diff --git a/advisories/BREW-ansible@13-CVE-2020-1736.json b/advisories/BREW-ansible@13-CVE-2020-1736.json index fd7469bcf3..f4bad6bb7e 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1736.json +++ b/advisories/BREW-ansible@13-CVE-2020-1736.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1736", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-03T08:45:29Z", "upstream": [ "GHSA-x7jh-595q-wq82", "CVE-2020-1736", @@ -30,8 +30,7 @@ ], "ecosystem_specific": { "fix": "bump", - "range_state": "fixed", - "upstream_fixed_in": "2.10.0" + "range_state": "fixed" } } ], diff --git a/advisories/BREW-ansible@13-CVE-2020-1738.json b/advisories/BREW-ansible@13-CVE-2020-1738.json index 460efff944..b0fede7b46 100644 --- a/advisories/BREW-ansible@13-CVE-2020-1738.json +++ b/advisories/BREW-ansible@13-CVE-2020-1738.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2020-1738", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-03T08:45:29Z", "upstream": [ "GHSA-f85h-23mf-2fwh", "CVE-2020-1738", @@ -30,8 +30,7 @@ ], "ecosystem_specific": { "fix": "bump", - "range_state": "fixed", - "upstream_fixed_in": "2.9.6" + "range_state": "fixed" } } ], diff --git a/advisories/BREW-ansible@13-CVE-2023-4237.json b/advisories/BREW-ansible@13-CVE-2023-4237.json index b1fc620161..99a14f86d0 100644 --- a/advisories/BREW-ansible@13-CVE-2023-4237.json +++ b/advisories/BREW-ansible@13-CVE-2023-4237.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2023-4237", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-03T08:45:29Z", "upstream": [ "GHSA-ww3m-ffrm-qvqv", "CVE-2023-4237", @@ -31,7 +31,6 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "2.15.2", "resource": "ansible-core", "resource_purl": "pkg:pypi/ansible-core@2.20.7" } diff --git a/advisories/BREW-ansible@13-CVE-2024-47226.json b/advisories/BREW-ansible@13-CVE-2024-47226.json index 2503aa403e..ed928d2846 100644 --- a/advisories/BREW-ansible@13-CVE-2024-47226.json +++ b/advisories/BREW-ansible@13-CVE-2024-47226.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-ansible@13-CVE-2024-47226", "published": "2026-08-13T16:35:22Z", - "modified": "2026-08-13T16:35:22Z", + "modified": "2026-09-03T08:45:29Z", "upstream": [ "PYSEC-2024-325", "CVE-2024-47226" @@ -30,7 +30,6 @@ "ecosystem_specific": { "fix": "bump", "range_state": "fixed", - "upstream_fixed_in": "4.1.0-NA", "resource": "pynetbox", "resource_purl": "pkg:pypi/pynetbox@7.8.0" } diff --git a/advisories/BREW-snakeviz-CVE-2012-2374.json b/advisories/BREW-snakeviz-CVE-2012-2374.json index 3fe97a83ad..b1f6a9850e 100644 --- a/advisories/BREW-snakeviz-CVE-2012-2374.json +++ b/advisories/BREW-snakeviz-CVE-2012-2374.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2012-2374", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-f7fv-v9rh-prvc", "CVE-2012-2374", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.1", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2014-9720.json b/advisories/BREW-snakeviz-CVE-2014-9720.json index cbdb89265e..09e81ddc6f 100644 --- a/advisories/BREW-snakeviz-CVE-2014-9720.json +++ b/advisories/BREW-snakeviz-CVE-2014-9720.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2014-9720", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-8vpw-mgpf-mpvv", "CVE-2014-9720", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.2.2", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2023-28370.json b/advisories/BREW-snakeviz-CVE-2023-28370.json index a7253ad2a1..b7ab814f51 100644 --- a/advisories/BREW-snakeviz-CVE-2023-28370.json +++ b/advisories/BREW-snakeviz-CVE-2023-28370.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2023-28370", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-hj3f-6gcp-jg8j", "CVE-2023-28370", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.3.2", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2024-52804.json b/advisories/BREW-snakeviz-CVE-2024-52804.json index ab2cd5b0bd..95a01d08c9 100644 --- a/advisories/BREW-snakeviz-CVE-2024-52804.json +++ b/advisories/BREW-snakeviz-CVE-2024-52804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2024-52804", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-8w49-h785-mj3c", "CVE-2024-52804", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.4.2", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2025-47287.json b/advisories/BREW-snakeviz-CVE-2025-47287.json index a2cb1a3914..3ebc386aff 100644 --- a/advisories/BREW-snakeviz-CVE-2025-47287.json +++ b/advisories/BREW-snakeviz-CVE-2025-47287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-47287", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:09:39Z", "upstream": [ "GHSA-7cx3-6m66-7c5m", "CVE-2025-47287", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2025-67724.json b/advisories/BREW-snakeviz-CVE-2025-67724.json index d55dd6415d..918cd978d6 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67724.json +++ b/advisories/BREW-snakeviz-CVE-2025-67724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67724", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-pr2v-jx2c-wg9f", "CVE-2025-67724", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2025-67725.json b/advisories/BREW-snakeviz-CVE-2025-67725.json index a022480703..3850ac22d5 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67725.json +++ b/advisories/BREW-snakeviz-CVE-2025-67725.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67725", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-c98p-7wgm-6p64", "CVE-2025-67725", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2025-67726.json b/advisories/BREW-snakeviz-CVE-2025-67726.json index a8b8157b9e..4ae878a294 100644 --- a/advisories/BREW-snakeviz-CVE-2025-67726.json +++ b/advisories/BREW-snakeviz-CVE-2025-67726.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2025-67726", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-jhmp-mqwm-3gq8", "CVE-2025-67726", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2026-31958.json b/advisories/BREW-snakeviz-CVE-2026-31958.json index 7bf70dcf80..81478699c2 100644 --- a/advisories/BREW-snakeviz-CVE-2026-31958.json +++ b/advisories/BREW-snakeviz-CVE-2026-31958.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-31958", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-qjxf-f2mg-c6mc", "CVE-2026-31958", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.5", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2026-35536.json b/advisories/BREW-snakeviz-CVE-2026-35536.json index 14096b7c62..03a2ce9a07 100644 --- a/advisories/BREW-snakeviz-CVE-2026-35536.json +++ b/advisories/BREW-snakeviz-CVE-2026-35536.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-35536", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:09:39Z", "upstream": [ "GHSA-78cv-mqj4-43f7", "CVE-2026-35536", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.5", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -47,24 +47,24 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2026-49853.json b/advisories/BREW-snakeviz-CVE-2026-49853.json index 278c6bf195..f22636f438 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49853.json +++ b/advisories/BREW-snakeviz-CVE-2026-49853.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49853", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:09:39Z", "upstream": [ "GHSA-3x9g-8vmp-wqvf", "CVE-2026-49853", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.6", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2026-49854.json b/advisories/BREW-snakeviz-CVE-2026-49854.json index 6b00841b28..e5f9f26e4a 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49854.json +++ b/advisories/BREW-snakeviz-CVE-2026-49854.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49854", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-cx3h-4qpv-8hc9", "CVE-2026-49854", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.6", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2026-49855.json b/advisories/BREW-snakeviz-CVE-2026-49855.json index e8eee65dd4..62c8a83389 100644 --- a/advisories/BREW-snakeviz-CVE-2026-49855.json +++ b/advisories/BREW-snakeviz-CVE-2026-49855.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-CVE-2026-49855", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-mgf9-4vpg-hj56", "CVE-2026-49855", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.6", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-CVE-2026-82397.json b/advisories/BREW-snakeviz-CVE-2026-82397.json new file mode 100644 index 0000000000..b5b96f423c --- /dev/null +++ b/advisories/BREW-snakeviz-CVE-2026-82397.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-snakeviz-CVE-2026-82397", + "published": "2026-09-03T10:11:36Z", + "modified": "2026-09-03T10:11:36Z", + "upstream": [ + "GHSA-mpf4-983q-p7j4", + "CVE-2026-82397" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "snakeviz", + "purl": "pkg:brew/snakeviz" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.2_5" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "6.5.8", + "resource": "tornado", + "resource_purl": "pkg:pypi/tornado@6.5.8" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "tornado", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", + "resource": "tornado" + } + ] + }, + "summary": " Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop", + "details": "## Summary\n\nTornado parses `application/x-www-form-urlencoded` bodies with `urllib.parse.parse_qs` and does not pass `max_num_fields`. A body made almost entirely of separators produces tens of millions of fields, and the parse happens on the event loop before the handler runs, so a single request stalls the whole server.\n\n## Where it is\n\n`tornado/escape.py`, at HEAD `e530031405e2154654dedc4c84d5656b557ea310`:\n\n```python\nresult = urllib.parse.parse_qs(\n qs, keep_blank_values, strict_parsing, encoding=\"latin1\", errors=\"strict\"\n)\n```\n\n`max_num_fields` is the parameter CPython added for exactly this, and it is absent.\n\nThe path to it is entirely server-side and pre-dispatch. `RequestHandler._execute` parses the body at `tornado/web.py:1821`, which reaches `HTTPServerRequest._parse_body` at `tornado/httputil.py:636`, and the urlencoded branch of `parse_body_arguments` calls `parse_qs_bytes` at `tornado/httputil.py:1030`.\n\nThe size that reaches it is bounded only by the body cap, which defaults to the stream's `max_buffer_size` of 104857600 at `tornado/iostream.py:239`, applied as the request body default at `tornado/http1connection.py:136-140`. A 100 MB body of separators is around fifty million fields.\n\n## Impact\n\nDenial of service against the whole process, not one request. Tornado is single-threaded and the parse is synchronous on the event loop, so every other connection waits. No authentication is needed if any route accepts a form post, which is the normal case.\n\n## Suggested fix\n\nPass a bound:\n\n```python\nresult = urllib.parse.parse_qs(\n qs, keep_blank_values, strict_parsing, encoding=\"latin1\", errors=\"strict\",\n max_num_fields=max_num_fields,\n)\n```\n\nwith a conservative default and a way for applications to raise it. CPython raises `ValueError` when the limit is exceeded, which maps cleanly onto a 400.\n\nLowering the default body cap for urlencoded specifically would help too, since 100 MB of form fields is not a shape any real client sends.\n\n## Why I do not think this is a duplicate\n\nThe published tornado advisories cover out-of-bounds access in the C extension, unbounded accumulation of decompressed chunks in `AsyncHTTPClient`, the Authorization header surviving cross-origin redirects, credential leakage on curl handle reuse, and cookie attribute validation. The decompression one is the nearest in spirit and is on the client side; this is the server parsing a request body. The call is unchanged at HEAD.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mpf4-983q-p7j4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82397" + }, + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/pull/3704" + }, + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de" + }, + { + "type": "PACKAGE", + "url": "https://github.com/tornadoweb/tornado" + }, + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/releases/tag/v6.5.8" + } + ] +} diff --git a/advisories/BREW-snakeviz-GHSA-753j-mpmx-qq6g.json b/advisories/BREW-snakeviz-GHSA-753j-mpmx-qq6g.json index 3435d10c1b..44d4ca4b71 100644 --- a/advisories/BREW-snakeviz-GHSA-753j-mpmx-qq6g.json +++ b/advisories/BREW-snakeviz-GHSA-753j-mpmx-qq6g.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-GHSA-753j-mpmx-qq6g", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:09:39Z", "upstream": [ "GHSA-753j-mpmx-qq6g" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.4.1", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-GHSA-8423-8fgw-73vq.json b/advisories/BREW-snakeviz-GHSA-8423-8fgw-73vq.json index 298bf050cd..e0cef519f5 100644 --- a/advisories/BREW-snakeviz-GHSA-8423-8fgw-73vq.json +++ b/advisories/BREW-snakeviz-GHSA-8423-8fgw-73vq.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-GHSA-8423-8fgw-73vq", "published": "2026-09-02T09:57:41Z", - "modified": "2026-09-02T09:57:41Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-8423-8fgw-73vq" ], @@ -19,16 +19,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.2.2_5" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "6.5.8", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -41,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-GHSA-pw6j-qg29-8w7f.json b/advisories/BREW-snakeviz-GHSA-pw6j-qg29-8w7f.json index df188de106..03f828fc7a 100644 --- a/advisories/BREW-snakeviz-GHSA-pw6j-qg29-8w7f.json +++ b/advisories/BREW-snakeviz-GHSA-pw6j-qg29-8w7f.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-GHSA-pw6j-qg29-8w7f", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-pw6j-qg29-8w7f" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.7", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-GHSA-qppv-j76h-2rpx.json b/advisories/BREW-snakeviz-GHSA-qppv-j76h-2rpx.json index e42730242b..93854e363e 100644 --- a/advisories/BREW-snakeviz-GHSA-qppv-j76h-2rpx.json +++ b/advisories/BREW-snakeviz-GHSA-qppv-j76h-2rpx.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-GHSA-qppv-j76h-2rpx", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-qppv-j76h-2rpx" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.3.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-GHSA-w235-7p84-xx57.json b/advisories/BREW-snakeviz-GHSA-w235-7p84-xx57.json index 1ca977573f..2c20060a34 100644 --- a/advisories/BREW-snakeviz-GHSA-w235-7p84-xx57.json +++ b/advisories/BREW-snakeviz-GHSA-w235-7p84-xx57.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-GHSA-w235-7p84-xx57", "published": "2026-08-13T17:34:42Z", - "modified": "2026-08-13T17:34:42Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-w235-7p84-xx57" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.4.1", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-snakeviz-GHSA-wwv5-g3v4-889x.json b/advisories/BREW-snakeviz-GHSA-wwv5-g3v4-889x.json index f15d17de85..cfceea8c8e 100644 --- a/advisories/BREW-snakeviz-GHSA-wwv5-g3v4-889x.json +++ b/advisories/BREW-snakeviz-GHSA-wwv5-g3v4-889x.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-snakeviz-GHSA-wwv5-g3v4-889x", "published": "2026-09-02T09:57:41Z", - "modified": "2026-09-02T09:57:41Z", + "modified": "2026-09-03T10:11:36Z", "upstream": [ "GHSA-wwv5-g3v4-889x" ], @@ -19,16 +19,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.2.2_5" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "6.5.8", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -41,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ]