CISA KEV · catalog date May 23, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2019-8720
A vulnerability was found in WebKit.
Exploited in the wild (CISA KEV since May 23, 2022). NVD reports CVSS 3.1 8.8. EPSS estimates 1.5% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
- State
- PUBLISHED
- Published
- Mar 6, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAredhatOriginal evidence ↗
Record text: A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
Inspect raw assertion
- Field
container- Value
- A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: WebKitGTK Memory Corruption Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- WebKitGTK Memory Corruption Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 1.54% probability · 73.13th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.015430000000; percentile 0.731250000000
FIRST EPSS · score date Aug 27, 2026 · 73.1th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
Inspect raw assertion
- Field
container- Value
- A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
WebKitGTK Memory Corruption Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- WebKitGTK Memory Corruption Vulnerability
1.54% probability · 73.13th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.015430000000; percentile 0.731250000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
24 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Fixed in webkitgtk 2.26.0"}]product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8Linked exactInspect raw assertion
cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
93a089e2-d66e-455c-969a-3140d991baf4
product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836Linked exactInspect raw assertions
cpe:2.3:a:redhat:codeready_linux_builder_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b399239a-5211-4174-9a47-a71dba786426
cpe:2.3:a:redhat:codeready_linux_builder_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8be16cc2-c6b4-4b73-98a1-f28475a92f49
product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203Linked exactInspect raw assertions
cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fb1df28d-0d84-4e40-8e46-ba0efd371111
cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
84bc50c8-5907-4bff-bd0f-c20586f81dc4
cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa48c33a-ecca-41a8-8a32-cd4fad6d963b
product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237Linked exactInspect raw assertions
cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c1a0ca2-2bbd-4a7a-b467-f456867d5ec6
cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1903c71d-08f1-4b84-ae75-62a84cb789e1
cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
40a60cb0-824e-4d3b-b26f-28e1f5edde44
product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935Linked exactInspect raw assertions
cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
845b853c-8f99-4987-aa8e-76078ce6a977
cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58d2c068-2ff0-4fab-8317-3abc6ef8b988
cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b3f1b4fa-2161-4be6-93e9-745e543b326c
product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07670103-fc39-4797-af5f-1604da1e6bf5
product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33c068a4-3780-4eab-a937-6082df847564
product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c3741b8-851f-475d-b428-523f4f722350
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0e3f09b5-569f-4c58-9fca-3c0953d107b5
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2244278a-3ac8-437f-9f23-6fa63e7c603d
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e8a7fdb4-f43c-44f8-b50b-31489e4905a1
product-98971da121beb18aba77f1066e47b34bf7289dd8eb033c7a6fe8e56e985a9f18Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_arm64_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f76c4f35-2e16-40bf-aff3-249316757798
product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87c21fe1-ea5c-498f-9c6c-d05f91a88217
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
566507b6-ac95-47f7-a3fb-c6f414e45f51
product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9ef5c4ac-ca69-41e3-ad93-7ac21931374a
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8c9bd9ae-46fc-4609-8d99-a3cfe91d58d1
product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1cdcff34-6f1d-45a1-be37-6a0e17b04801
product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b4a684c7-88fd-43c4-9bdb-ae337fcbd0ab
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47811209-5ce5-4375-8391-b0a7f6a0e420
product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
729c515e-1dd3-466d-a50b-afe058ffc94a
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
983533dd-3970-4a37-9a9c-582bd48aa1e5
product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2fLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37ce1dc7-72c5-483c-8921-0b462c8284d1
product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
51ef4996-72f4-4fa4-814f-f5991e7a8318
product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e28f226a-cbc7-4a32-be58-398fa5b42481
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
76c24d94-834a-4e9d-8f73-624afa99aaa2
product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1cLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
22d095ed-9247-4133-a133-73b7668565e4
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
871a5c26-db7b-4870-a5b2-5dd24c90b4a7
product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71daLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ac10d919-57fd-4725-b8d2-39ecb476902f
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1272df03-7674-4bd4-8e64-94004b195448
product-620fb96b7f8c3dad1ed3a016e96da2a9a5a83898e74776d63b998d9fe84efa9fLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bc6dd887-9744-43ea-8b3c-44c6b6339590
cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7614e5d3-4643-4cae-9578-9bb9d558211f
product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
825ece2d-e232-46e0-a047-074b34db1e97
product-7331691d1ac02379383cb61b95492a415169570a5c6729802971bb59efd91092Linked exactInspect raw assertion
cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.26.0
- Match ID
9a074f91-f0ef-4427-b9ab-a2ee9c899272
product-ecfcadc70c55ee6744411b43602d22503fa991d5f8b0e3924590864ec7945cc6Linked exactInspect raw assertion
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 2.26.0
- Match ID
1b5d0857-4da0-41d2-a8f4-fe70e80b9f64
Affected-product evidence
Accepted scope and product mapping
23 canonical links · 1 source-reported links
vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
16385819-4e2d-4f2a-88b7-ba490cfcd1126b96ff6c-b260-42a1-bff4-4c8b64b8d9ee6bf13efa-d830-4796-a380-5676425382bfvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
77eae0fc-dc78-4f57-8c19-4c4fa4ec79f28fe4716e-b552-48a7-a94a-c3a56ed18089vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1cd10c75-fd5b-424a-aa2b-c3c47596dbb4c689c0f2-8579-4cd7-b00f-542676bf31e4vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
eb1095f6-27f3-4eaf-a658-86069eeda68bvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-620fb96b7f8c3dad1ed3a016e96da2a9a5a83898e74776d63b998d9fe84efa9f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9b67d457-877e-4fd5-bef3-880fc4908910c3af97e2-c7f8-41de-9d3c-f38e3e0ff1a9vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4f43bc00-c86d-4e47-a490-a01f6b63ce3194ab203b-334b-4734-a991-49d2e3a71572vendor-8a3761f813854c6096cdd0ed4224503801e6abd1d5feb7a2d17b5429feac12b1 · product-7331691d1ac02379383cb61b95492a415169570a5c6729802971bb59efd91092
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3cef1018-bdc9-4c57-8808-c29a9203eae3vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bc9cd037-f051-4d75-aeae-9270dfb18ce5d47a8f9b-3433-4cbc-8d95-cd55bc354ed8vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c8e385f0-3ff3-4f3f-be57-430961c0372adeb6d5fc-b48c-4ac3-9d92-ae6914ecbd41vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
19f39181-b32c-4551-b4c5-6a0c87e7d63c7a30599b-4607-4173-92f4-28468f4a6a257beed220-dc0e-46e5-bd38-8bd6ab2d6c44be45dc95-58cd-4326-a8b1-ad48cb1c087cvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
be3a637d-f66d-4add-b6a0-3eca5690d423vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-98971da121beb18aba77f1066e47b34bf7289dd8eb033c7a6fe8e56e985a9f18
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7ce3587c-b05a-4cec-a801-214d7bdc88c3vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0d4126b5-2dda-4105-b6a3-cdae2b0c5e3a3c8e302e-f261-4ba2-8b74-d0d70b59cec08a0e3fb0-a669-4016-ba9d-f77ed39e1114vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6ee3aa9b-b529-46c0-8591-74062045ad6bvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
92215dca-9fb7-483d-a3b9-54329cad29009c6d3429-2a26-495a-8fd4-f7cfb014f453vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
60ff638a-e23a-4032-8028-b471c7dab6778915e80f-3098-4db9-b455-164a13ccf1f7vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b231e31-ecd5-4638-a1a2-9c6ac652cf28vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7be6343a-6b64-4641-ac71-2bdb5ed032f1vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cfe35469-3d82-41fd-a6fe-cd7b385aef7bvendor-b376b5cd121eeab789e6f912ec5c589bb6cd99677f20f8b6a939aae0e78a72f2 · product-ecfcadc70c55ee6744411b43602d22503fa991d5f8b0e3924590864ec7945cc6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1177b47e-f11e-4c46-a378-721351a84504vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
48b98ab1-919f-4ce5-a2ed-472a02390e825ca5ca20-3274-46a9-a078-c402b92a47f49a900815-65b7-41d9-85bf-b7657917180dvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
862182e2-8e2c-4581-87d5-06d24ebe7e4ca1518194-2954-40aa-bfad-fc25919850efvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ada1244f-f0a5-4bf7-ac0d-8055d0656a98Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3efb1dde-f0e6-4afe-99d9-7371a51899e8Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.