Evidence dossier

CVE-2019-8720

A vulnerability was found in WebKit.

Exploited in the wild (CISA KEV since May 23, 2022). NVD reports CVSS 3.1 8.8. EPSS estimates 1.5% exploit likelihood as of Aug 27, 2026.

73.674.1Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

State
PUBLISHED
Published
Mar 6, 2023
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    redhat

    Record text: A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

    Inspect raw assertion
    Field
    container
    Value
    A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: WebKitGTK Memory Corruption Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    WebKitGTK Memory Corruption Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 1.54% probability · 73.13th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.015430000000; percentile 0.731250000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 23, 2022 · first observed Jul 19, 2026

Exploit likelihood1.54%

FIRST EPSS · score date Aug 27, 2026 · 73.1th percentile · first observed Aug 27, 2026

SeverityCVSS 8.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
redhatOriginal assertion
Record text

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

Inspect raw assertion
Field
container
Value
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

WebKitGTK Memory Corruption Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
WebKitGTK Memory Corruption Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

1.54% probability · 73.13th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.015430000000; percentile 0.731250000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
41Underlying assertions
23Canonical products
41Target assertions
0Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

24 scope groups

redhat · source assertedn/awebkitgtkDirect source scope
Affected: Fixed in webkitgtk 2.26.0
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Fixed in webkitgtk 2.26.0"}]
NVD CPE · APPLICATIONredhatcodeready_linux_builderVulnerable target · 1 assertions
Version 8.0Canonical identity product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    93a089e2-d66e-455c-969a-3140d991baf4
NVD CPE · APPLICATIONredhatcodeready_linux_builder_eusVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:codeready_linux_builder_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b399239a-5211-4174-9a47-a71dba786426
  2. cpe:2.3:a:redhat:codeready_linux_builder_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8be16cc2-c6b4-4b73-98a1-f28475a92f49
NVD CPE · APPLICATIONredhatcodeready_linux_builder_for_arm64_eusVulnerable target · 3 assertions
Version 8.0; Version 8.4; Version 8.6Canonical identity product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb1df28d-0d84-4e40-8e46-ba0efd371111
  2. cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    84bc50c8-5907-4bff-bd0f-c20586f81dc4
  3. cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa48c33a-ecca-41a8-8a32-cd4fad6d963b
NVD CPE · APPLICATIONredhatcodeready_linux_builder_for_ibm_z_systems_eusVulnerable target · 3 assertions
Version 8.0; Version 8.4; Version 8.6Canonical identity product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3c1a0ca2-2bbd-4a7a-b467-f456867d5ec6
  2. cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1903c71d-08f1-4b84-ae75-62a84cb789e1
  3. cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    40a60cb0-824e-4d3b-b26f-28e1f5edde44
NVD CPE · APPLICATIONredhatcodeready_linux_builder_for_power_little_endian_eusVulnerable target · 3 assertions
Version 8.0; Version 8.4; Version 8.6Canonical identity product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    845b853c-8f99-4987-aa8e-76078ce6a977
  2. cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    58d2c068-2ff0-4fab-8317-3abc6ef8b988
  3. cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3f1b4fa-2161-4be6-93e9-745e543b326c
NVD CPE · OPERATING SYSTEMredhatenterprise_linuxVulnerable target · 1 assertions
Version 8.0Canonical identity product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:arm64:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07670103-fc39-4797-af5f-1604da1e6bf5
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_desktopVulnerable target · 1 assertions
Version 7.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    33c068a4-3780-4eab-a937-6082df847564
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 4 assertions
Version 8.4; Version 8.6Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c3741b8-851f-475d-b428-523f4f722350
  2. cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e3f09b5-569f-4c58-9fca-3c0953d107b5
  3. cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:arm64:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2244278a-3ac8-437f-9f23-6fa63e7c603d
  4. cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:arm64:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8a7fdb4-f43c-44f8-b50b-31489e4905a1
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_arm64_eusVulnerable target · 1 assertions
Version 8.6Canonical identity product-98971da121beb18aba77f1066e47b34bf7289dd8eb033c7a6fe8e56e985a9f18Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_arm64_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f76c4f35-2e16-40bf-aff3-249316757798
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systemsVulnerable target · 2 assertions
Version 7.0; Version 8.0Canonical identity product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    87c21fe1-ea5c-498f-9c6c-d05f91a88217
  2. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    566507b6-ac95-47f7-a3fb-c6f414e45f51
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systems_eusVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9ef5c4ac-ca69-41e3-ad93-7ac21931374a
  2. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c9bd9ae-46fc-4609-8d99-a3cfe91d58d1
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_big_endianVulnerable target · 1 assertions
Version 7.0Canonical identity product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1cdcff34-6f1d-45a1-be37-6a0e17b04801
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_little_endianVulnerable target · 2 assertions
Version 7.0; Version 8.0Canonical identity product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b4a684c7-88fd-43c4-9bdb-ae337fcbd0ab
  2. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47811209-5ce5-4375-8391-b0a7f6a0e420
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_little_endian_eusVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    729c515e-1dd3-466d-a50b-afe058ffc94a
  2. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    983533dd-3970-4a37-9a9c-582bd48aa1e5
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_scientific_computingVulnerable target · 1 assertions
Version 7.0Canonical identity product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    37ce1dc7-72c5-483c-8921-0b462c8284d1
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_serverVulnerable target · 1 assertions
Version 7.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51ef4996-72f4-4fa4-814f-f5991e7a8318
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_ausVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaeLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e28f226a-cbc7-4a32-be58-398fa5b42481
  2. cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    76c24d94-834a-4e9d-8f73-624afa99aaa2
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutionsVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    22d095ed-9247-4133-a133-73b7668565e4
  2. cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    871a5c26-db7b-4870-a5b2-5dd24c90b4a7
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_tusVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71daLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac10d919-57fd-4725-b8d2-39ecb476902f
  2. cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1272df03-7674-4bd4-8e64-94004b195448
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_update_services_for_sap_solutionsVulnerable target · 2 assertions
Version 8.4; Version 8.6Canonical identity product-620fb96b7f8c3dad1ed3a016e96da2a9a5a83898e74776d63b998d9fe84efa9fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bc6dd887-9744-43ea-8b3c-44c6b6339590
  2. cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7614e5d3-4643-4cae-9578-9bb9d558211f
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_workstationVulnerable target · 1 assertions
Version 7.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    825ece2d-e232-46e0-a047-074b34db1e97
NVD CPE · APPLICATIONwebkitgtkwebkitgtkVulnerable target · 1 assertions
Any version (unconstrained) (< 2.26.0)Canonical identity product-7331691d1ac02379383cb61b95492a415169570a5c6729802971bb59efd91092Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.26.0
    Match ID
    9a074f91-f0ef-4427-b9ab-a2ee9c899272
NVD CPE · APPLICATIONwpewebkitwpe_webkitVulnerable target · 1 assertions
Any version (unconstrained) (< 2.26.0)Canonical identity product-ecfcadc70c55ee6744411b43602d22503fa991d5f8b0e3924590864ec7945cc6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    through excluding 2.26.0
    Match ID
    1b5d0857-4da0-41d2-a8f4-fe70e80b9f64

Affected-product evidence

Accepted scope and product mapping

23 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
16385819-4e2d-4f2a-88b7-ba490cfcd1126b96ff6c-b260-42a1-bff4-4c8b64b8d9ee6bf13efa-d830-4796-a380-5676425382bf
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
77eae0fc-dc78-4f57-8c19-4c4fa4ec79f28fe4716e-b552-48a7-a94a-c3a56ed18089
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1cd10c75-fd5b-424a-aa2b-c3c47596dbb4c689c0f2-8579-4cd7-b00f-542676bf31e4
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
eb1095f6-27f3-4eaf-a658-86069eeda68b
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-620fb96b7f8c3dad1ed3a016e96da2a9a5a83898e74776d63b998d9fe84efa9f

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9b67d457-877e-4fd5-bef3-880fc4908910c3af97e2-c7f8-41de-9d3c-f38e3e0ff1a9
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4f43bc00-c86d-4e47-a490-a01f6b63ce3194ab203b-334b-4734-a991-49d2e3a71572
Mapping establishedEvidence supported

vendor-8a3761f813854c6096cdd0ed4224503801e6abd1d5feb7a2d17b5429feac12b1 · product-7331691d1ac02379383cb61b95492a415169570a5c6729802971bb59efd91092

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3cef1018-bdc9-4c57-8808-c29a9203eae3
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
bc9cd037-f051-4d75-aeae-9270dfb18ce5d47a8f9b-3433-4cbc-8d95-cd55bc354ed8
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c8e385f0-3ff3-4f3f-be57-430961c0372adeb6d5fc-b48c-4ac3-9d92-ae6914ecbd41
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
19f39181-b32c-4551-b4c5-6a0c87e7d63c7a30599b-4607-4173-92f4-28468f4a6a257beed220-dc0e-46e5-bd38-8bd6ab2d6c44be45dc95-58cd-4326-a8b1-ad48cb1c087c
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
be3a637d-f66d-4add-b6a0-3eca5690d423
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-98971da121beb18aba77f1066e47b34bf7289dd8eb033c7a6fe8e56e985a9f18

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7ce3587c-b05a-4cec-a801-214d7bdc88c3
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0d4126b5-2dda-4105-b6a3-cdae2b0c5e3a3c8e302e-f261-4ba2-8b74-d0d70b59cec08a0e3fb0-a669-4016-ba9d-f77ed39e1114
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6ee3aa9b-b529-46c0-8591-74062045ad6b
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
92215dca-9fb7-483d-a3b9-54329cad29009c6d3429-2a26-495a-8fd4-f7cfb014f453
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
60ff638a-e23a-4032-8028-b471c7dab6778915e80f-3098-4db9-b455-164a13ccf1f7
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5b231e31-ecd5-4638-a1a2-9c6ac652cf28
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7be6343a-6b64-4641-ac71-2bdb5ed032f1
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
cfe35469-3d82-41fd-a6fe-cd7b385aef7b
Mapping establishedEvidence supported

vendor-b376b5cd121eeab789e6f912ec5c589bb6cd99677f20f8b6a939aae0e78a72f2 · product-ecfcadc70c55ee6744411b43602d22503fa991d5f8b0e3924590864ec7945cc6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1177b47e-f11e-4c46-a378-721351a84504
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
48b98ab1-919f-4ce5-a2ed-472a02390e825ca5ca20-3274-46a9-a078-c402b92a47f49a900815-65b7-41d9-85bf-b7657917180d
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
862182e2-8e2c-4581-87d5-06d24ebe7e4ca1518194-2954-40aa-bfad-fc25919850ef
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ada1244f-f0a5-4bf7-ac0d-8055d0656a98
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3efb1dde-f0e6-4afe-99d9-7371a51899e8

Assessments

CVSS by origin

8.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.