Skip to content

Commit daaf809

Browse files
Sync Collecting Fix Commits: Wed Jul 29 14:49:18 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent f1d0113 commit daaf809

5 files changed

Lines changed: 164 additions & 20 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,17 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-CRF3-V9RR-V7HJ": {
5+
"0badae8714da8f3fdca36d9d7d234e80500b9bb1": "Improve GHSA-crf3-v9rr-v7hj",
6+
"73e5718a5b647612d0bef1c371c167386ea5a5f9": "Improve GHSA-crf3-v9rr-v7hj",
7+
"e34faa994a969a96da73434c6e96d687fa245753": "Publish Advisories\n\nGHSA-332v-fh8c-j8r7\nGHSA-359c-qmw4-f7gf\nGHSA-48px-72pc-9gfw\nGHSA-683g-rp82-2xcr\nGHSA-6p99-w6f4-qcvq\nGHSA-7h94-344f-429f\nGHSA-8mjr-j93g-6x4q\nGHSA-8p8v-838m-f36p\nGHSA-9vh2-928p-mm63\nGHSA-crf3-v9rr-v7hj\nGHSA-gm4w-wf6f-2ghm\nGHSA-h7w8-vg64-36f2\nGHSA-j58f-rgm2-v2p8\nGHSA-j6qh-f45v-j454\nGHSA-mr6p-pxvc-7864\nGHSA-q3h2-8p56-9cg6\nGHSA-q9pq-xp5c-jmhr\nGHSA-w2pp-vvh7-8jx9\nGHSA-x9fx-2h43-2prm"
8+
},
9+
"GHSA-QWWW-VCR4-C8H2": {
10+
"cd4ee71ce402a4cc78c69988fda1f117c1b64279": "Improve GHSA-qwww-vcr4-c8h2",
11+
"5d6e1e252e6125527d2d29377e6a5c9954dc252f": "Improve GHSA-qwww-vcr4-c8h2",
12+
"4da50480fc88ef6733f73e6cd547ac92f613a0e5": "Improve GHSA-qwww-vcr4-c8h2",
13+
"02ed867ff3261d2dfdd27361617c9d5be6cc80f0": "Publish Advisories\n\nGHSA-464c-974j-9xm6\nGHSA-5xvq-cp9x-6p6r\nGHSA-83w8-p2f5-377r\nGHSA-8pvw-jcv7-9cmj\nGHSA-qwww-vcr4-c8h2\nGHSA-r9mr-m37c-5fr3"
14+
},
415
"GHSA-45WH-RXQ4-JQC6": {
516
"b05e0324543407e660cf54384ff255d20cce8cf4": "Publish Advisories\n\nGHSA-45wh-rxq4-jqc6\nGHSA-5w4j-6h6c-4hr2\nGHSA-8vr5-4pf2-6p73\nGHSA-fcpv-9325-98hg\nGHSA-h334-888w-8prr"
617
},
@@ -17,11 +28,6 @@
1728
"b05e0324543407e660cf54384ff255d20cce8cf4": "Publish Advisories\n\nGHSA-45wh-rxq4-jqc6\nGHSA-5w4j-6h6c-4hr2\nGHSA-8vr5-4pf2-6p73\nGHSA-fcpv-9325-98hg\nGHSA-h334-888w-8prr",
1829
"fa1c2f93b0d15da115c038738e571c1a1553b4cc": "Publish Advisories\n\nGHSA-92r6-r5fj-xg82\nGHSA-h334-888w-8prr\nGHSA-mrjw-v97f-vmwh"
1930
},
20-
"GHSA-QWWW-VCR4-C8H2": {
21-
"5d6e1e252e6125527d2d29377e6a5c9954dc252f": "Improve GHSA-qwww-vcr4-c8h2",
22-
"4da50480fc88ef6733f73e6cd547ac92f613a0e5": "Improve GHSA-qwww-vcr4-c8h2",
23-
"02ed867ff3261d2dfdd27361617c9d5be6cc80f0": "Publish Advisories\n\nGHSA-464c-974j-9xm6\nGHSA-5xvq-cp9x-6p6r\nGHSA-83w8-p2f5-377r\nGHSA-8pvw-jcv7-9cmj\nGHSA-qwww-vcr4-c8h2\nGHSA-r9mr-m37c-5fr3"
24-
},
2531
"GHSA-MH99-V99M-4GVG": {
2632
"67d6b7b99e8288798b446cedf43dbf55884e5402": "Improve GHSA-mh99-v99m-4gvg",
2733
"690ed711e8ac3692514efeefb290c12c4ef01169": "Improve GHSA-mh99-v99m-4gvg",
@@ -265,10 +271,6 @@
265271
"GHSA-8R6W-3QQ5-4P4R": {
266272
"fb7da69bc5a48e84fd5bb22e39a301555019875a": "Publish GHSA-8r6w-3qq5-4p4r"
267273
},
268-
"GHSA-CRF3-V9RR-V7HJ": {
269-
"73e5718a5b647612d0bef1c371c167386ea5a5f9": "Improve GHSA-crf3-v9rr-v7hj",
270-
"e34faa994a969a96da73434c6e96d687fa245753": "Publish Advisories\n\nGHSA-332v-fh8c-j8r7\nGHSA-359c-qmw4-f7gf\nGHSA-48px-72pc-9gfw\nGHSA-683g-rp82-2xcr\nGHSA-6p99-w6f4-qcvq\nGHSA-7h94-344f-429f\nGHSA-8mjr-j93g-6x4q\nGHSA-8p8v-838m-f36p\nGHSA-9vh2-928p-mm63\nGHSA-crf3-v9rr-v7hj\nGHSA-gm4w-wf6f-2ghm\nGHSA-h7w8-vg64-36f2\nGHSA-j58f-rgm2-v2p8\nGHSA-j6qh-f45v-j454\nGHSA-mr6p-pxvc-7864\nGHSA-q3h2-8p56-9cg6\nGHSA-q9pq-xp5c-jmhr\nGHSA-w2pp-vvh7-8jx9\nGHSA-x9fx-2h43-2prm"
271-
},
272274
"GHSA-VG6V-J97M-H5XQ": {
273275
"928695930c857c5de64073fe5500cee26f947e59": "Publish Advisories\n\nGHSA-vg6v-j97m-h5xq\nGHSA-xvc3-826v-xf47"
274276
},

data/fix-commits/bc-java-fd129cd9.json

Lines changed: 13 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2,31 +2,36 @@
22
"vcs_url": "https://github.com/bcgit/bc-java",
33
"vulnerabilities": {
44
"CVE-2024-29857": {
5-
"22db5b9594127e5774d246bb596df36db313f42b": "Add Properties.EC_MAX_F2M_FIELD_SIZE for the org.bouncycastle.ec.max_f2m_field_size F2m field size bound (CVE-2024-29857) and use it in ECCurve rather than the inlined literal, mirroring the constant into the jdk1.4 overlay.",
6-
"b1e21a374d8672486afa7789d77f4ff26bf2416d": "Add missing 1.78 defects-fixed entries for CVE-2024-14041 (KyberSlash) and CVE-2024-29857 (F2m field size), cross-reference every 1.78 advisory CVE from its defects-fixed entry, and credit the Robusta team's constant-time analysis."
5+
"40400826b535f0e1d47391732c0180d8eb72d5c0": "Add Properties.EC_MAX_F2M_FIELD_SIZE for the org.bouncycastle.ec.max_f2m_field_size F2m field size bound (CVE-2024-29857) and use it in ECCurve rather than the inlined literal, mirroring the constant into the jdk1.4 overlay.",
6+
"30814a5091c7a2b4ce1e1332df189215e704518a": "Add missing 1.78 defects-fixed entries for CVE-2024-14041 (KyberSlash) and CVE-2024-29857 (F2m field size), cross-reference every 1.78 advisory CVE from its defects-fixed entry, and credit the Robusta team's constant-time analysis."
77
},
88
"CVE-2024-14041": {
9-
"b1e21a374d8672486afa7789d77f4ff26bf2416d": "Add missing 1.78 defects-fixed entries for CVE-2024-14041 (KyberSlash) and CVE-2024-29857 (F2m field size), cross-reference every 1.78 advisory CVE from its defects-fixed entry, and credit the Robusta team's constant-time analysis."
9+
"30814a5091c7a2b4ce1e1332df189215e704518a": "Add missing 1.78 defects-fixed entries for CVE-2024-14041 (KyberSlash) and CVE-2024-29857 (F2m field size), cross-reference every 1.78 advisory CVE from its defects-fixed entry, and credit the Robusta team's constant-time analysis."
1010
},
1111
"CVE-2026-3505": {
12-
"71b8e3657adce9828102d33772f290bfc60a1004": "Revert \"OpenPGP v6 SEIPDv2 AEAD chunkSize is unbounded on decrypt \u2192 1L<<(chunkSize+6) buffer: chunkSize 24 \u2192 1 GiB alloc (memory-DoS), 25 \u2192 NegativeArraySizeException. Concrete sibling asymmetry: v5 AEADEncDataPacket:51 has if (chunkSize > 16) throw (CVE-2026-3505) but v6 SymmetricEncIntegrityPacket:54 reads chunkSize=in.read() with no bound \u2014 the missed sibling. Attacker needs only the recipient's public key.\"\n\nThis reverts commit 1299519c70c21b4b56296762295528124f5825a7.",
13-
"1299519c70c21b4b56296762295528124f5825a7": "OpenPGP v6 SEIPDv2 AEAD chunkSize is unbounded on decrypt \u2192 1L<<(chunkSize+6) buffer: chunkSize 24 \u2192 1 GiB alloc (memory-DoS), 25 \u2192 NegativeArraySizeException. Concrete sibling asymmetry: v5 AEADEncDataPacket:51 has if (chunkSize > 16) throw (CVE-2026-3505) but v6 SymmetricEncIntegrityPacket:54 reads chunkSize=in.read() with no bound \u2014 the missed sibling. Attacker needs only the recipient's public key."
12+
"de6dd1e538465235db3036a8d3d889eaa9698919": "Revert \"OpenPGP v6 SEIPDv2 AEAD chunkSize is unbounded on decrypt \u2192 1L<<(chunkSize+6) buffer: chunkSize 24 \u2192 1 GiB alloc (memory-DoS), 25 \u2192 NegativeArraySizeException. Concrete sibling asymmetry: v5 AEADEncDataPacket:51 has if (chunkSize > 16) throw (CVE-2026-3505) but v6 SymmetricEncIntegrityPacket:54 reads chunkSize=in.read() with no bound \u2014 the missed sibling. Attacker needs only the recipient's public key.\"\n\nThis reverts commit 12f6884e4f647e13cca0c725a3233b216a3b485a.",
13+
"12f6884e4f647e13cca0c725a3233b216a3b485a": "OpenPGP v6 SEIPDv2 AEAD chunkSize is unbounded on decrypt \u2192 1L<<(chunkSize+6) buffer: chunkSize 24 \u2192 1 GiB alloc (memory-DoS), 25 \u2192 NegativeArraySizeException. Concrete sibling asymmetry: v5 AEADEncDataPacket:51 has if (chunkSize > 16) throw (CVE-2026-3505) but v6 SymmetricEncIntegrityPacket:54 reads chunkSize=in.read() with no bound \u2014 the missed sibling. Attacker needs only the recipient's public key."
1414
},
1515
"CVE-2018-5382": {
1616
"faf5daa6e9b8460f862afc0af1cc0da365f7d4d2": "Gate loading of legacy 16-bit-MAC BKS v0/v1 keystores behind enable_v1 (CVE-2018-5382)",
17+
"b2a1bf753b673478fb978757d2165bfccfcde27d": "Gate loading of legacy 16-bit-MAC BKS v0/v1 keystores behind enable_v1 (CVE-2018-5382)",
1718
"c014f78b148685527c5646b1204cd7f595005afa": "updates from FIPS API\nadded ref to CVE-2018-5382 in releasenotes.",
1819
"4534f41ab3ce581d1bb69d64276ab60d0df49a7e": "updates from FIPS API\nadded ref to CVE-2018-5382 in releasenotes.",
1920
"15b91d6e88441348d3d0b387528e470be46e759f": "updates from FIPS API\nadded ref to CVE-2018-5382 in releasenotes."
2021
},
2122
"CVE-2023-0464": {
2223
"f344468ccdb8ac645c67ae37dd714568552681aa": "Bound the policy-tree in the PKIXCertPathReviewer copies too (CVE-2023-0464 class)",
23-
"01db42757d45faf67e2111721c3c994203f5422d": "Bound the X.509 valid-policy-tree size during PKIX path validation (CVE-2023-0464 class)"
24+
"9728b30cfca6217289b6bd9d6b28270a0af17d44": "Bound the policy-tree in the PKIXCertPathReviewer copies too (CVE-2023-0464 class)",
25+
"01db42757d45faf67e2111721c3c994203f5422d": "Bound the X.509 valid-policy-tree size during PKIX path validation (CVE-2023-0464 class)",
26+
"a6b4857b7845b68cffad18a416d9893c76847a48": "Bound the X.509 valid-policy-tree size during PKIX path validation (CVE-2023-0464 class)"
2427
},
2528
"CVE-2024-0727": {
26-
"9a4ba02c3dd73e711b422103f151d1269af2c97c": "Complete CVE-2024-0727 null-content hardening across the PKCS#12 SPI pair"
29+
"9a4ba02c3dd73e711b422103f151d1269af2c97c": "Complete CVE-2024-0727 null-content hardening across the PKCS#12 SPI pair",
30+
"88324b45e07cccb718e28f943f26a885d3e42874": "Complete CVE-2024-0727 null-content hardening across the PKCS#12 SPI pair"
2731
},
2832
"CVE-2026-5588": {
29-
"6d9da1b13c466e840408d953116c46c6afdb9cc2": "Reject composite signatures missing or with extra components in CompositeVerifier (CVE-2026-5588 follow-up): require one component per key so a signature stripped to a verifying prefix no longer validates"
33+
"6d9da1b13c466e840408d953116c46c6afdb9cc2": "Reject composite signatures missing or with extra components in CompositeVerifier (CVE-2026-5588 follow-up): require one component per key so a signature stripped to a verifying prefix no longer validates",
34+
"0fcd48a5033a05c4fa3275263966a749d2fe442c": "Reject composite signatures missing or with extra components in CompositeVerifier (CVE-2026-5588 follow-up): require one component per key so a signature stripped to a verifying prefix no longer validates"
3035
},
3136
"CVE-2017-15361": {
3237
"672fd2ae98019ddeb3afebfdb821e5531496d57f": "Add RSA test case for CVE-2017-15361 vulnerability",

data/fix-commits/kafka-6b26dc92.json

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,15 @@
11
{
22
"vcs_url": "https://github.com/apache/kafka",
33
"vulnerabilities": {
4+
"CVE-2026-44432": {
5+
"76507853bfa6c59a9f43c0ad18cad75aec422fab": "MINOR: Updates build and project dependencies (#22939)\n\ndetails: - bcpkix: 1.84 -->> 1.85 - jgit: 7.6.0 -->> 7.7.1 -\njunit: 5.14.3 -->> 5.14.4 - junitPlatform: 1.14.3 -->> 1.14.4 -\nmavenArtifact: 3.9.15 -->> 3.9.16 - swagger: 2.2.48 -->> 2.2.52 -\nGradle plugins: - gradle-versions-plugin: version update (0.54.0 -->>\n0.56.0) and name change (from `com.github.ben-manes.versions plugin` to\n`io.github.ben-manes.versions`) - note: plugin now supports\nparallel build (and hence `--no-parallel` switch is not required\nanymore) - dependencycheck: 12.2.1 -->> 12.2.2 - spotbugs: 6.5.1\n-->> 6.5.9 - scoverage: 8.1 -->> 9.1 - shadow: 9.4.1 -->> 9.6.1\n\nCVEs addressed via bcpkix and jgit version updates: - bcpkix: several\nvulnerabilities are addressed:\nhttps://github.com/bcgit/bc-java/blob/r1rv85/docs/releasenotes.html#L330\n- JGit: these two vulnerabilities are addressed: - CVE-2026-44432\n- https://www.cve.org/CVERecord?id=CVE-2026-44432 -\n\nhttps://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\n- CVE-2026-56624 - https://www.cve.org/CVERecord?id=CVE-2026-56624\n- https://lists.apache.org/thread/o4c2jml522j3z80gbryqzc2f1253ltp6\n\nSome notable release notes links: - bcpkix:\nhttps://github.com/bcgit/bc-java/blob/r1rv85/docs/releasenotes.html#L22\n- JGit: -\nhttps://projects.eclipse.org/projects/technology.jgit/releases/7.7.0\n- https://projects.eclipse.org/projects/technology.jgit/releases/7.7.1\n- gradle-versions-plugin: -\nhttps://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.55.0\n-\nhttps://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.56.0\n- scoverage gradle plugin: -\nhttps://github.com/scoverage/gradle-scoverage/releases/tag/9.0 -\nhttps://github.com/scoverage/gradle-scoverage/releases/tag/9.1 -\nshadow gradle plugin:\nhttps://gradleup.com/shadow/changes/#961-2026-07-22\n\nReviewers: Mickael Maison <mickael.maison@gmail.com>"
6+
},
7+
"CVE-2026-56624": {
8+
"76507853bfa6c59a9f43c0ad18cad75aec422fab": "MINOR: Updates build and project dependencies (#22939)\n\ndetails: - bcpkix: 1.84 -->> 1.85 - jgit: 7.6.0 -->> 7.7.1 -\njunit: 5.14.3 -->> 5.14.4 - junitPlatform: 1.14.3 -->> 1.14.4 -\nmavenArtifact: 3.9.15 -->> 3.9.16 - swagger: 2.2.48 -->> 2.2.52 -\nGradle plugins: - gradle-versions-plugin: version update (0.54.0 -->>\n0.56.0) and name change (from `com.github.ben-manes.versions plugin` to\n`io.github.ben-manes.versions`) - note: plugin now supports\nparallel build (and hence `--no-parallel` switch is not required\nanymore) - dependencycheck: 12.2.1 -->> 12.2.2 - spotbugs: 6.5.1\n-->> 6.5.9 - scoverage: 8.1 -->> 9.1 - shadow: 9.4.1 -->> 9.6.1\n\nCVEs addressed via bcpkix and jgit version updates: - bcpkix: several\nvulnerabilities are addressed:\nhttps://github.com/bcgit/bc-java/blob/r1rv85/docs/releasenotes.html#L330\n- JGit: these two vulnerabilities are addressed: - CVE-2026-44432\n- https://www.cve.org/CVERecord?id=CVE-2026-44432 -\n\nhttps://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\n- CVE-2026-56624 - https://www.cve.org/CVERecord?id=CVE-2026-56624\n- https://lists.apache.org/thread/o4c2jml522j3z80gbryqzc2f1253ltp6\n\nSome notable release notes links: - bcpkix:\nhttps://github.com/bcgit/bc-java/blob/r1rv85/docs/releasenotes.html#L22\n- JGit: -\nhttps://projects.eclipse.org/projects/technology.jgit/releases/7.7.0\n- https://projects.eclipse.org/projects/technology.jgit/releases/7.7.1\n- gradle-versions-plugin: -\nhttps://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.55.0\n-\nhttps://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.56.0\n- scoverage gradle plugin: -\nhttps://github.com/scoverage/gradle-scoverage/releases/tag/9.0 -\nhttps://github.com/scoverage/gradle-scoverage/releases/tag/9.1 -\nshadow gradle plugin:\nhttps://gradleup.com/shadow/changes/#961-2026-07-22\n\nReviewers: Mickael Maison <mickael.maison@gmail.com>"
9+
},
10+
"GHSA-MF9V-MFXR-J63J": {
11+
"76507853bfa6c59a9f43c0ad18cad75aec422fab": "MINOR: Updates build and project dependencies (#22939)\n\ndetails: - bcpkix: 1.84 -->> 1.85 - jgit: 7.6.0 -->> 7.7.1 -\njunit: 5.14.3 -->> 5.14.4 - junitPlatform: 1.14.3 -->> 1.14.4 -\nmavenArtifact: 3.9.15 -->> 3.9.16 - swagger: 2.2.48 -->> 2.2.52 -\nGradle plugins: - gradle-versions-plugin: version update (0.54.0 -->>\n0.56.0) and name change (from `com.github.ben-manes.versions plugin` to\n`io.github.ben-manes.versions`) - note: plugin now supports\nparallel build (and hence `--no-parallel` switch is not required\nanymore) - dependencycheck: 12.2.1 -->> 12.2.2 - spotbugs: 6.5.1\n-->> 6.5.9 - scoverage: 8.1 -->> 9.1 - shadow: 9.4.1 -->> 9.6.1\n\nCVEs addressed via bcpkix and jgit version updates: - bcpkix: several\nvulnerabilities are addressed:\nhttps://github.com/bcgit/bc-java/blob/r1rv85/docs/releasenotes.html#L330\n- JGit: these two vulnerabilities are addressed: - CVE-2026-44432\n- https://www.cve.org/CVERecord?id=CVE-2026-44432 -\n\nhttps://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\n- CVE-2026-56624 - https://www.cve.org/CVERecord?id=CVE-2026-56624\n- https://lists.apache.org/thread/o4c2jml522j3z80gbryqzc2f1253ltp6\n\nSome notable release notes links: - bcpkix:\nhttps://github.com/bcgit/bc-java/blob/r1rv85/docs/releasenotes.html#L22\n- JGit: -\nhttps://projects.eclipse.org/projects/technology.jgit/releases/7.7.0\n- https://projects.eclipse.org/projects/technology.jgit/releases/7.7.1\n- gradle-versions-plugin: -\nhttps://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.55.0\n-\nhttps://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.56.0\n- scoverage gradle plugin: -\nhttps://github.com/scoverage/gradle-scoverage/releases/tag/9.0 -\nhttps://github.com/scoverage/gradle-scoverage/releases/tag/9.1 -\nshadow gradle plugin:\nhttps://gradleup.com/shadow/changes/#961-2026-07-22\n\nReviewers: Mickael Maison <mickael.maison@gmail.com>"
12+
},
413
"CVE-2026-54515": {
514
"1c58ed31936c864101f68d925dc249a1aeb49f83": "KAFKA-20773: Bump jackson to 2.21.5 (#22793)\n\nThis patch fixes a Jackson Databind vulnerability reported in:\n\nhttps: //nvd.nist.gov/vuln/detail/CVE-2026-54515\nReviewers: Mickael Maison <mickael.maison@gmail.com>\n\n---------\n\nSigned-off-by: Federico Valeri <fedevaleri@gmail.com>",
615
"1d2e1cb8bd416bd16cae61386cda9f7d0006813c": "KAFKA-20773: Bump jackson to 2.21.5 (#22793)\n\nThis patch fixes a Jackson Databind vulnerability reported in:\n\nhttps: //nvd.nist.gov/vuln/detail/CVE-2026-54515\nReviewers: Mickael Maison <mickael.maison@gmail.com>\n\n---------\n\nSigned-off-by: Federico Valeri <fedevaleri@gmail.com>",

0 commit comments

Comments
 (0)