CISA KEV · catalog date May 4, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive…
Exploited in the wild (CISA KEV since May 4, 2022). NVD reports CVSS 3.1 7.5. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.
As of Aug 27, 2026
Normalized restatement
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
- State
- PUBLISHED
- Published
- Apr 7, 2014
- Updated
- Oct 22, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAredhatOriginal evidence ↗
Record text: The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Inspect raw assertion
- Field
container- Value
- The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: OpenSSL Information Disclosure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- OpenSSL Information Disclosure Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 100th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999970000000
FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Inspect raw assertion
- Field
container- Value
- The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
OpenSSL Information Disclosure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- OpenSSL Information Disclosure Vulnerability
100% probability · 100th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999970000000
Applicability
Cited product scope
Grouped from 25 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
36 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-fe5a053acf706c1efeb3a41fa0ba2117ff18deaeb5f09c49df64fcdf7a073730Linked exactInspect raw assertions
cpe:2.3:a:broadcom:symantec_messaging_gateway:10.6.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 16 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d4def17d-93ad-4e79-96ed-e7c44332bd52
cpe:2.3:a:broadcom:symantec_messaging_gateway:10.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 16 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1745640a-621c-458b-92c6-c24ba06d79e5
product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e2076871-2e80-4605-a470-a41c1a8ec7ee
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d305f7a-d159-4716-ab26-5e38bb5cd991
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f61f047-129c-41a6-8a27-ffcbb8563e91
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f59a04-14cf-49e2-9973-645477ea09da
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
036e8a89-7a16-411f-9d31-676313bb7244
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ff47c9f0-d8da-4b55-89eb-9b2c9383adb9
cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5991814d-ca77-4c25-90d2-db542b17e0ad
product-a62951fd5b0bcbdda321fc9a3d8f0e02e82d108dda88e8d95777b86f38d974e6Linked exactInspect raw assertion
cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 0.9.44
- Match ID
3f09bc00-9d25-4c39-b705-a5a29f630517
product-efa829ec08ca87db141c61e2020960fd44d3805e38c0aef7a9b99572583dae0eLinked exactInspect raw assertion
cpe:2.3:h:intellian:v100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
df9c2817-7f10-4369-a106-68df9369b454
product-450b9eecfbfabd72a869ff5ba30aea20685d44eb2b2398f691465388f6611cbfLinked exactInspect raw assertions
cpe:2.3:o:intellian:v100_firmware:1.24:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82bf6806-3e91-4b22-b53d-13f4cd19f757
cpe:2.3:o:intellian:v100_firmware:1.20:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a3f2bcf2-2d0c-44ab-ae21-fbc7f04d099a
cpe:2.3:o:intellian:v100_firmware:1.21:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b46ddc44-a1b4-4df8-8ad5-fd235f1c2d54
product-b5d8196de59f3140c15b8fa9700ba5e1d5fbeaa23f669621cf48d661ce1e56beLinked exactInspect raw assertion
cpe:2.3:h:intellian:v60:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bd513662-1089-4bf8-a0f8-9be5cbf937be
product-11cce17e271b9a2188541ed9b3b8367c3a1dd70442cbe43542e96a721a127c3cLinked exactInspect raw assertions
cpe:2.3:o:intellian:v60_firmware:1.15:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9079ebfd-b901-4077-ad4b-a8b034bddea1
cpe:2.3:o:intellian:v60_firmware:1.25:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cfc20c7e-e264-4892-aa43-e289207935ee
product-0d0a0a1968e111cb2a872c6ad3b3153f6c96043e3b4b5d6c5263aa0331bdfff1Linked exactInspect raw assertions
cpe:2.3:a:mitel:micollab:7.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc89913a-f419-43e8-b846-d7aa769ea898
cpe:2.3:a:mitel:micollab:7.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c08973ef-e86a-46d7-9cf6-4374f2789ed1
cpe:2.3:a:mitel:micollab:7.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9c5c14ab-2c97-406e-98b5-0bdc8b0afea1
cpe:2.3:a:mitel:micollab:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2b28f2fb-f263-4b2e-a4c7-951a474fd7f9
cpe:2.3:a:mitel:micollab:7.3.0.104:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2317158-3ee7-4894-adc0-109e0d94da0a
cpe:2.3:a:mitel:micollab:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
03433a5d-632e-47a5-871a-5859c80cb038
product-2be188192ddabadcc3c90e36337f0ec6b7518edc8010139326e4c6051bac9cacLinked exactInspect raw assertions
cpe:2.3:a:mitel:mivoice:1.1.3.3:*:*:*:*:skype_for_business:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a93f15b3-1341-446f-85d0-e1842ea1f42c
cpe:2.3:a:mitel:mivoice:1.1.2.5:*:*:*:*:lync:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
501b4ed7-0a26-430a-91a2-29099d3cf493
cpe:2.3:a:mitel:mivoice:1.4.0.102:*:*:*:*:skype_for_business:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
edd5cce5-cd24-4288-952f-b5814454a890
cpe:2.3:a:mitel:mivoice:1.3.2.2:*:*:*:*:skype_for_business:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32b33a4d-1e37-4eaa-ae25-7da399d50046
cpe:2.3:a:mitel:mivoice:1.2.0.11:*:*:*:*:skype_for_business:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37a5858d-8de8-4865-a803-7d8a9d4ea306
product-4c73cb15764ae3d438e82e9c3115563e37661626ca23fdf4ebe6c494e6fd38b6Linked exactInspect raw assertion
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 1.0.1; through excluding 1.0.1g
- Match ID
9ee79ac6-5484-4a53-8333-373dad1b5649
product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdLinked exactInspect raw assertions
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a10bc294-9196-425f-9fb0-b1625465b47f
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfbf430b-0832-44b0-aa0e-ba9e467f7668
product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9bbcd86a-e6c7-4444-9d74-f861084090f0
product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1f3befdb-5156-4e1c-80bb-8be9feaa7623
product-1220950f14941e44f97ef359dfe4710143870ab715db6bc680fb3bcf3da40d5bLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
45010d45-2ff2-4b04-b115-6b6fe606d598
product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71daLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_server_tus:6.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
835ae071-ceae-49e5-8f0c-e5f50fb85efc
product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5ed5807-55b7-47c5-97a6-03233f4fbc3a
product-ee5762a44dde001fad8815d2e3b59842d7538a6f721ffa4cfe2c51876de71400Linked exactInspect raw assertion
cpe:2.3:a:redhat:gluster_storage:2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5b45f8e4-0e7a-4d55-84c2-5be5b6335269
product-c6ae95e309497ada4c1889e6d03b86bd52986c56a51129f0b89bc25e3be2097cLinked exactInspect raw assertion
cpe:2.3:a:redhat:storage:2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
53c986bd-2d1f-4865-b16d-72fd875e3776
product-bc21aa5dab2a412aef9570b514ef0e2d033cf0ebc75eadff51969247fea73111Linked exactInspect raw assertion
cpe:2.3:a:redhat:virtualization:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37ba55fc-d350-4deb-9802-40af59c99e79
product-cc6ec6762450d69f60663ab71d17b62a5632ce897f68a60fa2246485c3dea8b4Linked exactInspect raw assertion
cpe:2.3:h:ricon:s9922l:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 15 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb07c7e6-1dfd-4b39-ba17-fb2912cb92d4
product-2d124203ec0d574e4980d2d90f90e387244cc872e31b237058966b13d6663162Linked exactInspect raw assertion
cpe:2.3:o:ricon:s9922l_firmware:16.10.3\(3794\):*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 15 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9ed94033-99c2-419b-bbfa-247b4bb3ed4d
Affected-product evidence
Accepted scope and product mapping
28 canonical links · 1 source-reported links
vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-0d0a0a1968e111cb2a872c6ad3b3153f6c96043e3b4b5d6c5263aa0331bdfff1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
323d5cf2-2bd5-4f78-8823-0c18b3459827489189cb-ceeb-40c4-8b1d-21bc8760029d4e70fad7-fcef-41a4-86e1-4ea452ddc59e9c9183aa-eedc-4ce0-8fcb-8a7dd4da1352dec2fe89-bb56-4c3e-96d0-8ae8d44631dfdec770f9-52e3-4b67-b2c3-f8debc4e5624vendor-dcf2992722f8d9236509688fa6e81c29e26d09c935977282c182cf3d7c43dbad · product-11cce17e271b9a2188541ed9b3b8367c3a1dd70442cbe43542e96a721a127c3c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0f35c556-384b-4d71-9b4b-3e32081dea775779c9b8-245c-4852-9bcf-bf8d4dc27d60vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-1220950f14941e44f97ef359dfe4710143870ab715db6bc680fb3bcf3da40d5b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
53cdffc0-df99-4269-b601-68eb7a3d19eavendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-2be188192ddabadcc3c90e36337f0ec6b7518edc8010139326e4c6051bac9cac
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
09e48ff4-9dbb-430c-bccd-ef0ad726f2a61efa9164-cbc7-417a-9b73-1039a72a8001886516af-3c34-4373-a344-ae79e9e8e527df2de93a-809b-42bd-83d6-c5454f814493ed4bbafb-3085-43ad-8a71-06ad8c134a11vendor-9b9a4f7c53757d54116be31bfc5b57cc8c1b866fe174eef54e81b00da9cbca96 · product-2d124203ec0d574e4980d2d90f90e387244cc872e31b237058966b13d6663162
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a2619070-ef8c-4551-8aa5-e0b32e84ebe2vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-2ee3687d857ef4e7d7855e69d5d810975ed7fd2f64278f59d0d83561c199f088
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fecbd604-8fe8-45aa-9277-595d4486da7avendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0aef9f4d-903b-4b0e-a03c-7972d11251f4b4ad8583-739d-43c9-b2f5-9b68e534d7f3d7048371-c7db-427c-bf12-ddfa9c84d35fvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-40b3106e5b11b0ca790141ac954e661770082707a6074a0df6144a660cf7f943
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ea2ca678-a002-42a5-a87a-5c377bdef295vendor-dcf2992722f8d9236509688fa6e81c29e26d09c935977282c182cf3d7c43dbad · product-450b9eecfbfabd72a869ff5ba30aea20685d44eb2b2398f691465388f6611cbf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
777a7b37-f97a-46e5-96b7-a4fce9987680aa25bf50-f456-4558-bf25-cf3327ecb94db11870c8-9710-4daa-9bfd-fd98d02ef3d9vendor-5a77af36c70b399c4150afea532d5e14c369adb848ec490e6df6d406650eebc0 · product-4c73cb15764ae3d438e82e9c3115563e37661626ca23fdf4ebe6c494e6fd38b6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b100931-81bd-4782-afda-a5349408831cvendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a4c83b1b-aacd-46d5-bf89-211c51d02e5ba85524a1-78a8-4c11-8be7-d8dccb71c85evendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a927391d-da98-4132-b23c-c3ad31f61e86vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d8202cb8-0152-49ff-813a-6bf25055201fvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9f9f2e7fe3116d0172d42aabf5c95691aa1351408fb5bfec1d94e5544a80d36b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7542d28d-f4f4-4edf-8e2a-0003c57d6067vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1cc12e6a-327a-46d9-a70c-801013ab110532ba269f-369d-4f9d-97ec-4c8a666d9223525d2c87-b37a-4bd4-a4d6-27bafd29c497vendor-1f3d2a1ba8f2929dc0218ff65c40c7d0adf5a7f1ac2daac4220cb4426ea39a38 · product-a62951fd5b0bcbdda321fc9a3d8f0e02e82d108dda88e8d95777b86f38d974e6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cdc2d750-19fa-48e8-a274-a724fcde0f3dvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5364f8b2-a5cd-4bf7-b0ae-ca249662bb69vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b420f22fd76ce0742fb5c19085e2157239770007e9c98cd116d191f55b6659b1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
73d0874c-634b-4c7e-88ae-7bbdeee05c1dvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc21aa5dab2a412aef9570b514ef0e2d033cf0ebc75eadff51969247fea73111
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c6bcbb3d-d23a-4e21-b5a6-dc25ac487d39vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fe95d73d-01c2-43cc-9212-426a83405516vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-c6ae95e309497ada4c1889e6d03b86bd52986c56a51129f0b89bc25e3be2097c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b3bafd2a-c677-45ce-9269-14c874400101vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c7abf4e-77d5-4258-9348-db9285e445f632b15ad1-a5d7-4060-a307-58262f22e9afvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e4238ae1c5bccef1995dbaba1e69e517124b950a41c7c0da02a3c29b763a957c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0473b526-3c73-4807-b8ec-77ebe0e1fdfbvendor-1ef96dbceb2659e0c12aa3ca81be9737ad02807194ba9388842723c2ef343f2a · product-e8ee030c5af456555be375f8570a584b3115c53302e3628a30fcbd91fb8b0fc4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
58a1524f-3977-4291-ba59-b8ae5760ef9dvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9eb0cb93-19e8-4c4e-af5f-53badbfd85c0vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ed487335d78d4f7bccc5c55c64d0b4ee70c8e26c0250946ef28a7530c588ae52
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
094f9786-77b1-4bde-9dc9-32c92d2f0c73vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ee5762a44dde001fad8815d2e3b59842d7538a6f721ffa4cfe2c51876de71400
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c84d588e-e4f3-40b1-a648-4528f0502149vendor-1761cf71c9b584bcd78194cc476accf4e748d9e43e437af4eb2b05a93ea112e8 · product-fe5a053acf706c1efeb3a41fa0ba2117ff18deaeb5f09c49df64fcdf7a073730
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
172ae55a-af36-46cf-afcd-9339fd1a269bd0ef4593-49c9-49f8-8d09-b9f50e6fdd48Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
90d27e45-1913-407d-9c70-1d6e2f633ce5Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAV:N/AC:L/Au:N/C:P/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Validation
- Valid match
- Recomputed
- 7.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.