Evidence dossier

CVE-2019-0211

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed…

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 7.8. EPSS estimates 65.0% exploit likelihood as of Aug 27, 2026.

86.586.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

State
PUBLISHED
Published
Apr 8, 2019
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    apache

    Record text: In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

    Inspect raw assertion
    Field
    container
    Value
    In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Apache HTTP Server Privilege Escalation Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Apache HTTP Server Privilege Escalation Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 65.01% probability · 99.19th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.650050000000; percentile 0.991890000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood65.00%

FIRST EPSS · score date Aug 27, 2026 · 99.2th percentile · first observed Aug 27, 2026

SeverityCVSS 7.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

apacheOriginal assertion
Record text

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Inspect raw assertion
Field
container
Value
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Apache HTTP Server Privilege Escalation Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Apache HTTP Server Privilege Escalation Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

65.01% probability · 99.19th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.650050000000; percentile 0.991890000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
68Underlying assertions
27Canonical products
68Target assertions
0Constraint assertions

Grouped from 8 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

28 scope groups

apache · source assertedApacheApache HTTP ServerDirect source scope
Affected: 2.4.17 to 2.4.38
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "2.4.17 to 2.4.38"}]
NVD CPE · APPLICATIONapachehttp_serverVulnerable target · 1 assertions
Any version (unconstrained) (>= 2.4.17, <= 2.4.38)Canonical identity product-9ac1ed1c70311d36a45c72f8dd14128e1f8de18b347393d0fa18e946c202b58bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 2.4.17; through including 2.4.38
    Match ID
    3af858a9-701e-44f6-8db1-36b76c40733a
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 4 assertions
Version 14.04; Version 16.04; Version 18.04; Version 18.10Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    815d70a8-47d3-459c-a32c-9feaca0659d1
  2. cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3293e55-5506-4587-a318-d1734f781c09
  3. cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07c312a0-cd2c-4b9c-b064-6409b25c278f
  4. cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 1 assertions
Version 9.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    deece5fc-cacf-4496-a3e7-164736409252
NVD CPE · OPERATING SYSTEMfedoraprojectfedoraVulnerable target · 3 assertions
Version 28; Version 29; Version 30Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d100f7ce-fc64-4cc6-852a-6136d72da419
  2. cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97a4b8df-58da-4ab6-a1f9-331b36409ba3
  3. cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dc1bd7b7-6d88-42b8-878e-f1318ca5fcaf
NVD CPE · APPLICATIONnetapponcommand_unified_managerVulnerable target · 1 assertions
Version not applicableCanonical identity product-c8fd04cb7cbf514fd1a8bf9dafd5cd44499d96cff80cffaf10ccd171e11e4a5fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3fa5e22c-489b-4c5f-a5f3-c03f45ca8811
NVD CPE · OPERATING SYSTEMopensuseleapVulnerable target · 2 assertions
Version 15.0; Version 42.3Canonical identity product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f65dab0-3dad-49ff-bc73-3581cc3d5bf3
  2. cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1e78106-58e6-4d59-990f-75da575bfad9
NVD CPE · APPLICATIONoraclecommunications_session_report_managerVulnerable target · 4 assertions
Version 8.0.0; Version 8.1.0; Version 8.1.1; Version 8.2.0Canonical identity product-cba906812ace18556eb38b63d10f959a318fecf86d7a857508655d7528f4e6dbLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_session_report_manager:8.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7ddf6809-53a7-4f7d-9fa8-b522be8f7a21
  2. cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    086e2e5c-44eb-4c07-b298-c04189533996
  3. cpe:2.3:a:oracle:communications_session_report_manager:8.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa86a15f-fab8-4df5-95ac-da3d1cf7a720
  4. cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db43dfd4-d058-4001-bd19-488e059f4532
NVD CPE · APPLICATIONoraclecommunications_session_route_managerVulnerable target · 4 assertions
Version 8.0.0; Version 8.1.0; Version 8.1.1; Version 8.2.0Canonical identity product-84ef6de30bdd65a98e05d629523814af7aab0e6da595cb481574730265e7b4bdLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5682daeb-3810-4541-833a-568c868bce0b
  2. cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    01bc9aed-f81d-4344-ad97-eef19b6ea8c7
  3. cpe:2.3:a:oracle:communications_session_route_manager:8.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3b374f86-4ec8-4797-a8c3-5c1ff1dfc9f8
  4. cpe:2.3:a:oracle:communications_session_route_manager:8.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4b042935-bc42-4ca8-9379-7f0f894f9653
NVD CPE · APPLICATIONoracleenterprise_manager_ops_centerVulnerable target · 2 assertions
Version 12.3.3; Version 12.4.0Canonical identity product-1a32432af689ea0bc3ff9b90c5029f0506d7000b62ea7a504dc98cbf6d36ddf5Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    37209c6f-ef99-4d21-9608-b3a06d283d24
  2. cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab654dfa-fef9-4d00-adb0-f3f2b6acf13e
NVD CPE · APPLICATIONoraclehttp_serverVulnerable target · 1 assertions
Version 12.2.1.3.0Canonical identity product-bfccd54e33671fad7b63685c4bf72cdbd53aad278e2a851c4928fef18206adceLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfc79b17-e9d2-44d5-93ed-2f959e7a3d43
NVD CPE · APPLICATIONoracleinstantis_enterprisetrackVulnerable target · 3 assertions
Version 17.1; Version 17.2; Version 17.3Canonical identity product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7f69b9a5-f21b-4904-9f27-95c0f7a628e3
  2. cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    82ea4ba7-c38b-4af3-8914-9e3d089ebdd4
  3. cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b9c9bc66-fa5f-4774-9bda-7ab88e2839c4
NVD CPE · APPLICATIONoracleretail_xstore_point_of_serviceVulnerable target · 2 assertions
Version 7.0; Version 7.1Canonical identity product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0ed83e3-e6bf-4eaa-af8f-33485a88a218
  2. cpe:2.3:a:oracle:retail_xstore_point_of_service:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2f87fc90-16d0-4051-8280-b0dd4441f10b
NVD CPE · OPERATING SYSTEMredhatenterprise_linuxVulnerable target · 1 assertions
Version 8.0Canonical identity product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f4cff558-3c47-480d-a2f0-babf26042943
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 5 assertions
Version 8.1; Version 8.2; Version 8.4; Version 8.6; Version 8.8Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c3741b8-851f-475d-b428-523f4f722350
  2. cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    62c31522-0a17-4025-b269-855c7f4b45c2
  3. cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e3f09b5-569f-4c58-9fca-3c0953d107b5
  4. cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    831f0f47-3565-4763-b16f-c87b1ff2035e
  5. cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    92bc9265-6959-4d37-be5e-8c45e98992f8
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_arm_64Vulnerable target · 1 assertions
Version 8.0_aarch64Canonical identity product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a47ef78-a5b6-4b89-8b74-eeb0647c549f
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_arm_64_eusVulnerable target · 5 assertions
Version 8.1_aarch64; Version 8.2_aarch64; Version 8.4_aarch64; Version 8.6_aarch64; Version 8.8_aarch64Canonical identity product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.2_aarch64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ead7ec1d-5979-42e6-9da6-355b53431f3b
  2. cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.4_aarch64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ae49dca5-1b01-4478-a1e9-2e87e948a0c1
  3. cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8_aarch64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    213593d4-eb5a-4a1b-bdf3-3f043c5f6a6c
  4. cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    37b7ce5c-bfea-4f96-9759-d511ef189059
  5. cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.1_aarch64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ff1a19f-8a15-471a-b496-e1b4ba788356
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systemsVulnerable target · 1 assertions
Version 8.0_s390xCanonical identity product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    32af225e-94c0-4d07-900c-dd868c05f554
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systems_eusVulnerable target · 5 assertions
Version 8.1_s390x; Version 8.2_s390x; Version 8.4_s390x; Version 8.6_s390x; Version 8.8_s390xCanonical identity product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07332196-7e36-4e95-81bc-dd959629c1be
  2. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    22c65f53-d624-48a9-a9b7-4c78a31e19f9
  3. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00966ac5-1c84-4b5f-9665-5e99d4aeb3a2
  4. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d04f433-cb52-4f3d-8711-39d3bda27fe3
  5. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b758edc9-6421-422c-899e-a273d2936d8e
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_little_endianVulnerable target · 1 assertions
Version 8.0_ppc64leCanonical identity product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    23d471ac-7dca-4425-ad91-e5d928753a8c
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_little_endian_eusVulnerable target · 5 assertions
Version 8.1_ppc64le; Version 8.2_ppc64le; Version 8.4_ppc64le; Version 8.6_ppc64le; Version 8.8_ppc64leCanonical identity product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f91f9255-4ee1-43c7-8831-d2b6c228bfd9
  2. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f505d098-2143-4218-a528-d92bfc017ffd
  3. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    96e5cec7-d3b9-4895-96e9-e26d2acf1ae3
  4. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d9c30c59-07f7-4cce-b057-052eccd36db8
  5. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb28cf82-799f-4a6e-b1db-0ab423e6c05d
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_ausVulnerable target · 3 assertions
Version 8.2; Version 8.4; Version 8.6Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaeLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    76c24d94-834a-4e9d-8f73-624afa99aaa2
  2. cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e28f226a-cbc7-4a32-be58-398fa5b42481
  3. cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6897676d-53f9-45b3-b27f-7ff9a4c58d33
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_tusVulnerable target · 4 assertions
Version 8.2; Version 8.4; Version 8.6; Version 8.8Canonical identity product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71daLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac10d919-57fd-4725-b8d2-39ecb476902f
  2. cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1272df03-7674-4bd4-8e64-94004b195448
  3. cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b09acf2d-d83f-4a86-8185-9569605d8ee1
  4. cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1ca946d-1665-4874-9d41-c7d963dd1f56
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_update_services_for_sap_solutionsVulnerable target · 5 assertions
Version 8.0; Version 8.1; Version 8.4; Version 8.6; Version 8.8Canonical identity product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    01ed4f33-ebe7-4c04-8312-3da580effb68
  2. cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3addb02d-f377-43ce-b0a8-fc6c7d5cfabc
  3. cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb096d5d-e8f6-4164-8b76-0217b7151d30
  4. cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e881c927-df96-4d2e-9887-ff12e456b1fb
  5. cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3d1213c-eb9c-4475-9268-86ad947d256e
NVD CPE · APPLICATIONredhatjboss_core_servicesVulnerable target · 1 assertions
Version 1.0Canonical identity product-49ab02a91a17fb75f3078c0ca26e9810ac54102e80b429b0a50254aca6ec044fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2466282-51ab-478d-9ff4-fa524265ed2e

Affected-product evidence

Accepted scope and product mapping

27 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07241a8b-9c38-46e6-a65e-fa68a49410382b7560b4-f0b2-4fb1-b1bc-4ea78f5c0c3d4cec14e5-ef0a-4bee-a589-7bfa8df1614864654e92-3589-4202-9bc7-80e917919407855eec3a-dc14-4e4d-97d6-ce20f89c8fa0
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1a32432af689ea0bc3ff9b90c5029f0506d7000b62ea7a504dc98cbf6d36ddf5

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
008cb22e-f601-485c-95de-4a770cc8f994de2d90a0-4704-468b-b0ff-fc5aa9828012
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07a21952-6aa4-4373-94f3-d5818979ee7a2a09106c-bf3c-461d-9b9c-a6146bea20d92d0bbc6c-9976-4453-8443-395b1010c18d8fb8438f-78ce-4504-9f71-f2762eedb922a7f700d2-c31b-4f40-a81e-69ef12c2b7d9
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5243472b-32ef-4e9e-92de-035cf349240f785432d5-058a-4ca4-ae02-7ae15ac24c8acbbae551-2de0-4a71-98f3-9370651a0af7ce6f93ec-c2f3-45b8-9dc8-9c7b305eb1b2e485ff3c-46ac-45ae-9158-f89208e21f0d
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e2d9396e-2611-4237-b99b-ed1ea480487a
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-427b0c2c486fb2def0bb109cedfb1acee0df715e091df07211619dac22147450

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f56a36b0-0896-40ac-8e2c-8f08b390426c
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-49ab02a91a17fb75f3078c0ca26e9810ac54102e80b429b0a50254aca6ec044f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c65e921e-98e2-4541-a8f9-7c4ec5a80397
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a79ffef2-5f69-4883-b6a6-a57f044bc89d
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
20c97437-c7f7-4beb-a417-428c9828c26b62f0a7d3-c9d3-496c-aa1e-f8405704d50f7b1e4c11-b62e-460b-bc09-fd7c634e3280
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
61a84567-6076-476e-a196-09e26a4233917cb5c086-d5b7-45bb-a9f7-b4162a3bcfd3d4f99d95-a222-4158-ad30-5217c9503376
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7679dc501564d985768c6f49dad30b878a10aff5484e38e0c095065539bf2f95

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
88e3d8d2-62a5-4abf-803f-40cca8ecdc53
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-84ef6de30bdd65a98e05d629523814af7aab0e6da595cb481574730265e7b4bd

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4c5df97f-df77-4ee8-904f-fb96687de329a7126410-df59-4085-85b6-7744a1e7f852a993009b-d472-4e5f-bd10-fcc132c42e7adeb5c815-bd52-484f-9810-48f2bf3edb13
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2dbf8b49-eb33-4e03-b23e-d2b5bf6d4ccd82cff5f6-ff76-46c5-bad9-aed99eb16ece8b829075-3516-43ae-acc6-909ed4dd748f96014290-3d9a-4d9e-bc1f-c3ea7a3349aabcb17903-dec0-4ac6-b59e-b69f67bd4832
Mapping establishedEvidence supported

vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-9ac1ed1c70311d36a45c72f8dd14128e1f8de18b347393d0fa18e946c202b58b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
66ab9300-d854-4303-ae0f-ab7cdeb99daf
Mapping establishedEvidence supported

vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
11138356-cc02-4cba-b593-7394c51d15b95f39795f-fac9-4e3e-bb42-f44b5f38f3246319b817-df20-4ce1-8f8e-afc4f0ad8cbb91bd0013-024b-4931-bdd4-9e8bd4dd4b3f
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
17b96fa4-9b64-490c-8b70-df136062908f4fa39418-c86e-4444-89ab-58fcc5984d2fa9d1942a-e248-4aa5-92c2-ba4548ac3294bd48c778-ada7-4464-9d0d-d1e9839c4af7
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-bfccd54e33671fad7b63685c4bf72cdbd53aad278e2a851c4928fef18206adce

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a29fd0b1-86c0-4eac-962d-054f2118e5af
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6b7ec700-da00-44e5-a615-87e33e573ff5a91af47c-3bdb-4834-a93f-f8154afc30b6
Mapping establishedEvidence supported

vendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
079d7f25-9a8e-4b88-a63c-8fc6fd6acf7fdb041fc9-2e8f-4f38-89fb-ecfe4fc6cf58
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c8fd04cb7cbf514fd1a8bf9dafd5cd44499d96cff80cffaf10ccd171e11e4a5f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ea851d63-1dfb-46cf-82d1-ff104c7b47bc
Mapping establishedEvidence supported

vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0155dc86-d300-4a43-bcca-eb1edec974431d5e0331-88bd-410f-94b4-05381b579857b2249246-df13-400c-bcf0-0c004169e790
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ca784b1cfa46e7693787bdfda9b774a55e292d3cbfbb2944f6927553fd92cf5d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
122266ae-4bfc-4abd-8330-524f573d8824
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-cba906812ace18556eb38b63d10f959a318fecf86d7a857508655d7528f4e6db

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
159a7d20-c29e-4cf6-bcd7-41a6b021c631583cde81-f140-4c9c-b0b9-f8bffbf06855c0bbe9be-ed4b-4d89-93ea-146fd260f7f9ef9211b4-fa53-4d34-a7fe-151268ff5372
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ddf85b26-b586-409f-85fb-ad7c8b5c6660
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
641af8b8-e71e-4f59-a520-db8fef6218c8a762aa24-3009-436e-98ed-f08d01e32a36baa784e7-38d7-40a1-b98a-b19621d874e5e74b60e1-215a-4aff-93af-a855807aedcefdd11b33-591c-40f9-8a94-3a315dc182d4
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e26d44c4-ef3b-4379-b966-5542837da060
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c66d83b0-2b0e-4664-a157-413a6f1e6c85
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7315fb80-28eb-4967-9a67-4cfd9847996d

Assessments

CVSS by origin

7.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.2
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:L/AC:L/Au:N/C:C/I:C/A:C
7.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

7.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
7.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.