CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2019-0211
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed…
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 7.8. EPSS estimates 65.0% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
- State
- PUBLISHED
- Published
- Apr 8, 2019
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAapacheOriginal evidence ↗
Record text: In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Inspect raw assertion
- Field
container- Value
- In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Apache HTTP Server Privilege Escalation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache HTTP Server Privilege Escalation Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 65.01% probability · 99.19th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.650050000000; percentile 0.991890000000
FIRST EPSS · score date Aug 27, 2026 · 99.2th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Inspect raw assertion
- Field
container- Value
- In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Apache HTTP Server Privilege Escalation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache HTTP Server Privilege Escalation Vulnerability
65.01% probability · 99.19th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.650050000000; percentile 0.991890000000
Applicability
Cited product scope
Grouped from 8 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
28 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.4.17 to 2.4.38"}]product-9ac1ed1c70311d36a45c72f8dd14128e1f8de18b347393d0fa18e946c202b58bLinked exactInspect raw assertion
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.4.17; through including 2.4.38
- Match ID
3af858a9-701e-44f6-8db1-36b76c40733a
product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815d70a8-47d3-459c-a32c-9feaca0659d1
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b3293e55-5506-4587-a318-d1734f781c09
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07c312a0-cd2c-4b9c-b064-6409b25c278f
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d100f7ce-fc64-4cc6-852a-6136d72da419
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97a4b8df-58da-4ab6-a1f9-331b36409ba3
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc1bd7b7-6d88-42b8-878e-f1318ca5fcaf
product-c8fd04cb7cbf514fd1a8bf9dafd5cd44499d96cff80cffaf10ccd171e11e4a5fLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3fa5e22c-489b-4c5f-a5f3-c03f45ca8811
product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925Linked exactInspect raw assertions
cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f65dab0-3dad-49ff-bc73-3581cc3d5bf3
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1e78106-58e6-4d59-990f-75da575bfad9
product-cba906812ace18556eb38b63d10f959a318fecf86d7a857508655d7528f4e6dbLinked exactInspect raw assertions
cpe:2.3:a:oracle:communications_session_report_manager:8.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7ddf6809-53a7-4f7d-9fa8-b522be8f7a21
cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
086e2e5c-44eb-4c07-b298-c04189533996
cpe:2.3:a:oracle:communications_session_report_manager:8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa86a15f-fab8-4df5-95ac-da3d1cf7a720
cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db43dfd4-d058-4001-bd19-488e059f4532
product-84ef6de30bdd65a98e05d629523814af7aab0e6da595cb481574730265e7b4bdLinked exactInspect raw assertions
cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5682daeb-3810-4541-833a-568c868bce0b
cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
01bc9aed-f81d-4344-ad97-eef19b6ea8c7
cpe:2.3:a:oracle:communications_session_route_manager:8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b374f86-4ec8-4797-a8c3-5c1ff1dfc9f8
cpe:2.3:a:oracle:communications_session_route_manager:8.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b042935-bc42-4ca8-9379-7f0f894f9653
product-1a32432af689ea0bc3ff9b90c5029f0506d7000b62ea7a504dc98cbf6d36ddf5Linked exactInspect raw assertions
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37209c6f-ef99-4d21-9608-b3a06d283d24
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ab654dfa-fef9-4d00-adb0-f3f2b6acf13e
product-bfccd54e33671fad7b63685c4bf72cdbd53aad278e2a851c4928fef18206adceLinked exactInspect raw assertion
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfc79b17-e9d2-44d5-93ed-2f959e7a3d43
product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09Linked exactInspect raw assertions
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f69b9a5-f21b-4904-9f27-95c0f7a628e3
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82ea4ba7-c38b-4af3-8914-9e3d089ebdd4
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b9c9bc66-fa5f-4774-9bda-7ab88e2839c4
product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900Linked exactInspect raw assertions
cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0ed83e3-e6bf-4eaa-af8f-33485a88a218
cpe:2.3:a:oracle:retail_xstore_point_of_service:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f87fc90-16d0-4051-8280-b0dd4441f10b
product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cff558-3c47-480d-a2f0-babf26042943
product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c3741b8-851f-475d-b428-523f4f722350
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
62c31522-0a17-4025-b269-855c7f4b45c2
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0e3f09b5-569f-4c58-9fca-3c0953d107b5
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
831f0f47-3565-4763-b16f-c87b1ff2035e
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
92bc9265-6959-4d37-be5e-8c45e98992f8
product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5a47ef78-a5b6-4b89-8b74-eeb0647c549f
product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.2_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ead7ec1d-5979-42e6-9da6-355b53431f3b
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.4_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ae49dca5-1b01-4478-a1e9-2e87e948a0c1
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
213593d4-eb5a-4a1b-bdf3-3f043c5f6a6c
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37b7ce5c-bfea-4f96-9759-d511ef189059
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.1_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2ff1a19f-8a15-471a-b496-e1b4ba788356
product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32af225e-94c0-4d07-900c-dd868c05f554
product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07332196-7e36-4e95-81bc-dd959629c1be
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
22c65f53-d624-48a9-a9b7-4c78a31e19f9
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
00966ac5-1c84-4b5f-9665-5e99d4aeb3a2
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d04f433-cb52-4f3d-8711-39d3bda27fe3
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b758edc9-6421-422c-899e-a273d2936d8e
product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23d471ac-7dca-4425-ad91-e5d928753a8c
product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8_ppc64le:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f91f9255-4ee1-43c7-8831-d2b6c228bfd9
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1_ppc64le:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f505d098-2143-4218-a528-d92bfc017ffd
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2_ppc64le:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
96e5cec7-d3b9-4895-96e9-e26d2acf1ae3
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6_ppc64le:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d9c30c59-07f7-4cce-b057-052eccd36db8
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4_ppc64le:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb28cf82-799f-4a6e-b1db-0ab423e6c05d
product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
76c24d94-834a-4e9d-8f73-624afa99aaa2
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e28f226a-cbc7-4a32-be58-398fa5b42481
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6897676d-53f9-45b3-b27f-7ff9a4c58d33
product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71daLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ac10d919-57fd-4725-b8d2-39ecb476902f
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1272df03-7674-4bd4-8e64-94004b195448
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b09acf2d-d83f-4a86-8185-9569605d8ee1
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1ca946d-1665-4874-9d41-c7d963dd1f56
product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
01ed4f33-ebe7-4c04-8312-3da580effb68
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3addb02d-f377-43ce-b0a8-fc6c7d5cfabc
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fb096d5d-e8f6-4164-8b76-0217b7151d30
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e881c927-df96-4d2e-9887-ff12e456b1fb
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b3d1213c-eb9c-4475-9268-86ad947d256e
product-49ab02a91a17fb75f3078c0ca26e9810ac54102e80b429b0a50254aca6ec044fLinked exactInspect raw assertion
cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2466282-51ab-478d-9ff4-fa524265ed2e
Affected-product evidence
Accepted scope and product mapping
27 canonical links · 1 source-reported links
vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07241a8b-9c38-46e6-a65e-fa68a49410382b7560b4-f0b2-4fb1-b1bc-4ea78f5c0c3d4cec14e5-ef0a-4bee-a589-7bfa8df1614864654e92-3589-4202-9bc7-80e917919407855eec3a-dc14-4e4d-97d6-ce20f89c8fa0vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1a32432af689ea0bc3ff9b90c5029f0506d7000b62ea7a504dc98cbf6d36ddf5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
008cb22e-f601-485c-95de-4a770cc8f994de2d90a0-4704-468b-b0ff-fc5aa9828012vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07a21952-6aa4-4373-94f3-d5818979ee7a2a09106c-bf3c-461d-9b9c-a6146bea20d92d0bbc6c-9976-4453-8443-395b1010c18d8fb8438f-78ce-4504-9f71-f2762eedb922a7f700d2-c31b-4f40-a81e-69ef12c2b7d9vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5243472b-32ef-4e9e-92de-035cf349240f785432d5-058a-4ca4-ae02-7ae15ac24c8acbbae551-2de0-4a71-98f3-9370651a0af7ce6f93ec-c2f3-45b8-9dc8-9c7b305eb1b2e485ff3c-46ac-45ae-9158-f89208e21f0dvendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e2d9396e-2611-4237-b99b-ed1ea480487avendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-427b0c2c486fb2def0bb109cedfb1acee0df715e091df07211619dac22147450
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f56a36b0-0896-40ac-8e2c-8f08b390426cvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-49ab02a91a17fb75f3078c0ca26e9810ac54102e80b429b0a50254aca6ec044f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c65e921e-98e2-4541-a8f9-7c4ec5a80397vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a79ffef2-5f69-4883-b6a6-a57f044bc89dvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
20c97437-c7f7-4beb-a417-428c9828c26b62f0a7d3-c9d3-496c-aa1e-f8405704d50f7b1e4c11-b62e-460b-bc09-fd7c634e3280vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
61a84567-6076-476e-a196-09e26a4233917cb5c086-d5b7-45bb-a9f7-b4162a3bcfd3d4f99d95-a222-4158-ad30-5217c9503376vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7679dc501564d985768c6f49dad30b878a10aff5484e38e0c095065539bf2f95
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
88e3d8d2-62a5-4abf-803f-40cca8ecdc53vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-84ef6de30bdd65a98e05d629523814af7aab0e6da595cb481574730265e7b4bd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4c5df97f-df77-4ee8-904f-fb96687de329a7126410-df59-4085-85b6-7744a1e7f852a993009b-d472-4e5f-bd10-fcc132c42e7adeb5c815-bd52-484f-9810-48f2bf3edb13vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2dbf8b49-eb33-4e03-b23e-d2b5bf6d4ccd82cff5f6-ff76-46c5-bad9-aed99eb16ece8b829075-3516-43ae-acc6-909ed4dd748f96014290-3d9a-4d9e-bc1f-c3ea7a3349aabcb17903-dec0-4ac6-b59e-b69f67bd4832vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-9ac1ed1c70311d36a45c72f8dd14128e1f8de18b347393d0fa18e946c202b58b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
66ab9300-d854-4303-ae0f-ab7cdeb99dafvendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
11138356-cc02-4cba-b593-7394c51d15b95f39795f-fac9-4e3e-bb42-f44b5f38f3246319b817-df20-4ce1-8f8e-afc4f0ad8cbb91bd0013-024b-4931-bdd4-9e8bd4dd4b3fvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
17b96fa4-9b64-490c-8b70-df136062908f4fa39418-c86e-4444-89ab-58fcc5984d2fa9d1942a-e248-4aa5-92c2-ba4548ac3294bd48c778-ada7-4464-9d0d-d1e9839c4af7vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-bfccd54e33671fad7b63685c4bf72cdbd53aad278e2a851c4928fef18206adce
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a29fd0b1-86c0-4eac-962d-054f2118e5afvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6b7ec700-da00-44e5-a615-87e33e573ff5a91af47c-3bdb-4834-a93f-f8154afc30b6vendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
079d7f25-9a8e-4b88-a63c-8fc6fd6acf7fdb041fc9-2e8f-4f38-89fb-ecfe4fc6cf58vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c8fd04cb7cbf514fd1a8bf9dafd5cd44499d96cff80cffaf10ccd171e11e4a5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ea851d63-1dfb-46cf-82d1-ff104c7b47bcvendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0155dc86-d300-4a43-bcca-eb1edec974431d5e0331-88bd-410f-94b4-05381b579857b2249246-df13-400c-bcf0-0c004169e790vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ca784b1cfa46e7693787bdfda9b774a55e292d3cbfbb2944f6927553fd92cf5d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
122266ae-4bfc-4abd-8330-524f573d8824vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-cba906812ace18556eb38b63d10f959a318fecf86d7a857508655d7528f4e6db
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
159a7d20-c29e-4cf6-bcd7-41a6b021c631583cde81-f140-4c9c-b0b9-f8bffbf06855c0bbe9be-ed4b-4d89-93ea-146fd260f7f9ef9211b4-fa53-4d34-a7fe-151268ff5372vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ddf85b26-b586-409f-85fb-ad7c8b5c6660vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
641af8b8-e71e-4f59-a520-db8fef6218c8a762aa24-3009-436e-98ed-f08d01e32a36baa784e7-38d7-40a1-b98a-b19621d874e5e74b60e1-215a-4aff-93af-a855807aedcefdd11b33-591c-40f9-8a94-3a315dc182d4vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e26d44c4-ef3b-4379-b966-5542837da060vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c66d83b0-2b0e-4664-a157-413a6f1e6c85Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7315fb80-28eb-4967-9a67-4cfd9847996dAssessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 7.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.