# CASCA evidence receipt — CVE-2026-9165

- Generation: `gen-56ccdaf914f7b4be95b689ccae7dc20d`
- As known: 2026-07-19T05:00:42+00:00
- Comparison: first_public_core_generation
- Score policy: public-priority-v1.0.1
- Conflict: not observed in this generation

## Source assertions

- **CISA-ADP** (independent_enrichment): container — CISA ADP Vulnrichment
  - Observed: 2026-07-19T04:35:17.31812+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2026-9165
- **redhat** (original_assertion): container — Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service
  - Observed: 2026-07-19T04:35:17.31812+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2026-9165
- **FIRST EPSS** (original_assertion): model_probability — Probability 0.003190000000; percentile 0.239370000000
  - Observed: 2026-07-19T04:54:35.756809+00:00
  - Citation: https://www.first.org/epss/data_stats.html

## CVSS assessments

- **secalert@redhat.com** (Secondary, CVSS 3.1): 7.7 — score eligible
  - Evidence class: exact_record_cna; source rank: 1
  - Validation: valid_match
  - Vector: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H`
- **redhat** (unknown, CVSS 3.1): 7.7 — display only
  - Evidence class: direct_cve_record_display_only; source rank: not applicable
  - Validation: display-only direct record assessment
  - Vector: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H`

## Limitations and unknowns

- CISA KEV absence is unknown, not evidence of no exploitation.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.

Generated from CASCA normalized evidence. This receipt is not proof that an asset is affected, unaffected, safe, or fixed.
