CISA KEV · catalog date Apr 6, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line…
Exploited in the wild (CISA KEV since Apr 6, 2022). NVD reports CVSS 3.1 7.8. EPSS estimates 99.3% exploit likelihood as of Jul 31, 2026.
As of Aug 27, 2026
Normalized restatement
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- State
- PUBLISHED
- Published
- Jan 26, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Inspect raw assertion
- Field
container- Value
- Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Sudo Heap-Based Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Sudo Heap-Based Buffer Overflow Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.3% probability · 99.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.992950000000; percentile 0.999350000000
FIRST EPSS · score date Jul 31, 2026 · 99.9th percentile · first observed Aug 1, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Inspect raw assertion
- Field
container- Value
- Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Sudo Heap-Based Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Sudo Heap-Based Buffer Overflow Vulnerability
99.3% probability · 99.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.992950000000; percentile 0.999350000000
Applicability
Cited product scope
Grouped from 22 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
32 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-2751efd0fada5c60a30a4777d39da6fdd7fbf63cb63a89c17a66e90968712d70Linked exactInspect raw assertion
cpe:2.3:a:beyondtrust:privilege_management_for_mac:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 21.1.1
- Match ID
38a18800-4bb0-46a1-bd9d-78ec7a07e7b9
product-f076ac19f6b73edb4a883d4f44d95ea6d7c43c4a707246e0a9457b16adf7e821Linked exactInspect raw assertion
cpe:2.3:a:beyondtrust:privilege_management_for_unix\/linux:*:*:*:*:basic:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 10.3.2-10
- Match ID
48dc5b58-0e31-480e-bf05-787287dff42b
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07b237a9-69a3-4a9c-9da0-4e06bd37ae73
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
36d96259-24bd-44e2-96d9-78ce1d41f956
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e460aa51-fcda-46b9-ae97-e6676aa5e194
product-3f80430ccc7ac22549c5a4306d50db799be7d37c7a834ef40f81d303bf2d0c4eLinked exactInspect raw assertions
cpe:2.3:a:mcafee:web_gateway:9.2.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1e014e1e-0013-434f-9c59-178dac089687
cpe:2.3:a:mcafee:web_gateway:10.0.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3ce836fd-3453-4277-bc18-a4868c183f42
cpe:2.3:a:mcafee:web_gateway:8.2.17:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d2039589-b543-49b6-ac5f-74c4253b416d
product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79Linked exactInspect raw assertion
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3a756737-1cc4-42c2-a4df-e1c893b4e2d5
product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bfLinked exactInspect raw assertion
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5c2089ee-5d7f-47ec-8ea5-0f69790564c4
product-b96bd9c5f25fe809238d4145773458d6ff936886a379c046bfbe8070415bf846Linked exactInspect raw assertion
cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a3c19813-e823-456a-b1ce-ec0684ce1953
product-8317a20ee0e78d88ddaa53ccddf425e1ad29ba84bdf8d43df4267e569bf8ceeeLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0a4d418d-b526-46b9-b439-e1963bf88c0a
product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096Linked exactInspect raw assertion
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e7cf3019-975d-40bb-a8a4-894e62bd3797
product-5a693745af4649c25ce4328cad32bd84b52deae2cb334b0ab74065310c17e710Linked exactInspect raw assertion
cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2d814be-93ec-42ef-88c5-ea7e7df07be5
product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8Linked exactInspect raw assertion
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a6e9ef0c-afa8-4f7b-9fdc-1e0f7c26e737
product-3cf8ac092daf11945696bec8cc9c89ecfededa385f631d11839f95c38decf78dLinked exactInspect raw assertions
cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 10.4.0.1.0; through including 10.4.0.3.1
- Match ID
29a3f7ef-2a69-427f-9f75-dddbee34ba2b
cpe:2.3:a:oracle:communications_performance_intelligence_center:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 10.3.0.0.0; through including 10.3.0.2.1
- Match ID
977ca754-6ce0-4fcb-9683-d81b7a15449d
product-9d747d88b46c25be3e686516516fba0d4d0d98082d4fa6bacb54a8ff40749e0eLinked exactInspect raw assertion
cpe:2.3:h:oracle:micros_compact_workstation_3:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7da4f0ad-b8a4-4eb9-a220-feec9b147d3c
product-08e2e75bfe68d3d5263809d6f10be96f85eae73360be6158b1a258be73c02a39Linked exactInspect raw assertion
cpe:2.3:o:oracle:micros_compact_workstation_3_firmware:310:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1ce3ff32-e472-4e90-9de5-803ad6fd9e27
product-7c0f67bd5d346ecdad20c01f2772053eee096dc618718836d94969daa13dab33Linked exactInspect raw assertion
cpe:2.3:h:oracle:micros_es400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2bbd07a-4731-41d1-ab66-77082951d99c
product-59b3503caa00d1c5951731565f064fb58339616a7c4120286c00eaf820d9a2a2Linked exactInspect raw assertion
cpe:2.3:o:oracle:micros_es400_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 400; through including 410
- Match ID
9aa5297b-05df-4a23-b684-60f2107339b0
product-7fce2881907a9ec7b70e808013cab0b0958e8ac50360f684000a9b55c8cc5714Linked exactInspect raw assertion
cpe:2.3:h:oracle:micros_kitchen_display_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1424af8-9337-427b-b6fa-c5eb8b201fb7
product-c2cc516d23a52f82b3e64af58eb6ec4c5f96ed319b53c9d107ce75dbf84b4896Linked exactInspect raw assertion
cpe:2.3:o:oracle:micros_kitchen_display_system_firmware:210:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
57e6a365-f04f-4991-888f-d8e9391a9857
product-d995dc1e0dbad8d9a46a87614a2b85e953ede682903b22d5660097a9a2420f31Linked exactInspect raw assertion
cpe:2.3:h:oracle:micros_workstation_5a:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f607ba3f-246f-42be-9ebd-a2cae098c0c2
product-5d799810f2a06bda718108469201656c98221b05ea047f30149865288c6c7b9cLinked exactInspect raw assertion
cpe:2.3:o:oracle:micros_workstation_5a_firmware:5a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c78fdd3a-f241-4172-8725-7d51d8e705e7
product-b5495cf27ee432851bfadee1b1db04a79eb6e0396f0b1de13428dedbc0d33e71Linked exactInspect raw assertion
cpe:2.3:h:oracle:micros_workstation_6:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82a66154-5df0-43ff-9f70-1221d3e6f919
product-326f04a2cd5f4638570c0f6a89c7638865aac4b44d784f7766f8730d3143cfc8Linked exactInspect raw assertion
cpe:2.3:o:oracle:micros_workstation_6_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 610; through including 655
- Match ID
d59535d6-8d64-4b8f-bc1b-5846600c9f81
product-79a06bf57cd8920f0172aca556cef15fa4fb89952148235414d3f4ca00701f72Linked exactInspect raw assertion
cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 7.4.0; through including 7.7.1
- Match ID
26f05f85-7458-4c8f-b93f-93c92e506a40
Affected-product evidence
Accepted scope and product mapping
24 canonical links · 1 source-reported links
vendor-87e8a7dc5e23a6238c807dfa0cf873005b3b541cc12ee1f21993211df07f0fe0 · product-01f1349b4669bf7825f50dc0df6f4d62261777d7ccff2017f192e1365690e2d4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ddd0d59d-b700-48cd-8d31-58db199f79b4vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-08e2e75bfe68d3d5263809d6f10be96f85eae73360be6158b1a258be73c02a39
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6766d01e-33fd-4592-a5af-d72166f8142fvendor-c65f06a74a92d3c757d3f4bef8da4044306168b1e57a0c1af5a3ee0251e11f5c · product-2751efd0fada5c60a30a4777d39da6fdd7fbf63cb63a89c17a66e90968712d70
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a5a7694a-b456-4437-a815-09e90afe3e16vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-326f04a2cd5f4638570c0f6a89c7638865aac4b44d784f7766f8730d3143cfc8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
73cd4b91-f530-4bcf-885d-671d5144a4e5vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
51da82d5-8cdd-429d-8c0b-f800cb4c16da5e3ee6bb-b120-4113-9a55-d7d262696da7vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-3cf8ac092daf11945696bec8cc9c89ecfededa385f631d11839f95c38decf78d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d087430c-f8ad-4167-b164-fbdf57fa890ee512381e-0902-40b2-b75a-0ffa8780aa34vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
10371bae-18e7-4d47-aadf-8bf5d5e76418vendor-db57b0eb77a6268d576ee890ec07148fa2ef106f818f9ebb235bd9a85bc69bdb · product-3f80430ccc7ac22549c5a4306d50db799be7d37c7a834ef40f81d303bf2d0c4e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2e5dbc6c-2000-421c-ac61-9afdf9289cde44efeab7-6264-4ac0-90e8-af948125ee5485839482-50f8-4c10-bf3f-eaef431d6c76vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-59b3503caa00d1c5951731565f064fb58339616a7c4120286c00eaf820d9a2a2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0960ffb8-f7a5-43f6-8287-9961eeed5e61vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-5a693745af4649c25ce4328cad32bd84b52deae2cb334b0ab74065310c17e710
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9b0195e7-04d7-4d92-9919-616393796d0evendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5d799810f2a06bda718108469201656c98221b05ea047f30149865288c6c7b9c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
360e9ae6-cc59-4821-87a2-2241622afc63vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1286634c-0e73-4730-bd55-ef43dc7e5476vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-79a06bf57cd8920f0172aca556cef15fa4fb89952148235414d3f4ca00701f72
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
332a22e0-a901-4420-969c-0c5a650417bevendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bda4f9ae-fa3a-4923-bf23-730791a06d6fvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-8317a20ee0e78d88ddaa53ccddf425e1ad29ba84bdf8d43df4267e569bf8ceee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f348e563-7e75-4f9f-8f16-f2690f4490bbvendor-87e8a7dc5e23a6238c807dfa0cf873005b3b541cc12ee1f21993211df07f0fe0 · product-9e7950015409147048cfcb930485d1130e58ccb848ff62dd1f22eb916efd50f8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
eb078d58-0bfc-4ba6-acd9-4f55cc1fee67vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8c2e3c24-d809-4465-8f64-f0cef3d1e3dcvendor-87e8a7dc5e23a6238c807dfa0cf873005b3b541cc12ee1f21993211df07f0fe0 · product-a52596841ac7acbff9040aed9ba37a20f22be24056b9314c70f15dc59367975b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f2986a63-fb5e-4923-9dfe-6ae849d9d14avendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b96bd9c5f25fe809238d4145773458d6ff936886a379c046bfbe8070415bf846
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4863772a-aa6a-4b62-8707-51bbc7ab50fbvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c2cc516d23a52f82b3e64af58eb6ec4c5f96ed319b53c9d107ce75dbf84b4896
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cbeb008e-53ec-4a75-b234-7df835451be2vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
99be40cd-e398-4808-a554-f3d5f542d847af5c7fc4-b6c3-4e11-9c55-dd3594f7a3cevendor-87e8a7dc5e23a6238c807dfa0cf873005b3b541cc12ee1f21993211df07f0fe0 · product-d5e7327cd9f37e98fdd6f2e2f210acb2b1c294b310eb05218613d73304f94ab6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
147c233e-f164-4217-af2a-e0936b416cf2vendor-5a7066a47077266a770e58faac1bf034a7630fa167a90175d323b5b90214031c · product-ec6c475b3590320e51239c21e46ed829733b5cf1c09b72544d59a3d581e3c831
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
22686a2b-17d2-4e6c-bf1d-3a5d6d6dbf7491a29224-996d-472a-96b8-9bd067c97940e08711e4-d631-45a2-9229-56e7fa8bae67fbc0f014-1bdf-498b-b8c5-480d1aa07e04vendor-c65f06a74a92d3c757d3f4bef8da4044306168b1e57a0c1af5a3ee0251e11f5c · product-f076ac19f6b73edb4a883d4f44d95ea6d7c43c4a707246e0a9457b16adf7e821
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9656f7de-7ad7-49e9-b728-cdad621d0e2aCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fd895a15-6c4c-4781-97bf-0df7d93af6c8Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 7.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.