxmc-fm3p-q3x8\nGHSA-3h63-fx68-x5fm\nGHSA-c33v-7hr2-gw69\nGHSA-fqhc-8hwj-969h\nGHSA-gh28-ww79-7h4v\nGHSA-mx57-4jmx-5cvf\nGHSA-qj4w-p892-c352\nGHSA-r396-2q2c-pjhr\nGHSA-r83p-32gc-q9c8\nGHSA-vv9w-vff6-5rx9\nGHSA-vwxw-q9j2-rh5v\nGHSA-wxv8-w48j-r2f4\nGHSA-x3qr-8f53-fg74"
22392287
},
2240-
"GHSA-2F54-V4HM-FX73": {
2241-
"0a2e13bc7275a8017e4cf8c26ca4915d9b6b7c07": "Publish Advisories\n\nGHSA-2f54-v4hm-fx73\nGHSA-5cq6-9f97-wjwx\nGHSA-6275-mpwc-pq3g\nGHSA-8r2w-8p2v-h4g4\nGHSA-r2q3-hjc8-7x6q\nGHSA-x5pc-h62r-4rgx"
2242-
},
22432288
"GHSA-6275-MPWC-PQ3G": {
22442289
"0a2e13bc7275a8017e4cf8c26ca4915d9b6b7c07": "Publish Advisories\n\nGHSA-2f54-v4hm-fx73\nGHSA-5cq6-9f97-wjwx\nGHSA-6275-mpwc-pq3g\nGHSA-8r2w-8p2v-h4g4\nGHSA-r2q3-hjc8-7x6q\nGHSA-x5pc-h62r-4rgx"
22452290
},
@@ -7653,6 +7698,15 @@
76537698
"GHSA-XX64-WWV2-HCQQ": {
76547699
"2965e7747fb9057d1a4c5eecff93f19ce626e1ce": "Publish Advisories\n\nGHSA-w65c-cmxj-qrhm\nGHSA-fp55-jw48-c537\nGHSA-xx64-wwv2-hcqq"
76557700
},
7701+
"CVE-2026-25542": {
7702+
"74b714ba1a7377b8a381c07e772723e7ebcaac3d": "[GHSA-rmx9-2pp3-xhcr] Add multi-branch patch ranges for Tekton Pipelines\n\nVerificationPolicy regex pattern bypass via substring matching (CVE-2026-25542) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-rmx9-2pp3-xhcr"
7703+
},
7704+
"CVE-2026-40924": {
7705+
"7a4bc5f514a245316592d726d5f7c3a37d034468": "[GHSA-m2cx-gpqf-qf74] Add multi-branch patch ranges for Tekton Pipelines\n\nHTTP Resolver Unbounded Response Body Read Enables Denial of Service (CVE-2026-40924) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-m2cx-gpqf-qf74"
7706+
},
7707+
"CVE-2026-40923": {
7708+
"365aee4f1ae371c92bc4f5d05721a7059a8689c7": "[GHSA-rx35-6rhx-7858] Add multi-branch patch ranges for Tekton Pipelines\n\nVolumeMount path restriction bypass via missing filepath.Clean (CVE-2026-40923) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-rx35-6rhx-7858"
7709+
},
76567710
"CVE-2026-40938": {
76577711
"69d0b01f1bf9ab80640c53fae52703dc075f91d1": "[GHSA-94jr-7pqp-xhcq] Add multi-branch patch ranges for Tekton Pipelines\n\nGit Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE (CVE-2026-40938) was patched across five maintained LTS branches on\nApril 21, 2026, but the OSV entry here collapses the fix into a single\nrange. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)\nare incorrectly flagged as vulnerable by dependency tooling.\n\nUpdated to use one OSV range per branch so each patched version is\nrecognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.\n\nSource: https://github.com/tektoncd/pipeline/security/advisories/GHSA-94jr-7pqp-xhcq"
76587712
},
@@ -8699,12 +8753,6 @@
86998753
"GHSA-VFMQ-68HX-4JFW": {
87008754
"e34b71fc28c153e3f45b5f291e4f4f0e41a1e4ad": "Publish Advisories\n\nGHSA-j687-52p2-xcff\nGHSA-vfmq-68hx-4jfw"
87018755
},
8702-
"GHSA-M2CX-GPQF-QF74": {
8703-
"7b976f00ab9ebafbc3ae6e2d31875747708f4c4b": "Publish Advisories\n\nGHSA-m2cx-gpqf-qf74\nGHSA-rx35-6rhx-7858"
8704-
},
8705-
"GHSA-RX35-6RHX-7858": {
8706-
"7b976f00ab9ebafbc3ae6e2d31875747708f4c4b": "Publish Advisories\n\nGHSA-m2cx-gpqf-qf74\nGHSA-rx35-6rhx-7858"
8707-
},
87088756
"GHSA-3HJV-C53M-58JJ": {
87098757
"b75c23ae2ec6fa2cf398217992ca29c2aa5dbbb1": "Publish GHSA-3hjv-c53m-58jj"
87108758
},
@@ -8756,9 +8804,6 @@
87568804
"GHSA-H6JM-F4HH-FW27": {
87578805
"a1b7bf0a76110a64880325c37ca1d12825ef6587": "Publish Advisories\n\nGHSA-3888-q23f-x7qh\nGHSA-h6jm-f4hh-fw27"
87588806
},
8759-
"GHSA-RMX9-2PP3-XHCR": {
8760-
"66301f90688f679bad9138077a699ee5852aeed8": "Publish GHSA-rmx9-2pp3-xhcr"
8761-
},
87628807
"GHSA-665X-PPC4-685W": {
87638808
"807a46c9148e34e50a88ca2ae8fab2891f4e2605": "Publish Advisories\n\nGHSA-665x-ppc4-685w\nGHSA-xq8m-7c5p-c2r6"
87648809
},
@@ -44208,9 +44253,6 @@
4420844253
"3556e6dd6d1833db8c2ab58e1c635617736ea502": "Publish Advisories\n\nGHSA-5j98-mcp5-4vw2\nGHSA-7xvh-c266-cfr5\nGHSA-fxm2-cmwj-qvx4",
4420944254
"8b8b77c0b429ff43d20ea16b402c37a73279b44e": "Publish Advisories\n\nGHSA-5j98-mcp5-4vw2\nGHSA-fxm2-cmwj-qvx4"
4421044255
},
44211-
"GHSA-8GW3-RXH4-V6JX": {
44212-
"fc0a4eb031620c7823aaf0ce6249b5ee33ded9e7": "Publish GHSA-8gw3-rxh4-v6jx"
44213-
},
4421444256
"GHSA-FF85-QW3H-G9VP": {
4421544257
"97cc88e27917f77be817552fe039204d538569b6": "Publish Advisories\n\nGHSA-ff85-qw3h-g9vp\nGHSA-mqp8-pgg5-7x7m\nGHSA-ff85-qw3h-g9vp\nGHSA-mqp8-pgg5-7x7m",
4421644258
"e9215787b3be86bcec594992e6097e8d6d7bb91a": "Publish Advisories\n\nGHSA-ff85-qw3h-g9vp\nGHSA-j6gg-r5jc-47cm\nGHSA-x3hx-ch7p-8xgg\nGHSA-xpg8-8xpv-948p"

0 commit comments

Comments
 (0)