{
  "builtAt": "2026-10-08T01:31:27.308Z",
  "totalCriticalAndHigh": 50,
  "global": {
    "critical": [
      {
        "cveId": "RLSA-2026:76763",
        "severity": "critical",
        "cvssV3Score": 9.1,
        "summary": "Important: dovecot security, bug fix, and enhancement update",
        "publishedAt": "2026-10-07T06:01:37.070463Z",
        "ecosystemPackage": "dovecot",
        "ecosystemFixedVersion": "1:2.3.16-16.el8_10",
        "ecosystem": "Rocky Linux:8",
        "source": "osv-rocky"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106446",
        "severity": "critical",
        "cvssV3Score": 9.8,
        "summary": "Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLite",
        "publishedAt": "2026-10-06T20:17:26.430Z",
        "ecosystemPackage": "node-handlebars",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106419",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:18:11.670Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106417",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
        "publishedAt": "2026-10-06T19:18:11.433Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106414",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur",
        "publishedAt": "2026-10-06T19:18:11.090Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106401",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
        "publishedAt": "2026-10-06T19:18:09.617Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106382",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
        "publishedAt": "2026-10-06T19:18:07.400Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106375",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
        "publishedAt": "2026-10-06T19:18:06.630Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106372",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
        "publishedAt": "2026-10-06T19:18:06.300Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106358",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
        "publishedAt": "2026-10-06T19:18:04.740Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106329",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve",
        "publishedAt": "2026-10-06T19:18:01.243Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106323",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s",
        "publishedAt": "2026-10-06T19:18:00.567Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106298",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:17:57.807Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106281",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:17:55.827Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106241",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec",
        "publishedAt": "2026-10-06T19:17:51.030Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106239",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:17:50.800Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106234",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity:",
        "publishedAt": "2026-10-06T19:17:50.250Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106227",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:17:49.450Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106211",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:17:47.520Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106197",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
        "publishedAt": "2026-10-06T19:17:45.897Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-102322",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:17:39.420Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "CVE-2026-106419",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:18:11.670",
        "ecosystemPackage": null,
        "ecosystemFixedVersion": null,
        "ecosystem": null,
        "source": "nvd"
      },
      {
        "cveId": "CVE-2026-106417",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
        "publishedAt": "2026-10-06T19:18:11.433",
        "ecosystemPackage": null,
        "ecosystemFixedVersion": null,
        "ecosystem": null,
        "source": "nvd"
      },
      {
        "cveId": "CVE-2026-106414",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur",
        "publishedAt": "2026-10-06T19:18:11.090",
        "ecosystemPackage": null,
        "ecosystemFixedVersion": null,
        "ecosystem": null,
        "source": "nvd"
      },
      {
        "cveId": "CVE-2026-106401",
        "severity": "critical",
        "cvssV3Score": 9.6,
        "summary": "Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
        "publishedAt": "2026-10-06T19:18:09.617",
        "ecosystemPackage": null,
        "ecosystemFixedVersion": null,
        "ecosystem": null,
        "source": "nvd"
      }
    ],
    "high": [
      {
        "cveId": "RLSA-2026:76737",
        "severity": "high",
        "cvssV3Score": 7.4,
        "summary": "Important: rust-sequoia-sq security, bug fix, and enhancement update",
        "publishedAt": "2026-10-07T18:10:06.023020Z",
        "ecosystemPackage": "rust-sequoia-sq",
        "ecosystemFixedVersion": "0:1.4.0.1-2.el10_2",
        "ecosystem": "Rocky Linux:10",
        "source": "osv-rocky"
      },
      {
        "cveId": "DEBIAN-CVE-2026-77214",
        "severity": "high",
        "cvssV3Score": 8.2,
        "summary": "",
        "publishedAt": "2026-10-07T15:17:53.327Z",
        "ecosystemPackage": "expat",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-46570",
        "severity": "high",
        "cvssV3Score": 8.1,
        "summary": "",
        "publishedAt": "2026-10-07T15:17:21.010Z",
        "ecosystemPackage": "ntfs-3g",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-46572",
        "severity": "high",
        "cvssV3Score": 7.4,
        "summary": "",
        "publishedAt": "2026-10-07T14:17:11.470Z",
        "ecosystemPackage": "ntfs-3g",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-42618",
        "severity": "high",
        "cvssV3Score": 7.1,
        "summary": "",
        "publishedAt": "2026-10-07T14:17:09.740Z",
        "ecosystemPackage": "ntfs-3g",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-42617",
        "severity": "high",
        "cvssV3Score": 7.1,
        "summary": "",
        "publishedAt": "2026-10-07T14:17:09.587Z",
        "ecosystemPackage": "ntfs-3g",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "RLSA-2026:76734",
        "severity": "high",
        "cvssV3Score": 7.4,
        "summary": "Important: rust-rpm-sequoia security, bug fix, and enhancement update",
        "publishedAt": "2026-10-07T12:11:09.662802Z",
        "ecosystemPackage": "rust-rpm-sequoia",
        "ecosystemFixedVersion": "0:1.10.2.1-1.el10_2",
        "ecosystem": "Rocky Linux:10",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76743",
        "severity": "high",
        "cvssV3Score": 7.5,
        "summary": "Important: opentelemetry-collector security update",
        "publishedAt": "2026-10-07T12:10:19.768697Z",
        "ecosystemPackage": "opentelemetry-collector",
        "ecosystemFixedVersion": "0:0.158.0-1.el10_2",
        "ecosystem": "Rocky Linux:10",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76762",
        "severity": "high",
        "cvssV3Score": 7.5,
        "summary": "Important: perl-DBI security update",
        "publishedAt": "2026-10-07T12:10:19.768697Z",
        "ecosystemPackage": "perl-DBI",
        "ecosystemFixedVersion": "0:1.643-26.el10_2.7",
        "ecosystem": "Rocky Linux:10",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76735",
        "severity": "high",
        "cvssV3Score": 7.4,
        "summary": "Important: rust-sequoia-sqv security update",
        "publishedAt": "2026-10-07T12:10:19.768697Z",
        "ecosystemPackage": "rust-sequoia-sqv",
        "ecosystemFixedVersion": "0:1.3.0.2-1.el10_2",
        "ecosystem": "Rocky Linux:10",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76733",
        "severity": "high",
        "cvssV3Score": 7.4,
        "summary": "Important: rust-rpm-sequoia security update",
        "publishedAt": "2026-10-07T06:05:54.740077Z",
        "ecosystemPackage": "rust-rpm-sequoia",
        "ecosystemFixedVersion": "0:1.10.2.1-1.el9_8",
        "ecosystem": "Rocky Linux:9",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:75768",
        "severity": "high",
        "cvssV3Score": 7.3,
        "summary": "Important: vim security update",
        "publishedAt": "2026-10-07T06:05:17.389889Z",
        "ecosystemPackage": "vim",
        "ecosystemFixedVersion": "2:8.2.2637-26.el9_8.23",
        "ecosystem": "Rocky Linux:9",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76747",
        "severity": "high",
        "cvssV3Score": 8.8,
        "summary": "Important: freerdp security update",
        "publishedAt": "2026-10-07T06:01:37.070463Z",
        "ecosystemPackage": "freerdp",
        "ecosystemFixedVersion": "2:2.11.7-14.el8_10",
        "ecosystem": "Rocky Linux:8",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76877",
        "severity": "high",
        "cvssV3Score": 7.8,
        "summary": "Moderate: ghostscript security update",
        "publishedAt": "2026-10-07T06:01:37.070463Z",
        "ecosystemPackage": "ghostscript",
        "ecosystemFixedVersion": "0:9.27-18.el8_10",
        "ecosystem": "Rocky Linux:8",
        "source": "osv-rocky"
      },
      {
        "cveId": "RLSA-2026:76045",
        "severity": "high",
        "cvssV3Score": 8.7,
        "summary": "Important: libpcap security update",
        "publishedAt": "2026-10-07T06:01:11.181183Z",
        "ecosystemPackage": "libpcap",
        "ecosystemFixedVersion": "4:1.9.1-6.el8_10",
        "ecosystem": "Rocky Linux:8",
        "source": "osv-rocky"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106062",
        "severity": "high",
        "cvssV3Score": 7.8,
        "summary": "A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buf",
        "publishedAt": "2026-10-06T21:17:04.903Z",
        "ecosystemPackage": "gimp",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-101258",
        "severity": "high",
        "cvssV3Score": 7.8,
        "summary": "A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corrup",
        "publishedAt": "2026-10-06T21:17:02.120Z",
        "ecosystemPackage": "ghostscript",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-83550",
        "severity": "high",
        "cvssV3Score": 7.1,
        "summary": "A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows fo",
        "publishedAt": "2026-10-06T19:18:16.280Z",
        "ecosystemPackage": "prometheus-postgres-exporter",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106443",
        "severity": "high",
        "cvssV3Score": 8.8,
        "summary": "WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic ",
        "publishedAt": "2026-10-06T19:18:13.327Z",
        "ecosystemPackage": "weasyprint",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106426",
        "severity": "high",
        "cvssV3Score": 8.3,
        "summary": "Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:18:12.483Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106423",
        "severity": "high",
        "cvssV3Score": 8.8,
        "summary": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:18:12.130Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106421",
        "severity": "high",
        "cvssV3Score": 8.8,
        "summary": "Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:18:11.893Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106412",
        "severity": "high",
        "cvssV3Score": 8.3,
        "summary": "Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a cra",
        "publishedAt": "2026-10-06T19:18:10.860Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106411",
        "severity": "high",
        "cvssV3Score": 8.8,
        "summary": "Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
        "publishedAt": "2026-10-06T19:18:10.750Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      },
      {
        "cveId": "DEBIAN-CVE-2026-106409",
        "severity": "high",
        "cvssV3Score": 8.3,
        "summary": "Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic.",
        "publishedAt": "2026-10-06T19:18:10.523Z",
        "ecosystemPackage": "chromium",
        "ecosystemFixedVersion": null,
        "ecosystem": "Debian:12",
        "source": "osv-debian"
      }
    ]
  },
  "ecosystems": {
    "ubuntu": {
      "critical": [
        {
          "cveId": "UBUNTU-CVE-2026-72287",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into \"normal\" checks Move the off-by-default consistency check for vmcs12.tpr_threshold vs. the virtual APIC vTPR i",
          "publishedAt": "2026-08-15T06:22:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-74394",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate data length check imm_buf->len is a user-controlled uint32_t received from the network. Adding it to imm_data_offset without ov",
          "publishedAt": "2026-08-15T06:22:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-64564",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== c",
          "publishedAt": "2026-08-04T07:16:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-64535",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch o",
          "publishedAt": "2026-07-27T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-63940",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other c",
          "publishedAt": "2026-07-20T00:00:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-53398",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the de",
          "publishedAt": "2026-07-19T12:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-53225",
          "severity": "critical",
          "cvssV3Score": 9.1,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parame",
          "publishedAt": "2026-06-25T09:16:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": "3.13.0-215.266",
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-53215",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver sti",
          "publishedAt": "2026-06-25T09:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-53260",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot reported a weird reqsk->rsk_refcnt underflow in __inet_csk_reqsk_queue_drop(). The captured req",
          "publishedAt": "2026-06-25T09:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-52955",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the ",
          "publishedAt": "2026-06-24T17:17:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": "3.13.0-215.266",
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-52989",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it trigger",
          "publishedAt": "2026-06-24T17:17:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-52993",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one.  In tipc_buf_append(), it was being",
          "publishedAt": "2026-06-24T17:17:00Z",
          "ecosystemPackage": "linux-azure",
          "ecosystemFixedVersion": "4.15.0-1206.221~14.04.1",
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-53002",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow che",
          "publishedAt": "2026-06-24T17:17:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": "3.13.0-217.268",
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-46135",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), bu",
          "publishedAt": "2026-05-28T10:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-45988",
          "severity": "critical",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get re",
          "publishedAt": "2026-05-27T14:17:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": "3.13.0-214.265",
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        }
      ],
      "high": [
        {
          "cveId": "UBUNTU-CVE-2026-84782",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the interna",
          "publishedAt": "2026-09-29T00:00:00Z",
          "ecosystemPackage": "openssl",
          "ecosystemFixedVersion": "1.0.1f-1ubuntu2.27+esm17",
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-87902",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are me",
          "publishedAt": "2026-09-22T17:17:00Z",
          "ecosystemPackage": "wordpress",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80725",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plai",
          "publishedAt": "2026-08-29T07:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80696",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Fix reading the minimum alarm voltage Coverity reports an out-of-bounds access when reading the minimum alarm voltage for the VGPIO channel. Add the missin",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80631",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject compressed segment that overflows the compressed input lzo_decompress_bio() validates each on-disk segment length seg_len only against the workspace cbuf",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80634",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps inside WARN_ON_ONCE(). num_encaps is ",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80637",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: fix unaligned memory access in timestamp adjustment Use get_unaligned_be32() and put_unaligned_be32() to safely read and write the timestamp fields. Th",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80644",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: ocfs2: don't BUG_ON an invalid journal dinode [BUG] A fuzzed OCFS2 image can corrupt the current slot journal dinode while mount is still in progress. The mount path first ",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80665",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN kvm_handle_vncr_abort() assumes that s1_walk_result conveys an abort when kvm_translate_vncr() returns ",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80668",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer API by GC worker approach for expectations, as it already happened in ma",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80671",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON register_pid() has several issues when processing untrusted perf.data: 1. Integer overflow: (pid + 1) * sizeof(s",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80672",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: ntfs: fix u16 truncation of restart-area length check ntfs_check_restart_area() validates that the $LogFile restart area and its trailing log client record array fit within",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80673",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() When resolving an attribute lookup with a non-zero @lowest_vcn, ntfs_external_attr_find() peeks",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80674",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden the validator A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list() only on the non-resident path; nt",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux-hwe-edge",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:16.04:LTS",
          "source": "osv-ubuntu"
        },
        {
          "cveId": "UBUNTU-CVE-2026-80681",
          "severity": "high",
          "cvssV3Score": null,
          "summary": "In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). Inside route_shortcircuit(), pskb_may",
          "publishedAt": "2026-08-28T08:16:00Z",
          "ecosystemPackage": "linux",
          "ecosystemFixedVersion": null,
          "ecosystem": "Ubuntu:Pro:14.04:LTS",
          "source": "osv-ubuntu"
        }
      ]
    },
    "debian": {
      "critical": [
        {
          "cveId": "DEBIAN-CVE-2026-106446",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLite",
          "publishedAt": "2026-10-06T20:17:26.430Z",
          "ecosystemPackage": "node-handlebars",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106419",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:18:11.670Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106417",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)",
          "publishedAt": "2026-10-06T19:18:11.433Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106414",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur",
          "publishedAt": "2026-10-06T19:18:11.090Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106401",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
          "publishedAt": "2026-10-06T19:18:09.617Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106382",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
          "publishedAt": "2026-10-06T19:18:07.400Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106375",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
          "publishedAt": "2026-10-06T19:18:06.630Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106372",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
          "publishedAt": "2026-10-06T19:18:06.300Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106358",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)",
          "publishedAt": "2026-10-06T19:18:04.740Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106329",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve",
          "publishedAt": "2026-10-06T19:18:01.243Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106323",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s",
          "publishedAt": "2026-10-06T19:18:00.567Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106298",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:17:57.807Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106281",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:17:55.827Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106241",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec",
          "publishedAt": "2026-10-06T19:17:51.030Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106239",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:17:50.800Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        }
      ],
      "high": [
        {
          "cveId": "DEBIAN-CVE-2026-77214",
          "severity": "high",
          "cvssV3Score": 8.2,
          "summary": "",
          "publishedAt": "2026-10-07T15:17:53.327Z",
          "ecosystemPackage": "expat",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-46570",
          "severity": "high",
          "cvssV3Score": 8.1,
          "summary": "",
          "publishedAt": "2026-10-07T15:17:21.010Z",
          "ecosystemPackage": "ntfs-3g",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-46572",
          "severity": "high",
          "cvssV3Score": 7.4,
          "summary": "",
          "publishedAt": "2026-10-07T14:17:11.470Z",
          "ecosystemPackage": "ntfs-3g",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-42618",
          "severity": "high",
          "cvssV3Score": 7.1,
          "summary": "",
          "publishedAt": "2026-10-07T14:17:09.740Z",
          "ecosystemPackage": "ntfs-3g",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-42617",
          "severity": "high",
          "cvssV3Score": 7.1,
          "summary": "",
          "publishedAt": "2026-10-07T14:17:09.587Z",
          "ecosystemPackage": "ntfs-3g",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106062",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buf",
          "publishedAt": "2026-10-06T21:17:04.903Z",
          "ecosystemPackage": "gimp",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-101258",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corrup",
          "publishedAt": "2026-10-06T21:17:02.120Z",
          "ecosystemPackage": "ghostscript",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-83550",
          "severity": "high",
          "cvssV3Score": 7.1,
          "summary": "A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows fo",
          "publishedAt": "2026-10-06T19:18:16.280Z",
          "ecosystemPackage": "prometheus-postgres-exporter",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106443",
          "severity": "high",
          "cvssV3Score": 8.8,
          "summary": "WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic ",
          "publishedAt": "2026-10-06T19:18:13.327Z",
          "ecosystemPackage": "weasyprint",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106426",
          "severity": "high",
          "cvssV3Score": 8.3,
          "summary": "Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:18:12.483Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106423",
          "severity": "high",
          "cvssV3Score": 8.8,
          "summary": "Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:18:12.130Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106421",
          "severity": "high",
          "cvssV3Score": 8.8,
          "summary": "Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:18:11.893Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106412",
          "severity": "high",
          "cvssV3Score": 8.3,
          "summary": "Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a cra",
          "publishedAt": "2026-10-06T19:18:10.860Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106411",
          "severity": "high",
          "cvssV3Score": 8.8,
          "summary": "Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
          "publishedAt": "2026-10-06T19:18:10.750Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        },
        {
          "cveId": "DEBIAN-CVE-2026-106409",
          "severity": "high",
          "cvssV3Score": 8.3,
          "summary": "Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic.",
          "publishedAt": "2026-10-06T19:18:10.523Z",
          "ecosystemPackage": "chromium",
          "ecosystemFixedVersion": null,
          "ecosystem": "Debian:12",
          "source": "osv-debian"
        }
      ]
    },
    "redhat": {
      "critical": [
        {
          "cveId": "RLSA-2026:76763",
          "severity": "critical",
          "cvssV3Score": 9.1,
          "summary": "Important: dovecot security, bug fix, and enhancement update",
          "publishedAt": "2026-10-07T06:01:37.070463Z",
          "ecosystemPackage": "dovecot",
          "ecosystemFixedVersion": "1:2.3.16-16.el8_10",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75673",
          "severity": "critical",
          "cvssV3Score": 9.1,
          "summary": "Important: mariadb-connector-c security update",
          "publishedAt": "2026-10-06T06:05:20.701291Z",
          "ecosystemPackage": "mariadb-connector-c",
          "ecosystemFixedVersion": "0:3.2.6-2.el9_8",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75674",
          "severity": "critical",
          "cvssV3Score": 9.1,
          "summary": "Important: mariadb-connector-c security update",
          "publishedAt": "2026-10-06T06:01:39.276103Z",
          "ecosystemPackage": "mariadb-connector-c",
          "ecosystemFixedVersion": "0:3.1.11-3.el8_10",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:73979",
          "severity": "critical",
          "cvssV3Score": 9.3,
          "summary": "Critical: freerdp security update",
          "publishedAt": "2026-10-02T18:08:21.502699Z",
          "ecosystemPackage": "freerdp",
          "ecosystemFixedVersion": "2:3.10.3-12.el10_2.13",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:74084",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Critical: webkit2gtk3 security update",
          "publishedAt": "2026-10-01T06:01:37.018877Z",
          "ecosystemPackage": "webkit2gtk3",
          "ecosystemFixedVersion": "0:2.54.0-1.el8_10",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:72279",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: ipa security, bug fix, and enhancement update",
          "publishedAt": "2026-09-29T12:10:25.697024Z",
          "ecosystemPackage": "ipa",
          "ecosystemFixedVersion": "0:4.13.4-1.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:71487",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: unbound security update",
          "publishedAt": "2026-09-25T18:04:58.698983Z",
          "ecosystemPackage": "unbound",
          "ecosystemFixedVersion": "0:1.24.2-3.el9_8.8",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:71419",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: unbound security update",
          "publishedAt": "2026-09-25T12:09:37.504383Z",
          "ecosystemPackage": "unbound",
          "ecosystemFixedVersion": "0:1.24.2-7.el10_2.6",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:70564",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: ipa security, bug fix, and enhancement update",
          "publishedAt": "2026-09-24T18:05:00.461776Z",
          "ecosystemPackage": "ipa",
          "ecosystemFixedVersion": "0:4.13.4-1.el9_8",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:70754",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: unbound security update",
          "publishedAt": "2026-09-24T06:01:33.182947Z",
          "ecosystemPackage": "unbound",
          "ecosystemFixedVersion": "0:1.16.2-5.14.el8_10.4",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:69098",
          "severity": "critical",
          "cvssV3Score": 9.6,
          "summary": "Important: webkit2gtk3 security update",
          "publishedAt": "2026-09-22T18:04:11.996091Z",
          "ecosystemPackage": "webkit2gtk3",
          "ecosystemFixedVersion": "0:2.54.0-1.el9_8",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:64785",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: 389-ds-base security, bug fix, and enhancement update",
          "publishedAt": "2026-09-09T12:09:16.585859Z",
          "ecosystemPackage": "389-ds-base",
          "ecosystemFixedVersion": "0:3.2.0-10.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:64784",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: 389-ds-base security, bug fix, and enhancement update",
          "publishedAt": "2026-09-09T12:05:17.368443Z",
          "ecosystemPackage": "389-ds-base",
          "ecosystemFixedVersion": "0:2.8.0-10.el9_8",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:64791",
          "severity": "critical",
          "cvssV3Score": 9.8,
          "summary": "Critical: 389-ds:1.4 security, bug fix, and enhancement update",
          "publishedAt": "2026-09-09T06:01:32.269149Z",
          "ecosystemPackage": "389-ds-base",
          "ecosystemFixedVersion": "0:1.4.3.39-28.module+el8.10.0+40311+cd962df1",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:48790",
          "severity": "critical",
          "cvssV3Score": 9.1,
          "summary": "Important: osbuild-composer security update",
          "publishedAt": "2026-08-01T00:01:06.498175Z",
          "ecosystemPackage": "osbuild-composer",
          "ecosystemFixedVersion": "0:101.5-1.el8_10.rocky.0.6",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        }
      ],
      "high": [
        {
          "cveId": "RLSA-2026:76737",
          "severity": "high",
          "cvssV3Score": 7.4,
          "summary": "Important: rust-sequoia-sq security, bug fix, and enhancement update",
          "publishedAt": "2026-10-07T18:10:06.023020Z",
          "ecosystemPackage": "rust-sequoia-sq",
          "ecosystemFixedVersion": "0:1.4.0.1-2.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76734",
          "severity": "high",
          "cvssV3Score": 7.4,
          "summary": "Important: rust-rpm-sequoia security, bug fix, and enhancement update",
          "publishedAt": "2026-10-07T12:11:09.662802Z",
          "ecosystemPackage": "rust-rpm-sequoia",
          "ecosystemFixedVersion": "0:1.10.2.1-1.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76743",
          "severity": "high",
          "cvssV3Score": 7.5,
          "summary": "Important: opentelemetry-collector security update",
          "publishedAt": "2026-10-07T12:10:19.768697Z",
          "ecosystemPackage": "opentelemetry-collector",
          "ecosystemFixedVersion": "0:0.158.0-1.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76762",
          "severity": "high",
          "cvssV3Score": 7.5,
          "summary": "Important: perl-DBI security update",
          "publishedAt": "2026-10-07T12:10:19.768697Z",
          "ecosystemPackage": "perl-DBI",
          "ecosystemFixedVersion": "0:1.643-26.el10_2.7",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76735",
          "severity": "high",
          "cvssV3Score": 7.4,
          "summary": "Important: rust-sequoia-sqv security update",
          "publishedAt": "2026-10-07T12:10:19.768697Z",
          "ecosystemPackage": "rust-sequoia-sqv",
          "ecosystemFixedVersion": "0:1.3.0.2-1.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76733",
          "severity": "high",
          "cvssV3Score": 7.4,
          "summary": "Important: rust-rpm-sequoia security update",
          "publishedAt": "2026-10-07T06:05:54.740077Z",
          "ecosystemPackage": "rust-rpm-sequoia",
          "ecosystemFixedVersion": "0:1.10.2.1-1.el9_8",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75768",
          "severity": "high",
          "cvssV3Score": 7.3,
          "summary": "Important: vim security update",
          "publishedAt": "2026-10-07T06:05:17.389889Z",
          "ecosystemPackage": "vim",
          "ecosystemFixedVersion": "2:8.2.2637-26.el9_8.23",
          "ecosystem": "Rocky Linux:9",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76747",
          "severity": "high",
          "cvssV3Score": 8.8,
          "summary": "Important: freerdp security update",
          "publishedAt": "2026-10-07T06:01:37.070463Z",
          "ecosystemPackage": "freerdp",
          "ecosystemFixedVersion": "2:2.11.7-14.el8_10",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76877",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "Moderate: ghostscript security update",
          "publishedAt": "2026-10-07T06:01:37.070463Z",
          "ecosystemPackage": "ghostscript",
          "ecosystemFixedVersion": "0:9.27-18.el8_10",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:76045",
          "severity": "high",
          "cvssV3Score": 8.7,
          "summary": "Important: libpcap security update",
          "publishedAt": "2026-10-07T06:01:11.181183Z",
          "ecosystemPackage": "libpcap",
          "ecosystemFixedVersion": "4:1.9.1-6.el8_10",
          "ecosystem": "Rocky Linux:8",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75570",
          "severity": "high",
          "cvssV3Score": 8.8,
          "summary": "Important: freerdp security update",
          "publishedAt": "2026-10-06T12:10:42.614631Z",
          "ecosystemPackage": "freerdp",
          "ecosystemFixedVersion": "2:3.10.3-12.el10_2.14",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75576",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "Important: kernel security, bug fix, and enhancement update",
          "publishedAt": "2026-10-06T12:10:42.614631Z",
          "ecosystemPackage": "kernel",
          "ecosystemFixedVersion": "0:6.12.0-211.62.1.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75579",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "Important: sudo security update",
          "publishedAt": "2026-10-06T12:10:42.614631Z",
          "ecosystemPackage": "sudo",
          "ecosystemFixedVersion": "0:1.9.17-10.p2.el10_2.7",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75583",
          "severity": "high",
          "cvssV3Score": 7.8,
          "summary": "Important: libvirt security, bug fix, and enhancement update",
          "publishedAt": "2026-10-06T12:10:42.614631Z",
          "ecosystemPackage": "libvirt",
          "ecosystemFixedVersion": "0:11.10.0-12.9.el10_2",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        },
        {
          "cveId": "RLSA-2026:75577",
          "severity": "high",
          "cvssV3Score": 7.5,
          "summary": "Important: bind security update",
          "publishedAt": "2026-10-06T12:10:42.614631Z",
          "ecosystemPackage": "bind",
          "ecosystemFixedVersion": "2:9.18.33-15.el10_2.12",
          "ecosystem": "Rocky Linux:10",
          "source": "osv-rocky"
        }
      ]
    }
  }
}