CISA KEV · catalog date Mar 4, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2025-22225
VMware ESXi contains an arbitrary write vulnerability.
Exploited in the wild (CISA KEV since Mar 4, 2025). NVD reports CVSS 3.1 8.2. EPSS estimates 1.0% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
- State
- PUBLISHED
- Published
- Mar 4, 2025
- Updated
- Aug 4, 2026
- Evidence coverage
- 85%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: VMware ESXi Arbitrary Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- VMware ESXi Arbitrary Write Vulnerability
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAvmwareOriginal evidence ↗
Record text: VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Inspect raw assertion
- Field
container- Value
- VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 1% probability · 60.18th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.009970000000; percentile 0.601770000000
FIRST EPSS · score date Aug 27, 2026 · 60.2th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Aug 4, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
VMware ESXi Arbitrary Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- VMware ESXi Arbitrary Write Vulnerability
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Inspect raw assertion
- Field
container- Value
- VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
1% probability · 60.18th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.009970000000; percentile 0.601770000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
8 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "5.x, 4.5.x"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "8.0", "lessThan": "ESXi80U3d-24585383", "versionType": "custom"}, {"status": "affected", "version": "8.0", "lessThan": "ESXi80U2d-24585300", "versionType": "custom"}, {"status": "affected", "version": "7.0", "lessThan": "ESXi70U3s-24585291", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "3.x, 2.x"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "5.x, 4.x, 3.x, 2.x"}]product-29d7e06677052d6292d0854ba656869395ea8e26a3dfe12b466a234813f9d5c3Linked exactInspect raw assertion
cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
31a7bb38-3238-413e-9736-f1a165d40867
product-23a252291fc54c7d970af8a89ad978d1de708dae5df8285a6f74b35881b5bd32Linked exactInspect raw assertions
cpe:2.3:o:vmware:esxi:7.0:update_3o:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
da4e9185-44ba-41e6-8600-c8616e199334
cpe:2.3:o:vmware:esxi:8.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a1a402a-9262-4b97-a0b7-e5ae045e394d
cpe:2.3:o:vmware:esxi:7.0:update_3k:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f965d853-ee4a-41f5-840b-2d009acc9754
cpe:2.3:o:vmware:esxi:7.0:update_3d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80a0dd2e-f1cc-413b-91f9-e3986011a0a0
cpe:2.3:o:vmware:esxi:8.0:a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fe44b379-9943-4dd1-8514-26f87482afa8
cpe:2.3:o:vmware:esxi:7.0:update_3m:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9fb5738f-27e4-42c6-bd1b-f7f66a7ef0a6
cpe:2.3:o:vmware:esxi:7.0:beta:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f030a666-1955-438b-8417-5c294905399f
cpe:2.3:o:vmware:esxi:8.0:update_2b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b16ed7c1-9881-452a-8be0-eddeaefe3d7b
cpe:2.3:o:vmware:esxi:7.0:update_3p:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f50302bb-b950-4178-a109-358393e0a50a
cpe:2.3:o:vmware:esxi:7.0:update_3i:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
acaa9494-5248-4b01-8bc1-c38ab615ffd7
cpe:2.3:o:vmware:esxi:7.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5cba6b5a-f345-41d1-8aa0-e5f274a2d8fb
cpe:2.3:o:vmware:esxi:7.0:update_1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c8db7f6-5765-4355-b30e-9cac39eca5d9
cpe:2.3:o:vmware:esxi:8.0:update_1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f8767f7-7c3d-457d-9eac-e8a30796f751
cpe:2.3:o:vmware:esxi:7.0:update_3j:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf12014b-bf2b-42ef-b70c-59cda8e2176f
cpe:2.3:o:vmware:esxi:8.0:update_1a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
29af8474-2d7a-4c5a-82b9-7a873ad90c2e
cpe:2.3:o:vmware:esxi:7.0:update_3r:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
78604fe5-510f-4979-b2e3-d36b3083224a
cpe:2.3:o:vmware:esxi:7.0:update_1b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b7619c16-5306-4c4a-88e8-e80876635f66
cpe:2.3:o:vmware:esxi:8.0:update_1d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
18fd08c9-5895-4bf4-bbe0-c2dda5f6b836
cpe:2.3:o:vmware:esxi:7.0:update_1a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a790d41e-b398-4233-9ec7-cf5be2bc3161
cpe:2.3:o:vmware:esxi:7.0:update_2c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c202879-9230-4e1d-bab8-4fb7ce4bbc24
cpe:2.3:o:vmware:esxi:7.0:update_3n:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fc3668a6-262b-42bf-9e90-28baa9bb3347
cpe:2.3:o:vmware:esxi:7.0:update_3c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2f831a7-544e-4b45-ba49-7f7a0234579c
cpe:2.3:o:vmware:esxi:7.0:update_3g:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e75b2f03-702e-4359-9bb2-e234f1dc38c8
cpe:2.3:o:vmware:esxi:7.0:update_1e:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e6de184-35c8-4a13-91d4-4b43e9f0168c
cpe:2.3:o:vmware:esxi:8.0:update_2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
360c1b71-5360-4379-b0de-63bb8f5e6da2
cpe:2.3:o:vmware:esxi:8.0:update_2c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ed92209f-fbd6-43f9-9a15-3842b139fcc9
cpe:2.3:o:vmware:esxi:8.0:update_3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6b701151-1b57-4e2d-a9ab-586facea2385
cpe:2.3:o:vmware:esxi:8.0:b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2a797377-8945-4d75-aa68-a768855e5842
cpe:2.3:o:vmware:esxi:7.0:update_2e:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
39817170-5c45-4f8a-916d-81b7352055dd
cpe:2.3:o:vmware:esxi:7.0:update_3e:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c77771b2-bc64-47a5-b6db-9cbcc4456b67
cpe:2.3:o:vmware:esxi:7.0:update_2d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc6dc107-5142-4155-a33b-d5be72e9ed38
cpe:2.3:o:vmware:esxi:7.0:update_2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d3e3a02d-6c1e-4de8-b845-60f53c056f32
cpe:2.3:o:vmware:esxi:8.0:update_1c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7781a2ca-d927-48cd-9932-ae42b7ba1efe
cpe:2.3:o:vmware:esxi:7.0:update_1d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1e4de8c7-72fb-4bec-ad9e-378786295011
cpe:2.3:o:vmware:esxi:8.0:update_3b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4230b9aa-9e0c-4ae2-814d-8dd641394879
cpe:2.3:o:vmware:esxi:7.0:update_3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4adc3cff-7415-46a5-817a-2f053b261e8c
cpe:2.3:o:vmware:esxi:8.0:c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79d84d76-54be-49e9-905c-7d65b4b42d68
cpe:2.3:o:vmware:esxi:7.0:update_1c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
238e7af4-722b-423d-abb1-424286b06715
cpe:2.3:o:vmware:esxi:7.0:update_3q:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bcca4a31-1291-4fb4-9fa5-d2ccd086d660
cpe:2.3:o:vmware:esxi:7.0:update_3f:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
86de9ce6-f6c0-47d2-b3ab-34852a8b9603
cpe:2.3:o:vmware:esxi:8.0:update_3c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2fa150b-93e4-44d2-bf6d-347085a95776
cpe:2.3:o:vmware:esxi:7.0:update_3l:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba7b7313-ff53-43c9-af4d-b639053d3fa3
cpe:2.3:o:vmware:esxi:7.0:update_2a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
12d385f0-db2b-4802-ad0e-31441da056b9
product-d3deac29ab6bd35c48c3c775587f94cbece614f7e514c1ec2f6475a12c21ec81Linked exactInspect raw assertions
cpe:2.3:a:vmware:telco_cloud_infrastructure:3.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d11103a7-6ab5-4e78-be11-bc2a04a09f19
cpe:2.3:a:vmware:telco_cloud_infrastructure:2.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7e46a694-8698-4283-9e25-01f222b63e9a
cpe:2.3:a:vmware:telco_cloud_infrastructure:2.7:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9a045567-2563-4539-8e95-361087cb7762
cpe:2.3:a:vmware:telco_cloud_infrastructure:2.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59b9476f-e5e7-46b6-ac38-4630d0933462
product-f33a9924ca675fab005c67daa6024da2d60a3504bfa15dcb96775f36535e19d7Linked exactInspect raw assertions
cpe:2.3:a:vmware:telco_cloud_platform:4.0.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0f6e30f8-b977-40a5-9e45-89b5c5e59170
cpe:2.3:a:vmware:telco_cloud_platform:4.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
448206aa-a023-4aa1-98fd-35bc2a2ab2b5
cpe:2.3:a:vmware:telco_cloud_platform:2.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b5f8d61f-6e8b-4ee3-91de-eba6ff7d289e
cpe:2.3:a:vmware:telco_cloud_platform:3.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fc33d39a-5760-467e-8284-f4e5d8082bbd
cpe:2.3:a:vmware:telco_cloud_platform:2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c5f01d7-2675-4d09-b52b-b02d0ef52aea
cpe:2.3:a:vmware:telco_cloud_platform:5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d6b84f65-2e52-4445-8f97-2729b84b18e3
cpe:2.3:a:vmware:telco_cloud_platform:2.7:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1e94d58-26a0-4e84-8cad-f8cdb6707642
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.