CISA KEV · catalog date Apr 1, 2025 · first observed Aug 6, 2026
Evidence dossier
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Exploited in the wild (CISA KEV since Apr 1, 2025). NVD reports CVSS 3.1 9.8. EPSS estimates 99.9% exploit likelihood as of Aug 6, 2026.
As of Aug 27, 2026
Normalized restatement
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
- State
- PUBLISHED
- Published
- Mar 10, 2025
- Updated
- Oct 29, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAapacheOriginal evidence ↗
Record text: Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Inspect raw assertion
- Field
container- Value
- Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Apache Tomcat Path Equivalence Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Tomcat Path Equivalence Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.93% probability · 99.97th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999250000000; percentile 0.999680000000
FIRST EPSS · score date Aug 6, 2026 · 100th percentile · first observed Aug 6, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Inspect raw assertion
- Field
container- Value
- Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Apache Tomcat Path Equivalence Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Tomcat Path Equivalence Vulnerability
99.93% probability · 99.97th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999250000000; percentile 0.999680000000
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
5 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.0.0-M1", "versionType": "semver", "lessThanOrEqual": "11.0.2"}, {"status": "affected", "version": "10.1.0-M1", "versionType": "semver", "lessThanOrEqual": "10.1.34"}, {"status": "affected", "version": "9.0.0.M1", "versionType": "semver", "lessThanOrEqual": "9.0.98"}, {"status": "affected", "version": "8.5.0", "versionType": "semver", "lessThanOrEqual": "8.5.100"}, {"status": "unknown", "version": "3", "lessThan": "8.5.0", "versionType": "semver"}, {"status": "unknown", "version": "10.0.0-M1", "versionType": "semver", "lessThanOrEqual": "10.0.27"}]product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441Linked exactInspect raw assertions
cpe:2.3:a:apache:tomcat:11.0.0:milestone23:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8a28c2e2-b7bc-46ce-94e4-ae3ef172aa47
cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f6bd4180-d3e8-42ab-96b1-3869ecf47f6c
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 9.0.99
- Match ID
eeadc2e0-4a95-47b8-b506-d8e677838967
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 10.1.1; through excluding 10.1.35
- Match ID
108d9f43-5a29-475e-9ee2-66ce8899b318
cpe:2.3:a:apache:tomcat:11.0.0:milestone21:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7914d26b-cbd6-4846-9bd3-403708d69319
cpe:2.3:a:apache:tomcat:11.0.0:milestone13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb557e88-fa9d-4b69-aa6f-eaee7f9b01ac
cpe:2.3:a:apache:tomcat:11.0.0:milestone14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
72d3c6f1-84fa-4f82-96c1-9a8da1c1f30f
cpe:2.3:a:apache:tomcat:10.1.0:milestone9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6284b74a-1051-40a7-9d74-380feeec3f88
cpe:2.3:a:apache:tomcat:11.0.0:milestone17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ecbbc1f1-c86b-40af-b740-a99f6b27682a
cpe:2.3:a:apache:tomcat:10.1.0:milestone16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
81b27c03-d626-42ec-ae4e-1e66624908e3
cpe:2.3:a:apache:tomcat:11.0.0:milestone18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9d2206b2-f3ff-43f2-b3e2-3caac64c691d
cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7cb9d150-eed6-4ae9-bcbe-48932e50035e
cpe:2.3:a:apache:tomcat:10.1.0:milestone20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ed30e850-c475-4133-bde3-74cb3768d787
cpe:2.3:a:apache:tomcat:10.1.0:milestone8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ce1a9030-b397-4ba6-8e13-da1503872ddb
cpe:2.3:a:apache:tomcat:11.0.0:milestone10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
57088bdd-a136-45ef-a8a1-2ebf79cec2ce
cpe:2.3:a:apache:tomcat:11.0.0:milestone3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1f981f5-035a-4edd-8a9f-481ee8bc7ff7
cpe:2.3:a:apache:tomcat:11.0.0:milestone4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
03a171af-2ec8-4422-912c-547cdb58caaa
cpe:2.3:a:apache:tomcat:11.0.0:milestone1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1aa7ff6-e8e7-4bf6-983e-0a99b0183008
cpe:2.3:a:apache:tomcat:10.1.0:milestone13:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fc64bb57-4912-481e-ae8d-c8fcd36142bb
cpe:2.3:a:apache:tomcat:11.0.0:milestone9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 47
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
98792138-dd56-42df-9612-3bdc65eec117
cpe:2.3:a:apache:tomcat:11.0.0:milestone2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2aad52ce-94f5-4f98-a027-9a7e68818cb6
cpe:2.3:a:apache:tomcat:11.0.0:milestone7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 45
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f50942f-df54-46c0-8371-9a476dd3eea3
cpe:2.3:a:apache:tomcat:10.1.0:milestone12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
64668ccf-dbc9-442d-9e0f-fd40e1d0ddb7
cpe:2.3:a:apache:tomcat:11.0.0:milestone16:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
02a84634-a8f2-4ba9-b9f3-bef36aec5480
cpe:2.3:a:apache:tomcat:10.1.0:milestone15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
919c16bd-79a7-4597-8d23-2cbded2ef615
cpe:2.3:a:apache:tomcat:10.1.0:milestone19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5571f54a-2eac-41b6-bda9-7d33cfe97f70
cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e321fb4-0b0c-497a-bb75-909d888c93cb
cpe:2.3:a:apache:tomcat:11.0.0:milestone12:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0092fb35-3b00-484f-a24d-7828396a4ff6
cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b0cae57-af7a-40e6-9519-f5c9f422c1be
cpe:2.3:a:apache:tomcat:11.0.0:milestone6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 44
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49350a6e-5e1d-45b2-a874-3b8601b3adcc
cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9846609d-51fc-4cdd-97b3-8c6e07108f14
cpe:2.3:a:apache:tomcat:11.0.0:milestone11:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b32d1d7a-a04f-444e-8f45-bb9a9e4b0199
cpe:2.3:a:apache:tomcat:11.0.0:milestone15:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3521c81b-37d9-48fc-9540-d0d333b9a4a4
cpe:2.3:a:apache:tomcat:10.1.0:milestone6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d334103f-f64e-4869-bcc8-670a5afcc76c
cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d402b5d-5901-43eb-8e6a-ecbd512ce367
cpe:2.3:a:apache:tomcat:11.0.0:milestone25:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e6282085-5716-4874-b0b0-180ecdee128f
cpe:2.3:a:apache:tomcat:11.0.0:milestone5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 43
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
538e68c4-0ba4-495f-aef8-4ef6ee7963cf
cpe:2.3:a:apache:tomcat:10.1.0:milestone14:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49b43bfd-6b6c-4e6d-a9d8-308709ddfb44
cpe:2.3:a:apache:tomcat:11.0.0:milestone19:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0495a538-4102-40d0-a35c-0179cfd52a9d
cpe:2.3:a:apache:tomcat:11.0.0:milestone8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 46
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d12c2c95-b79f-4aa4-8ce3-99a3ee7991ab
cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33c71ae1-b38e-4783-bac2-3cda7b4d9eba
cpe:2.3:a:apache:tomcat:10.1.0:milestone17:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bd81405d-81a5-4683-a355-b39c912dad2d
cpe:2.3:a:apache:tomcat:11.0.0:milestone20:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
77ba6600-0890-4ba1-b447-ec1746bab4fd
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 11.0.1; through excluding 11.0.3
- Match ID
b7e3d41f-f7c8-4bab-a80b-287facb0f7e4
cpe:2.3:a:apache:tomcat:11.0.0:milestone24:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
069b0d8e-8223-4c4e-a834-c6235d6c3450
cpe:2.3:a:apache:tomcat:10.1.0:milestone18:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2dce3576-86bc-4bb8-a5fb-1274744dfd7f
cpe:2.3:a:apache:tomcat:10.1.0:milestone7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
941fcf7b-ffb6-4967-95c7-bb3d32c73daf
cpe:2.3:a:apache:tomcat:11.0.0:milestone22:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
123c6285-03be-49fc-b821-8bdb25d02863
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa6feec2-9f11-4643-8827-749718254fed
product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029Linked exactInspect raw assertion
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
95ba156c-c977-4f0c-8dfb-3fae9cc8c02d
product-ac128f79df6958432aba953aa4fde55d70b2ccbfc258439c013b541010526631Linked exactInspect raw assertion
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad7447bc-f315-4298-a822-549942fc118b
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.