CISA KEV · catalog date Jan 23, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2020-11023
Potential XSS vulnerability in jQuery
Exploited in the wild (CISA KEV since Jan 23, 2025). NVD reports CVSS 3.1 6.1. EPSS estimates 83.8% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
- State
- PUBLISHED
- Published
- Apr 29, 2020
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAGitHub_MOriginal evidence ↗
Record text: Potential XSS vulnerability in jQuery
Inspect raw assertion
- Field
container- Value
- Potential XSS vulnerability in jQuery
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: JQuery Cross-Site Scripting (XSS) Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- JQuery Cross-Site Scripting (XSS) Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 83.83% probability · 99.67th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.838300000000; percentile 0.996690000000
FIRST EPSS · score date Aug 27, 2026 · 99.7th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Potential XSS vulnerability in jQuery
Inspect raw assertion
- Field
container- Value
- Potential XSS vulnerability in jQuery
JQuery Cross-Site Scripting (XSS) Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- JQuery Cross-Site Scripting (XSS) Vulnerability
83.83% probability · 99.67th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.838300000000; percentile 0.996690000000
Applicability
Cited product scope
Grouped from 23 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
61 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": ">= 1.0.3, < 3.5.0"}]product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
product-212d47c5af963e5c3aa6b05f4c9bed84d410f1ed5651403daaf3aa19bbcf8d60Linked exactInspect raw assertions
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 8.8.0; through excluding 8.8.6
- Match ID
7ba49db0-ecc3-4155-b76c-0ca292600de6
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 8.7.0; through excluding 8.7.14
- Match ID
bbfe42e2-6583-4ebe-b320-b8cf9ca0c3bc
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 7.0; through excluding 7.70
- Match ID
70c672ee-2027-4a29-8c14-3450def1462a
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80f0fa5d-8d3b-4c0e-81e2-87998286af33
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
36d96259-24bd-44e2-96d9-78ce1d41f956
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e460aa51-fcda-46b9-ae97-e6676aa5e194
product-45e667ca9592a8016b1e60d2c7b2f68269f96187c19a889834314c32b2a82180Linked exactInspect raw assertion
cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 1.0.3; through excluding 3.5.0
- Match ID
1888a4d3-5058-41fc-9f3b-e837cfc0505c
product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79Linked exactInspect raw assertions
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f3e0b672-3e06-4422-b2a4-0bd073aec2a1
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b55e8d50-99b4-47ec-86f9-699b67d473ce
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e8f29e19-3a64-4426-a2aa-f169440267cc
product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bfLinked exactInspect raw assertion
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5c2089ee-5d7f-47ec-8ea5-0f69790564c4
product-90198fbd61598d38488d520b15a086d5c545d55a6f664f9ab3d5c0f5a5c239edLinked exactInspect raw assertion
cpe:2.3:a:netapp:cloud_insights_storage_workload_security_agent:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b199052-5732-4726-b06b-a12c70dfb891
product-5e8aff139fa83ae85f478f3473c05dbdb594f6f806121b02c3f419f2a2da62d5Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7afc73ce-abb9-42d3-9a71-3f5bc5381e0e
product-fc149af9032ace9a010e9f89149c81bc45faeba303217af053928b26be955f3dLinked exactInspect raw assertion
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
108a2215-50fb-4074-94cf-c130fa14566d
product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9c8c20-42eb-4ab5-bd97-212deb070c43
product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exactInspect raw assertion
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6770b6c3-732e-4e22-bf1c-2d2fd610061c
product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cddf61b7-ec5c-467c-b710-b89f502cd04f
product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
234defe0-5ce5-4b0a-96b8-5d227cb8ed31
product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8497a4c9-8474-4a62-8331-3fe862ed4098
product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0b4ad8a-f172-4558-aec6-ff424ba2d912
product-e1a5a15eac66519d4e1187be3639955761cab5eb471d3f739edd906febb8b689Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
803bc414-b250-4e3a-a478-a3881340d6b8
product-f6f14489b90770f5fcf332bfe05780026ac83b5a028570dad28517167b27d8b7Linked exactInspect raw assertion
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32f0b6c0-f930-480d-962b-3f4efdcc13c7
product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e63d8b0f-006e-4801-bf9d-1c001bbfb4f9
product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7fff7106-ed78-49ba-9ec5-b889e3685d53
product-0b15bdf94d171d9ff04dd6ff3be42b5de90d27fbebaa46da1a0a64b95b2b58c1Linked exactInspect raw assertion
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
736aeae9-782b-4f71-9893-ded53367e102
product-a9b8857994572d5d62ec3361bb9cf6d6b9ed2a9b747716f6a517489acf47bb51Linked exactInspect raw assertion
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0feb3337-bfde-462a-908b-176f92053cec
product-fcd38a3bd0a96c349925cecfd0d22ecf9836f21d88da8f545d6938975aa84275Linked exactInspect raw assertion
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b06f4839-d16a-4a61-9bb5-55b13f41e47f
product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6dLinked exactInspect raw assertion
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56409cec-5a1e-4450-aa42-641e459cc2af
product-43fae047c10c7188dd893c16176580df3d9e6f9ba4a3070fbce7d29c7e3e2d48Linked exactInspect raw assertion
cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c93821cf-3117-4763-8163-dd49f6d2ca8e
Affected-product evidence
Accepted scope and product mapping
52 canonical links · 1 source-reported links
vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-0b61a20dbab9097f6fb81a44ff1833985957ab4d849df056540d41f61a0fbcdf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
178406bc-95a0-496a-bbb3-217901d40668aa7687a3-a37b-4da6-82cf-563d013e155cd0ecb904-48a0-4d64-8030-2edc076d0c0ef22c4cad-522d-4058-9191-74a9ea666661vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1341d7da843bb30e28edc37d9755b3e50cf08c94281e5ccd20b146fc50aae38b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6f06d3ed-8d06-4711-8f9e-6d507c658d90e96fc439-cf91-480e-a995-ca9cdb12c14avendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-14111d2f45ac076e2d0fab551f2e4f27edcbeedc6fa87436fdfc0c56be1e56fb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
affcfa5a-ac33-4306-ab5c-fb21002bddabvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-181f01090952860a3c83b14fb597f21ba906037377a0b635b6b97b6cfbbe2c6e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
493a15e2-a969-4455-80dd-4128dd5f4774963a5127-b9b8-48b6-8fd4-e35bc411b23ba1a1b6ff-4a55-40b5-b7b0-e419ffdd5391c4885800-b380-4917-aa3c-4dcfd1ed90fde265ae9a-6e3e-468e-b091-58539c44c3f3vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1a9306a675712fb96b99645849deb869b89fddeb3e9b691d56df3ce1604e6fe5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2a90f76c-53a0-4345-8c4c-5eb37fd4658c5b7101b4-1ea1-4610-b981-0c7da3d476e9617a86c9-3f52-4cea-b1d1-cf097a879281vendor-d55b47b2745317860e139def3459e19d9b08135435764a68197c45036b2c0a7b · product-212d47c5af963e5c3aa6b05f4c9bed84d410f1ed5651403daaf3aa19bbcf8d60
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3110840a-3e8d-46eb-aa79-571daaccfc0063824099-d1b5-487d-9c58-bf668eb008dac9e70f6c-e116-4dbc-82e0-3aba07e1bd51vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2b6ca2326d5a8521120302483d8a49cf690ada497645b1dabd6326b0af90b535
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
69659703-4613-44b0-85d7-d32ed7b4818dvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-30e1260e81122258cf7fbaa6a590661af1ffb3d556ae33f222c5ea3f70587411
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8fda709e-fd54-44d1-b45d-e5ed6f28c8a3vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-3939b2bfa10af9f477c9c9ce0fef01b4a66135217a0ed2bdf98269d8c1ff8725
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ed0dcc5d-a24a-45f4-83c6-9d392a60faa9vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ea288ca2-f509-43c7-924e-52a6c6d19e92vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4522ebd6-a137-4914-b8a9-ec31ed121be2vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
63a11bfb-89f6-4f3e-9242-ba27daddc3b7vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3db18bc6b8ab9c044c383d7df0a90023d0b870d1ab18b593378eb054160b5167
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9a4ae697-50a8-4d6b-9813-42f1e7a66723vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-43fae047c10c7188dd893c16176580df3d9e6f9ba4a3070fbce7d29c7e3e2d48
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e22ef7fc-d99a-4ebd-b9f5-f88909d637devendor-b11a4917395b26fd126b980b37ee4e8efac1f353b7226f695b84e1eed8fff410 · product-45e667ca9592a8016b1e60d2c7b2f68269f96187c19a889834314c32b2a82180
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c74e7f0e-2420-4c11-afdf-055c260dca9avendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-467f77da28f6d584c339450ec9f6f4546312f7ede87d49cc14e8d6abf1f8f425
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
80ed362b-6579-4dd6-8f3d-97836a8b297cvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-59cc0b5ef6ceca92448eb2a79887cea0e3efe9418e85944802d907ef58d1b00f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a0841cc0-7d37-4efb-88c9-c7f3515e9b18vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5dea0658c22c58082000dbc1d02246b86f315239e42e442f2bf3e3d22eafbbda
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8cef123b-085b-4121-b7dd-60258a63f452vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5fd5fe773972a5181fe1344ac4e0c1e21794f0ebc1eca08c257db8268d5f8546
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
02be290c-5214-4e15-bdd0-7338de4f21a7vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-69b140db5f3721bf98d087280bcedbb088b2bf7253bd71972e6d75fa2d9b0027
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
da611f72-2016-423b-bd3f-0d8c5cfad7b1vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-69dafe4f729214312a333b1a16544a5f15a940ba5c03872c046470faba381ec5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5268bb85-3fde-4648-94ba-9a81557f578avendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-6a6ed7326a89afeec0956b2e8b528be770f821c6e7e7660d656abd2a6d6aa457
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7409a36f-8502-474a-892a-b32bf3cd0b8avendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
84c54922-7a29-4464-86ba-5d24472e1567vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-6d8e91e573fa3f7a843bac07003254455edfe9ad767e03ad91a075399442396f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
03d408d7-38b7-418c-b33d-9c509eb542d26722f58c-60d5-40fa-846f-61a666a9beb6a5dd39cc-0daf-4fe0-b76d-e83fa26b18bcd6ce696d-7330-4513-9b01-966214a68a08vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-71831900c48716a9a58f62030adc8c38252594aafc495820ffaabb02898c85a5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
379b1844-0051-4484-8939-54e2361115d8d6c53c96-a4bf-4f8c-bc28-1f7898799fc9vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7408bee14b201df56ba79a093a16ebcccdd09751b1d73782c2ea9e3f85eee87e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18e4267c-ddbe-4e1d-a1bc-37cdcc7b3743347061bf-903a-4f51-b712-359a8296090843279099-a529-40fa-bd54-4eb7f810567bfdf79a18-7b8c-4a10-8624-673e63e78d99vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
06eb2f17-7395-4335-9cd6-61963fe82ac57542f02f-5d23-4b30-8499-9bcebcd27ee6a5b4fec6-eed3-4340-9632-26f20261579avendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-79ab8a76dc8813281a68d0159b37b8f2b6f4a381b83b754ca3e9ca871f8e0da6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
45bc90e6-c13c-4e95-9c53-46b9a68a1b2fvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7c699e19a13f0273c993445d995a4520431edff8db1d821b2a216ecbcde3e979
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7fd1f1f1-0303-43a7-8a70-3d5608d870d9vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7e8b10c768949a77a8258aa0535fec62ae11890516ba88e91216f11c57ecef02
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3a08d352-5873-44bf-9b36-f9197380ce39vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6d71da2d-55c5-435d-8333-02c52af8ea16vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-84ef6de30bdd65a98e05d629523814af7aab0e6da595cb481574730265e7b4bd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
29461ea5-ccf0-416a-ba89-639ebec08ad15718e85f-f4b8-49ca-bfed-7612aba55d01e1ebed73-8c43-492d-aac2-155c8d4c6b55vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-90198fbd61598d38488d520b15a086d5c545d55a6f664f9ab3d5c0f5a5c239ed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9488bef2-b7c2-4567-9953-0f85891fc892vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-945e84ea7e458e0421c2b4a51bb1b0d7b1ef739c746ad63003ec75fbaa89af9d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2317e3da-5aeb-45c7-b7f9-e7bf362cd289vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-967a1bf85410dce3db878ea55227aa7679701f05106e1629b1749b0439bfa315
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0e1e621c-7d05-41c2-8941-71d9e8601427459eeeff-dd03-4920-a784-124c1e2449f2vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9f435847613ed9018416f1a900a608f4dd934d3156d59607c58b52ca2d1ecfd1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3b7f73a1-7498-4c9e-a49a-5ba9b9c05007vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-a6bffb301eb198294ecf3f2cf09cb4f7bc26e3320bac15bd2a4abfe4283dd284
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
70574dde-6e99-4adb-baee-7b828037b4b3e4218c46-ad9f-4052-8ee9-e5b4c84e5f54vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-a9b8857994572d5d62ec3361bb9cf6d6b9ed2a9b747716f6a517489acf47bb51
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
669669ff-8e33-472e-bfe5-3a719ef16e6evendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ac573a3f6fc9b0f04cb447fecf51c692205015afcb33997b2812f5f6e6c64504
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3dc0352a-2de7-438d-9a2e-b91c5949ce62vendor-03895055af21501a9d08c968f906b8b5da14112bde35699d61304768ec8bb3c0 · product-b283cbb17cb2605a2e2e0c5cdfd62e1544a27cc84f5584875dc41a84575cd246
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6f7aebcf-69f7-44e9-a19e-2b5e4121bdedvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cfc06987-f299-4858-ba76-d39e8c4bbb70vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
743cec1d-fe7d-4b77-8985-b16f4b5af7e7vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1a78a716-6023-418f-b226-4a070546e284236c9893-20b0-4bdb-b741-44ca15c74687cf6e2475-0540-4bdd-91b6-eb2d0a22e56bvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-caaa8e228e72c153d0b12fb5994e6a4efe7929e90f7500b9c3dea5c9245a4b54
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
56348eb9-b0a5-46d3-8bc7-dedf9b9c8b55vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-cba906812ace18556eb38b63d10f959a318fecf86d7a857508655d7528f4e6db
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3f0e9a3e-9be7-44b0-904a-b3b95919e20a76514c2c-3ec9-4dfd-979d-fbc1b8e60074f5f6782d-12d8-4419-bb2d-279cdf6136cfvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-cfe5d46cb1083fa06df42f506508992d8fbef448c68d6420b6889c47c808ab02
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18066815-59ef-41f9-87d5-621f82e923a6vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-d5a8b7c1bd67e05ed1b7b9780c8ce0ba33b8d70fa0f7ada40e3aacaef174065c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
96968344-2e43-453b-8628-4c24e00ff968vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-e8df9318cbbc972f5d886a638aeeb0426a6fdc5e024c770123efbc1c3e099aef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ff57426e-f876-4fd5-8181-53bf041f2becvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f0ef8dd19534f104401c9b628dfdbb30c81c43ad829e352071d1ee4598318724
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18a4fa6a-2762-4313-9cbb-0f7978a202bavendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6c42c54a-8593-4ef1-bb61-3718510ff58bvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f6f14489b90770f5fcf332bfe05780026ac83b5a028570dad28517167b27d8b7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
846e18bb-c108-4e22-a477-a16b83822370vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-fc149af9032ace9a010e9f89149c81bc45faeba303217af053928b26be955f3d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
157d17cb-3c2a-4f38-8111-f8085425683eCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
adedb2fb-9126-4671-beec-6bf2641af14bAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NAV:N/AC:M/Au:N/C:N/I:P/A:NCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:NCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:NDirect CVE/CNA normalized decisions
GitHub_M
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N- Validation
- Valid match
- Recomputed
- 6.9
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.