{
    "bomFormat": "CycloneDX",
    "specVersion": "1.5",
    "serialNumber": "urn:uuid:493e5f23-5c3b-45ba-a931-cda115442d70",
    "version": 1,
    "metadata": {
        "timestamp": "2025-01-16T00:00:00Z",
        "authors": [
            {
                "name": "Connext Security Team",
                "email": "security@rti.com"
            }
        ],
        "component": {
            "type": "framework",
            "bom-ref": "Connext Pro",
            "supplier": {
                "name": "Real-Time Innovations, Inc. (RTI)",
                "url": [
                    "https://www.rti.com"
                ]
            },
            "name": "Connext Professional",
            "version": "7.3.1.6"
        },
        "properties": [
            {
                "name": "last_updated",
                "value": "2026-08-29T00:07:28Z"
            }
        ]
    },
    "vulnerabilities": [
        {
            "bom-ref": "CVE-2011-1145",
            "id": "CVE-2011-1145",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1145"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2011-1145&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&version=3.1"
                    },
                    "score": 7.8,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2011-1145&vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)&version=2"
                    },
                    "score": 4.6,
                    "severity": "medium",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:L/AC:L/Au:N/C:P/I:P/A:P"
                }
            ],
            "cwes": [
                120
            ],
            "description": "The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.",
            "published": "2019-11-14T02:15:10Z",
            "updated": "2024-11-21T01:25:39Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not call the impacted APIs",
                "firstIssued": "2024-06-12T13:10:44.519000Z",
                "lastUpdated": "2024-08-05T11:53:38.915000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-203"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-593529"
                }
            ]
        },
        {
            "bom-ref": "CVE-2012-2657",
            "id": "CVE-2012-2657",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-2657"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2012-2657&vector=(AV:L/AC:L/Au:N/C:N/I:N/A:P)&version=2"
                    },
                    "score": 2.1,
                    "severity": "low",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:L/AC:L/Au:N/C:N/I:N/A:P"
                }
            ],
            "cwes": [
                119
            ],
            "description": "Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue would not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker, although it seems likely that other, more serious issues would also be exposed, and this issue might not cross privilege boundaries in that context.",
            "published": "2012-08-31T18:55:00Z",
            "updated": "2024-11-21T01:39:23Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The code that triggers the vulnerability is not present in Connext.",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-169235"
                }
            ]
        },
        {
            "bom-ref": "CVE-2018-7409",
            "id": "CVE-2018-7409",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-7409"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2018-7409&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv3",
                    "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2018-7409&vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&version=2"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P"
                }
            ],
            "cwes": [
                119
            ],
            "description": "In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.",
            "published": "2018-02-22T18:29:00Z",
            "updated": "2024-11-21T04:12:05Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The code that triggers the vulnerability is not present in Connext.",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-148319"
                }
            ]
        },
        {
            "bom-ref": "CVE-2020-24370",
            "id": "CVE-2020-24370",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24370"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2020-24370&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2020-24370&vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&version=2"
                    },
                    "score": 5.0,
                    "severity": "medium",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P"
                }
            ],
            "cwes": [
                191
            ],
            "description": "ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).",
            "published": "2020-08-17T17:15:13Z",
            "updated": "2024-11-21T05:14:41Z",
            "analysis": {
                "state": "not_affected",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-146889"
                }
            ]
        },
        {
            "bom-ref": "CVE-2020-24371",
            "id": "CVE-2020-24371",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24371"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2020-24371&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2020-24371&vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&version=2"
                    },
                    "score": 5.0,
                    "severity": "medium",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P"
                }
            ],
            "cwes": [
                763
            ],
            "description": "lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.",
            "published": "2020-08-17T17:15:13Z",
            "updated": "2024-11-21T05:14:41Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The code that triggers the vulnerability is not present in Connext.",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-142250"
                }
            ]
        },
        {
            "bom-ref": "CVE-2021-3520",
            "id": "CVE-2021-3520",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3520"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2021-3520&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2021-3520&vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)&version=2"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P"
                }
            ],
            "cwes": [
                190,
                787
            ],
            "description": "There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.",
            "published": "2021-06-02T13:15:13Z",
            "updated": "2024-11-21T06:21:44Z",
            "analysis": {
                "state": "not_affected",
                "justification": "protected_at_runtime",
                "response": [
                    "update"
                ],
                "detail": "We never pass an outputSize < 0 (see fix under https://github.com/lz4/lz4/pull/972/commits/8301a21773ef61656225e264f4f06ae14462bca7) . We always sanitize the passed outputSize parameter in all current usages.",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-177195"
                }
            ]
        },
        {
            "bom-ref": "CVE-2021-43519",
            "id": "CVE-2021-43519",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43519"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2021-43519&vector=AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H&version=3.1"
                    },
                    "score": 5.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2021-43519&vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)&version=2"
                    },
                    "score": 4.3,
                    "severity": "medium",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:N/A:P"
                }
            ],
            "cwes": [
                674
            ],
            "description": "Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.",
            "published": "2021-11-09T13:15:08Z",
            "updated": "2024-11-21T06:29:20Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The impacted code is not reachable in the product",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-189532"
                }
            ]
        },
        {
            "bom-ref": "CVE-2021-44647",
            "id": "CVE-2021-44647",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44647"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2021-44647&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&version=3.1"
                    },
                    "score": 5.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2021-44647&vector=(AV:L/AC:L/Au:N/C:N/I:N/A:P)&version=2"
                    },
                    "score": 2.1,
                    "severity": "low",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:L/AC:L/Au:N/C:N/I:N/A:P"
                }
            ],
            "cwes": [
                843
            ],
            "description": "Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.",
            "published": "2022-01-11T13:15:07Z",
            "updated": "2024-11-21T06:31:18Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The code that triggers the vulnerability is not present in Connext.",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-194232"
                }
            ]
        },
        {
            "bom-ref": "CVE-2021-45985",
            "id": "CVE-2021-45985",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45985"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2021-45985&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&version=3.1"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                787
            ],
            "description": "In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.",
            "published": "2023-04-10T09:15:07Z",
            "updated": "2024-11-21T06:33:25Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The code that triggers the vulnerability is not present in Connext.",
                "firstIssued": "2023-04-20T20:18:32.307000Z",
                "lastUpdated": "2023-07-17T10:50:34.215000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-95"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-513829"
                }
            ]
        },
        {
            "bom-ref": "CVE-2022-28805",
            "id": "CVE-2022-28805",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28805"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2022-28805&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H&version=3.1"
                    },
                    "score": 9.1,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2022-28805&vector=(AV:N/AC:L/Au:N/C:P/I:N/A:P)&version=2"
                    },
                    "score": 6.4,
                    "severity": "medium",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:P"
                }
            ],
            "cwes": [
                125
            ],
            "description": "singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.",
            "published": "2022-04-08T06:15:07Z",
            "updated": "2024-11-21T06:57:57Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The code path that leads to the vulnerability is not reachable in our usage of Lua.",
                "firstIssued": "2023-01-16T12:06:31.575000Z",
                "lastUpdated": "2023-01-24T12:13:58.073000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-50"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-203400"
                }
            ]
        },
        {
            "bom-ref": "CVE-2022-31631",
            "id": "CVE-2022-31631",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31631"
            },
            "ratings": [
                {
                    "source": {
                        "name": "security@php.net"
                    },
                    "score": 9.1,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                }
            ],
            "cwes": [
                74
            ],
            "description": "In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.",
            "published": "2025-02-12T22:15:29Z",
            "updated": "2025-07-02T21:35:56Z",
            "analysis": {
                "state": "not_affected",
                "justification": "protected_at_runtime",
                "detail": "This issue affects the SQLite Driver used by PHP. The vulnerability does not originate from the SQLite3 library itself, but from the way it is being used. The sqlite3_snprintf() function from the SQLite3 library expects an int parameter to specify the buffer size. However, the PHP SQLite driver passes a size_t value, which on a 64-bit system can be larger than the maximum value of an int, leading to a potential overflow. Connext Pro does not directly call sqlite3_snprintf(). This function is only invoked via the SQLite3 library, which correctly manages its buffer sizes to prevent the integer overflow described, ensuring that this vulnerability is not applicable.",
                "firstIssued": "2025-07-10T13:37:13Z",
                "lastUpdated": "2025-07-10T13:37:13Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-375"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-707596"
                }
            ]
        },
        {
            "bom-ref": "CVE-2022-33099",
            "id": "CVE-2022-33099",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33099"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2022-33099&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&version=3.1"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator?name=CVE-2022-33099&vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)&version=2"
                    },
                    "score": 5.0,
                    "severity": "medium",
                    "method": "CVSSv2",
                    "vector": "CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P"
                }
            ],
            "cwes": [
                787
            ],
            "description": "An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.",
            "published": "2022-07-01T12:15:08Z",
            "updated": "2024-11-21T07:07:32Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The code that triggers the vulnerability is not present in Connext.",
                "firstIssued": "2022-10-05T13:24:28.660000Z",
                "lastUpdated": "2022-10-19T11:20:02.434000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-32"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-230272"
                }
            ]
        },
        {
            "bom-ref": "CVE-2022-37434",
            "id": "CVE-2022-37434",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37434"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2022-37434&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                787
            ],
            "description": "zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).",
            "published": "2022-08-05T07:15:07Z",
            "updated": "2024-11-21T07:14:59Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext is not affected since we are not using inflateGetHeader function from the zlib library.",
                "firstIssued": "2023-04-26T13:47:24.750000Z",
                "lastUpdated": "2023-06-26T14:05:02.317000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-81"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-248499"
                }
            ]
        },
        {
            "bom-ref": "CVE-2023-23088",
            "id": "CVE-2023-23088",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23088"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2023-23088&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                787
            ],
            "description": "Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.",
            "published": "2023-02-03T18:15:17Z",
            "updated": "2024-11-21T07:45:51Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "We don't use Barenboim json-parser in our code base. The code impacted code is not present in our codebase.",
                "firstIssued": "2024-05-03T14:43:35.976000Z",
                "lastUpdated": "2024-07-31T21:16:11.149000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-200"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-593528"
                }
            ]
        },
        {
            "bom-ref": "CVE-2023-45853",
            "id": "CVE-2023-45853",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45853"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2023-45853&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2023/45xxx/CVE-2023-45853.json"
                    },
                    "score": 8.8,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                190
            ],
            "description": "MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.",
            "published": "2023-10-14T02:15:09Z",
            "updated": "2024-12-20T17:41:31Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "No. The affected code is https://github.com/madler/zlib/blob/develop/contrib/minizip/zip.c#L1016C20-L1016C43 . We do not use MiniZip in our code. There is no `contrib` or `minizip` folder in our codebase.",
                "firstIssued": "2024-03-05T13:34:45.109000Z",
                "lastUpdated": "2024-07-31T08:52:59.634000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-202"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-533513"
                }
            ]
        },
        {
            "bom-ref": "CVE-2024-21208",
            "id": "CVE-2024-21208",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21208"
            },
            "ratings": [
                {
                    "source": {
                        "name": "secalert_us@oracle.com"
                    },
                    "score": 3.7,
                    "severity": "low",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
                }
            ],
            "cwes": [
                203
            ],
            "description": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and  21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
            "published": "2024-10-15T20:15:09Z",
            "updated": "2025-06-18T20:27:14Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "Not affected since we don\u2019t use Java WebStart or Java Applets.",
                "firstIssued": "2025-06-27T20:18:12Z",
                "lastUpdated": "2025-06-27T20:18:12Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-362"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-705430"
                }
            ]
        },
        {
            "bom-ref": "CVE-2024-21210",
            "id": "CVE-2024-21210",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21210"
            },
            "ratings": [
                {
                    "source": {
                        "name": "secalert_us@oracle.com"
                    },
                    "score": 3.7,
                    "severity": "low",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
                }
            ],
            "cwes": [
                203
            ],
            "description": "Vulnerability in Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and  23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
            "published": "2024-10-15T20:15:09Z",
            "updated": "2025-06-18T20:27:23Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "Not affected since we don\u2019t use Java WebStart or Java Applets.",
                "firstIssued": "2025-06-27T20:19:39Z",
                "lastUpdated": "2025-06-27T20:19:39Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-362"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-705431"
                }
            ]
        },
        {
            "bom-ref": "CVE-2024-21217",
            "id": "CVE-2024-21217",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21217"
            },
            "ratings": [
                {
                    "source": {
                        "name": "secalert_us@oracle.com"
                    },
                    "score": 3.7,
                    "severity": "low",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
                }
            ],
            "description": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and  21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
            "published": "2024-10-15T20:15:11Z",
            "updated": "2024-10-18T18:29:36Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Not affected since we don't use Java Web Start or Applets in any of our products.",
                "firstIssued": "2025-02-05T17:13:28Z",
                "lastUpdated": "2025-02-05T17:13:28Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-303"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-646816"
                }
            ]
        },
        {
            "bom-ref": "CVE-2024-21235",
            "id": "CVE-2024-21235",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21235"
            },
            "ratings": [
                {
                    "source": {
                        "name": "secalert_us@oracle.com"
                    },
                    "score": 4.8,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
                }
            ],
            "description": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23;   Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23;   Oracle GraalVM Enterprise Edition: 20.3.15 and  21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
            "published": "2024-10-15T20:15:12Z",
            "updated": "2024-10-18T18:30:26Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Not affected since we don't use Java Web Start or Applets in any of our products.",
                "firstIssued": "2025-02-05T17:15:45Z",
                "lastUpdated": "2025-02-05T17:15:45Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-303"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-646818"
                }
            ]
        },
        {
            "bom-ref": "CVE-2024-47554",
            "id": "CVE-2024-47554",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2024/47xxx/CVE-2024-47554.json"
                    },
                    "score": 4.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
                }
            ],
            "cwes": [
                400
            ],
            "description": "Uncontrolled Resource Consumption vulnerability in Apache Commons IO.\n\nThe org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.\n\n\nThis issue affects Apache Commons IO: from 2.0 before 2.14.0.\n\nUsers are recommended to upgrade to version 2.14.0 or later, which fixes the issue.",
            "published": "2024-10-03T12:15:02Z",
            "updated": "2024-12-04T15:15:11Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the impacted component.",
                "firstIssued": "2024-11-25T12:06:41.884000Z",
                "lastUpdated": "2024-11-27T15:37:49.870000Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-277"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-645644"
                }
            ]
        },
        {
            "bom-ref": "CVE-2024-58249",
            "id": "CVE-2024-58249",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58249"
            },
            "ratings": [
                {
                    "source": {
                        "name": "cve@mitre.org"
                    },
                    "score": 3.7,
                    "severity": "low",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
                }
            ],
            "cwes": [
                826
            ],
            "description": "In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.",
            "published": "2025-04-16T16:15:29Z",
            "updated": "2025-04-17T20:22:16Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The vulnerable code is not present in the wxWidget version that we are using. It affects versions of wxWidgets between 3.1.5 and 3.2.7. The version of wxWidgets that Shapes Demo uses is not in the aforementioned range.",
                "firstIssued": "2025-08-26T09:27:07Z",
                "lastUpdated": "2025-08-26T09:27:07Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-388"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-704057"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-10966",
            "id": "CVE-2025-10966",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10966"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/10xxx/CVE-2025-10966.json"
                    },
                    "score": 4.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
                }
            ],
            "description": "curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.",
            "published": "2025-11-07T08:15:39Z",
            "updated": "2025-11-12T16:20:22Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "We are not affected because this CVE only affects curl when built with the wolfSSL backend. The curl built for use with Collector Service is only built with OpenSSL.",
                "firstIssued": "2025-12-18T14:52:02Z",
                "lastUpdated": "2025-12-18T14:52:02Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-452"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-740917"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-11563",
            "id": "CVE-2025-11563",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11563"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/11xxx/CVE-2025-11563.json"
                    },
                    "score": 4.6,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
                }
            ],
            "cwes": [
                22
            ],
            "description": "URLs containing percent-encoded slashes (`/` or `\\`) can trick wcurl into\nsaving the output file outside of the current directory without the user\nexplicitly asking for it.\n\nThis flaw only affects the wcurl command line tool.",
            "published": "2026-02-25T08:16:18Z",
            "updated": "2026-02-26T20:06:37Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "We are not affected by this vulnerability as it only affects the wcurl command line tool which we do not use.",
                "firstIssued": "2026-03-04T15:10:43Z",
                "lastUpdated": "2026-03-04T15:10:43Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-538"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-946392"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-13034",
            "id": "CVE-2025-13034",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/13xxx/CVE-2025-13034.json"
                    },
                    "score": 5.9,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "cwes": [
                295
            ],
            "description": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
            "published": "2026-01-08T10:15:45Z",
            "updated": "2026-01-20T14:54:02Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The Collector Service is not built with the GnuTLS backend.",
                "firstIssued": "2026-02-11T19:19:20Z",
                "lastUpdated": "2026-02-11T19:19:20Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-488"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-930567"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-14017",
            "id": "CVE-2025-14017",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/14xxx/CVE-2025-14017.json"
                    },
                    "score": 6.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
                }
            ],
            "description": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
            "published": "2026-01-08T10:15:45Z",
            "updated": "2026-01-27T21:29:39Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service does not use LDAP.",
                "firstIssued": "2026-02-11T19:12:21Z",
                "lastUpdated": "2026-02-11T19:12:21Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-488"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-930568"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-14524",
            "id": "CVE-2025-14524",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/14xxx/CVE-2025-14524.json"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
                }
            ],
            "cwes": [
                601
            ],
            "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
            "published": "2026-01-08T10:15:46Z",
            "updated": "2026-01-20T14:53:11Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service only uses basic authentication.",
                "firstIssued": "2026-02-11T19:04:50Z",
                "lastUpdated": "2026-02-11T19:04:50Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-488"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-930569"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-14819",
            "id": "CVE-2025-14819",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14819"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/14xxx/CVE-2025-14819.json"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
                }
            ],
            "cwes": [
                295
            ],
            "description": "When doing TLS related transfers with reused easy or multi handles and\naltering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.",
            "published": "2026-01-08T10:15:46Z",
            "updated": "2026-01-20T14:51:26Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service does not use the CURLSSLOPT_NO_PARTIALCHAIN option.",
                "firstIssued": "2026-02-11T19:03:13Z",
                "lastUpdated": "2026-02-11T19:03:13Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-488"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-930570"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-15079",
            "id": "CVE-2025-15079",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/15xxx/CVE-2025-15079.json"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
                }
            ],
            "cwes": [
                297
            ],
            "description": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
            "published": "2026-01-08T10:15:47Z",
            "updated": "2026-01-20T14:50:24Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service does not use SFTP or SCP.",
                "firstIssued": "2026-02-11T19:13:32Z",
                "lastUpdated": "2026-02-11T19:13:32Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-488"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-930571"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-15224",
            "id": "CVE-2025-15224",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/15xxx/CVE-2025-15224.json"
                    },
                    "score": 3.1,
                    "severity": "low",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
                }
            ],
            "cwes": [
                287
            ],
            "description": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
            "published": "2026-01-08T10:15:47Z",
            "updated": "2026-01-20T14:47:52Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service does not use SFTP or SCP.",
                "firstIssued": "2026-02-11T19:20:21Z",
                "lastUpdated": "2026-02-11T19:20:21Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-488"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-930572"
                }
            ]
        },
        {
            "bom-ref": "CVE-2025-48924",
            "id": "CVE-2025-48924",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48924"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2025/48xxx/CVE-2025-48924.json"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
                }
            ],
            "cwes": [
                674
            ],
            "description": "Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with\u00a0commons-lang:commons-lang\u00a02.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before\u00a03.18.0.\n\nThe methods ClassUtils.getClass(...) can throw\u00a0StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could\u00a0cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue.",
            "published": "2025-07-11T15:15:24Z",
            "updated": "2025-07-28T13:45:38Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "No RTI Connext products invoke the impacted function ClassUtils.getClass, either within the RTI tools' direct source code or in any plugin dependencies.",
                "firstIssued": "2025-08-07T10:51:16Z",
                "lastUpdated": "2025-08-07T10:51:16Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-378"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-710140"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-1965",
            "id": "CVE-2026-1965",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/1xxx/CVE-2026-1965.json"
                    },
                    "score": 6.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "cwes": [
                305
            ],
            "description": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
            "published": "2026-03-11T11:15:59Z",
            "updated": "2026-03-12T14:11:19Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service only uses a single set of credentials when making HTTPS requests.",
                "firstIssued": "2026-03-19T18:53:12Z",
                "lastUpdated": "2026-03-19T18:53:12Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-540"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-950705"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-3783",
            "id": "CVE-2026-3783",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/3xxx/CVE-2026-3783.json"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
                }
            ],
            "cwes": [
                522
            ],
            "description": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
            "published": "2026-03-11T11:16:00Z",
            "updated": "2026-03-12T14:10:37Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service does not use OAuth2 tokens.",
                "firstIssued": "2026-03-19T18:51:23Z",
                "lastUpdated": "2026-03-19T18:51:23Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-540"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-950704"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-3784",
            "id": "CVE-2026-3784",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/3xxx/CVE-2026-3784.json"
                    },
                    "score": 6.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
                }
            ],
            "cwes": [
                305
            ],
            "description": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
            "published": "2026-03-11T11:16:00Z",
            "updated": "2026-03-12T14:09:50Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "When Collector Service uses curl to connect to a server, only one set of credentials is used.",
                "firstIssued": "2026-03-19T18:47:16Z",
                "lastUpdated": "2026-03-19T18:47:16Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-540"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-950702"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-3805",
            "id": "CVE-2026-3805",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3805"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/3xxx/CVE-2026-3805.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                416
            ],
            "description": "When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory.",
            "published": "2026-03-11T11:16:00Z",
            "updated": "2026-03-12T14:08:56Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The Collector Service does not use the SMB protocol.",
                "firstIssued": "2026-03-19T18:48:55Z",
                "lastUpdated": "2026-03-19T18:48:55Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-540"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-950703"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-4873",
            "id": "CVE-2026-4873",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/4xxx/CVE-2026-4873.json"
                    },
                    "score": 5.9,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
                }
            ],
            "cwes": [
                295,
                319
            ],
            "description": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
            "published": "2026-05-13T13:01:55Z",
            "updated": "2026-06-17T10:57:22Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires clear-text IMAP, POP3, or SMTP transfers followed by a TLS-required transfer to the same host, credentials, and scheme. The Collector uses HTTP(S), not those mail protocols.",
                "firstIssued": "2026-08-27T13:24:40Z",
                "lastUpdated": "2026-08-27T13:24:40Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982467"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-5545",
            "id": "CVE-2026-5545",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-5545&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N&version=3.1"
                    },
                    "score": 6.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"
                }
            ],
            "cwes": [
                613
            ],
            "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
            "published": "2026-05-13T13:01:56Z",
            "updated": "2026-06-17T10:59:12Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires a Negotiate-authenticated request followed by a request for different credentials to the same host while the connection remains reusable. The Collector sends optional Basic authentication and does not configure HTTP Negotiate.",
                "firstIssued": "2026-08-27T13:23:25Z",
                "lastUpdated": "2026-08-27T13:23:25Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982466"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-5773",
            "id": "CVE-2026-5773",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-5773&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&version=3.1"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                }
            ],
            "cwes": [
                918
            ],
            "description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different 'share' than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
            "published": "2026-05-13T13:01:56Z",
            "updated": "2026-06-17T10:59:37Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires SMB or SMB(S) transfers to the same server using different shares. The Collector only uses OTLP HTTP(S) and has no SMB transfer path.",
                "firstIssued": "2026-08-27T13:22:41Z",
                "lastUpdated": "2026-08-27T13:22:41Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982465"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-6253",
            "id": "CVE-2026-6253",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/6xxx/CVE-2026-6253.json"
                    },
                    "score": 5.9,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                522
            ],
            "description": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
            "published": "2026-05-13T13:01:56Z",
            "updated": "2026-06-17T11:00:33Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires different proxies selected for different URL schemes, credentials on the first proxy, no credentials on the second, and a redirect from one scheme to the other. The Collector creates one configured OTLP HTTP(S) endpoint and does not configure redirects or multiple proxies.",
                "firstIssued": "2026-08-27T13:26:22Z",
                "lastUpdated": "2026-08-27T13:26:22Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982470"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-6276",
            "id": "CVE-2026-6276",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-6276&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&version=3.1"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                319
            ],
            "description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
            "published": "2026-05-13T13:01:56Z",
            "updated": "2026-06-17T11:00:35Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires reusing a libcurl easy handle after setting a custom Host: header, then sending cookies  without that header. The Collector does not set custom Host headers or use cookies in its OTLP exporters.",
                "firstIssued": "2026-08-27T13:20:56Z",
                "lastUpdated": "2026-08-27T13:20:56Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982464"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-6429",
            "id": "CVE-2026-6429",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/6xxx/CVE-2026-6429.json"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
                }
            ],
            "description": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
            "published": "2026-05-13T13:01:56Z",
            "updated": "2026-06-17T11:00:49Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires a .netrc credential source, clear-text HTTP for both the original and redirected URLs, one shared HTTP proxy, and connection reuse. The Collector does not use .netrc and can be configured for HTTP or HTTPS, but does not expose a redirect configuration in its OTLP properties.",
                "firstIssued": "2026-08-27T13:27:02Z",
                "lastUpdated": "2026-08-27T13:27:02Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982471"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-7168",
            "id": "CVE-2026-7168",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-7168&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N&version=3.1"
                    },
                    "score": 5.3,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
                }
            ],
            "cwes": [
                294
            ],
            "description": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
            "published": "2026-05-13T13:01:57Z",
            "updated": "2026-06-17T11:01:57Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires reusing one libcurl handle after Digest authentication through proxy A and then changing it to proxy B. The Collector source does not configure proxy authentication or change proxies.",
                "firstIssued": "2026-08-27T13:25:36Z",
                "lastUpdated": "2026-08-27T13:25:36Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-591"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-982469"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8286",
            "id": "CVE-2026-8286",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8286.json"
                    },
                    "score": 8.1,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
                }
            ],
            "cwes": [
                295
            ],
            "description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
            "published": "2026-07-03T07:16:24Z",
            "updated": "2026-07-07T19:42:11Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires STARTTLS transfers using IMAP, POP3, SMTP, FTP, or LDAP with mismatched TLS settings. The Collector uses HTTP(S) OTLP endpoints and does not use these protocols.",
                "firstIssued": "2026-08-27T13:41:13Z",
                "lastUpdated": "2026-08-27T13:41:13Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018483"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8458",
            "id": "CVE-2026-8458",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8458.json"
                    },
                    "score": 6.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
            "published": "2026-07-03T07:16:24Z",
            "updated": "2026-07-07T23:12:17Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires HTTP Negotiate authentication with different service names on otherwise matching connections. The Collector uses optional Basic authentication and does not configure Negotiate or service names.",
                "firstIssued": "2026-08-27T13:42:03Z",
                "lastUpdated": "2026-08-27T13:42:03Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018484"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8924",
            "id": "CVE-2026-8924",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8924.json"
                    },
                    "score": 9.1,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                }
            ],
            "description": "A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
            "published": "2026-07-03T07:16:24Z",
            "updated": "2026-07-07T23:06:00Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires cookie use, Public Suffix List handling, and a trailing-dot hostname controlled by a malicious server. The Collector does not use cookies and its OTLP endpoint configuration does not establish a cookie jar.",
                "firstIssued": "2026-08-27T13:42:34Z",
                "lastUpdated": "2026-08-27T13:42:34Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018485"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8925",
            "id": "CVE-2026-8925",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8925"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8925.json"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                415
            ],
            "description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
            "published": "2026-07-03T07:16:24Z",
            "updated": "2026-07-07T23:04:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires IMAP, POP3, or SMTP SASL authentication with libcurl built against libgsasl. The Collector uses OTLP HTTP(S), not mail protocols or SASL.",
                "firstIssued": "2026-08-27T13:43:15Z",
                "lastUpdated": "2026-08-27T13:43:15Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018486"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8926",
            "id": "CVE-2026-8926",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8926"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8926.json"
                    },
                    "score": 9.1,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                }
            ],
            "cwes": [
                522
            ],
            "description": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T23:02:54Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires a .netrc credential source and a URL containing a username without a password. The Collector supplies an OTLP URL from its configured hostname and uses an explicit Basic Authorization header when configured; it does not use .netrc.",
                "firstIssued": "2026-08-27T13:43:47Z",
                "lastUpdated": "2026-08-27T13:43:47Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018487"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8927",
            "id": "CVE-2026-8927",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8927.json"
                    },
                    "score": 9.1,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                }
            ],
            "cwes": [
                294
            ],
            "description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T23:21:03Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires sequential transfers using environment-variable proxy selection, Digest authentication to proxy A, then proxy B, with a reused handle. The Collector does not configure proxy authentication or multiple proxy transfers.",
                "firstIssued": "2026-08-27T13:44:25Z",
                "lastUpdated": "2026-08-27T13:44:25Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018488"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-8932",
            "id": "CVE-2026-8932",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8932.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "description": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T23:18:32Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires reusing a libcurl connection after changing client-certificate or private-key TLS settings. The Collector configures a CA certificate for HTTPS server verification, but does not configure client certificates or mTLS private keys in the OTLP exporters.",
                "firstIssued": "2026-08-27T13:40:10Z",
                "lastUpdated": "2026-08-27T13:40:10Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018482"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-9079",
            "id": "CVE-2026-9079",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9079"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9079.json"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                522
            ],
            "description": "libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T15:05:55Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires reuse of a libcurl handle while changing or clearing proxy authentication credentials. The Collector does not configure proxy credentials or change proxy credentials between transfers.",
                "firstIssued": "2026-08-27T13:35:54Z",
                "lastUpdated": "2026-08-27T13:35:54Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018476"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-9080",
            "id": "CVE-2026-9080",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9080"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9080.json"
                    },
                    "score": 7.3,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
                }
            ],
            "cwes": [
                416
            ],
            "description": "Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T15:05:26Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires an application to call curl_easy_pause() from the event-based CURLMOPT_SOCKETFUNCTION callback. The Collector does not use the curl multi socket callback or pause API.",
                "firstIssued": "2026-08-27T13:36:36Z",
                "lastUpdated": "2026-08-27T13:36:36Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018477"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-9545",
            "id": "CVE-2026-9545",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9545"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9545.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                }
            ],
            "description": "In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T15:03:56Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires the ngtcp2 and nghttp3 HTTP/3 backend, TLS early data enabled, session reuse, and a cached session followed by connection to an impostor server. The Collector's OTLP exporters use HTTP(S), with no configured HTTP/3 or TLS early-data setting.",
                "firstIssued": "2026-08-27T13:37:26Z",
                "lastUpdated": "2026-08-27T13:37:26Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018478"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-9547",
            "id": "CVE-2026-9547",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9547.json"
                    },
                    "score": 7.4,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
                }
            ],
            "description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
            "published": "2026-07-03T07:16:25Z",
            "updated": "2026-07-07T14:52:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires SCP or SFTP with the libssh backend and the CURLOPT_SSH_KEYFUNCTION callback. The Collector uses HTTP(S) OTLP export and does not use SSH transfers or the libssh backend.",
                "firstIssued": "2026-08-27T13:33:51Z",
                "lastUpdated": "2026-08-27T13:33:51Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018471"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-10536",
            "id": "CVE-2026-10536",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10536"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/10xxx/CVE-2026-10536.json"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                416
            ],
            "description": "A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.",
            "published": "2026-07-03T07:16:23Z",
            "updated": "2026-07-07T18:02:03Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires an application to configure HTTP/2 stream dependencies with CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, then reset and clean up the handle. The Collector's OTLP exporters do not configure HTTP/2 stream dependencies.",
                "firstIssued": "2026-08-27T13:34:32Z",
                "lastUpdated": "2026-08-27T13:34:32Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018472"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-11586",
            "id": "CVE-2026-11586",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11586"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/11xxx/CVE-2026-11586.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                770
            ],
            "description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
            "published": "2026-07-03T07:16:23Z",
            "updated": "2026-07-07T17:59:46Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires libcurl WebSocket use and an attacker-controlled server flooding the client with PING frames. The full Collector's WebSocket adapter uses CivetWeb, not libcurl; its libcurl path is OTLP HTTP(S).",
                "firstIssued": "2026-08-27T13:35:15Z",
                "lastUpdated": "2026-08-27T13:35:15Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018475"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-11822",
            "id": "CVE-2026-11822",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11822"
            },
            "ratings": [
                {
                    "source": {
                        "name": "disclosure@vulncheck.com"
                    },
                    "score": 8.5,
                    "severity": "high",
                    "method": "CVSSv4",
                    "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
                },
                {
                    "source": {
                        "name": "disclosure@vulncheck.com"
                    },
                    "score": 7.8,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                122
            ],
            "description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.",
            "published": "2026-06-09T20:16:32Z",
            "updated": "2026-06-11T17:12:47Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The vulnerability requires the FTS5 extension (the root vector of the issue), which must be explicitly enabled at compile time using the SQLITE_ENABLE_FTS5 definition. Because FTS5 is disabled by default and our build system does not enable it, we are not vulnerable.",
                "firstIssued": "2026-06-16T10:15:15Z",
                "lastUpdated": "2026-06-16T10:15:15Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-603"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-999361"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-11824",
            "id": "CVE-2026-11824",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11824"
            },
            "ratings": [
                {
                    "source": {
                        "name": "disclosure@vulncheck.com"
                    },
                    "score": 8.5,
                    "severity": "high",
                    "method": "CVSSv4",
                    "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
                },
                {
                    "source": {
                        "name": "disclosure@vulncheck.com"
                    },
                    "score": 7.8,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                122
            ],
            "description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.",
            "published": "2026-06-09T20:16:32Z",
            "updated": "2026-06-11T17:12:11Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The vulnerability requires the FTS5 extension (the root vector of the issue), which must be explicitly enabled at compile time using the SQLITE_ENABLE_FTS5 definition. Because FTS5 is disabled by default and our build system does not enable it, we are not vulnerable.",
                "firstIssued": "2026-06-16T10:18:10Z",
                "lastUpdated": "2026-06-16T10:18:10Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-603"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-999364"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-14456",
            "id": "CVE-2026-14456",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14456"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/14xxx/CVE-2026-14456.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                770
            ],
            "description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
            "published": "2026-08-13T15:19:31Z",
            "updated": "2026-08-13T18:17:18Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the QUIC protocol.",
                "firstIssued": "2026-08-20T15:24:51Z",
                "lastUpdated": "2026-08-20T15:24:51Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-646"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1051150"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-14457",
            "id": "CVE-2026-14457",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14457"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/14xxx/CVE-2026-14457.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                476
            ],
            "description": "Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary.",
            "published": "2026-08-25T13:17:49Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not support RPKs.",
                "firstIssued": "2026-08-28T21:16:35Z",
                "lastUpdated": "2026-08-28T21:16:35Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061108"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-11856",
            "id": "CVE-2026-11856",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/11xxx/CVE-2026-11856.json"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                294
            ],
            "description": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.",
            "published": "2026-07-03T07:16:23Z",
            "updated": "2026-07-07T19:43:55Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Requires reuse of a libcurl handle after Digest authentication to host A, followed by a request to host B. The Collector uses a configured OTLP endpoint and optional Basic authentication, not Digest authentication or cross-origin handle reuse.",
                "firstIssued": "2026-08-27T13:38:16Z",
                "lastUpdated": "2026-08-27T13:38:16Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018480"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-12064",
            "id": "CVE-2026-12064",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12064"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/12xxx/CVE-2026-12064.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "cwes": [
                295
            ],
            "description": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.",
            "published": "2026-07-03T07:16:24Z",
            "updated": "2026-07-07T19:43:11Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "This flaw affects only the curl command-line tool when using schemeless SFTP or SCP URLs. The Collector does not invoke the curl tool and uses libcurl through OTLP HTTP(S).",
                "firstIssued": "2026-08-27T13:39:29Z",
                "lastUpdated": "2026-08-27T13:39:29Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-630"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1018481"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-18798",
            "id": "CVE-2026-18798",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18798"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/18xxx/CVE-2026-18798.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                415
            ],
            "description": "Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.",
            "published": "2026-08-25T13:17:49Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the QUIC protocol.",
                "firstIssued": "2026-08-28T21:28:42Z",
                "lastUpdated": "2026-08-28T21:28:42Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061112"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-22184",
            "id": "CVE-2026-22184",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22184"
            },
            "ratings": [
                {
                    "source": {
                        "name": "disclosure@vulncheck.com"
                    },
                    "score": 4.6,
                    "severity": "medium",
                    "method": "CVSSv4",
                    "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-22184&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1"
                    },
                    "score": 9.8,
                    "severity": "critical",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
            ],
            "cwes": [
                787
            ],
            "description": "zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.",
            "published": "2026-01-07T21:16:01Z",
            "updated": "2026-01-15T14:16:27Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_present",
                "detail": "The untgz code is not present in the Core Libraries.",
                "firstIssued": "2026-01-22T15:19:51Z",
                "lastUpdated": "2026-01-22T15:19:51Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-493"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-932447"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-27171",
            "id": "CVE-2026-27171",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27171"
            },
            "ratings": [
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-27171&vector=AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&version=3.1"
                    },
                    "score": 5.5,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "source": {
                        "name": "cve@mitre.org"
                    },
                    "score": 2.9,
                    "severity": "low",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
                }
            ],
            "cwes": [
                1284
            ],
            "description": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
            "published": "2026-02-18T04:16:01Z",
            "updated": "2026-02-20T16:45:28Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use crc32_combine64 or crc32_combine_gen64 from the zlib library.",
                "firstIssued": "2026-02-23T19:37:36Z",
                "lastUpdated": "2026-02-23T19:37:36Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-536"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-945094"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-34479",
            "id": "CVE-2026-34479",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34479"
            },
            "ratings": [
                {
                    "source": {
                        "name": "security@apache.org"
                    },
                    "score": 6.9,
                    "severity": "medium",
                    "method": "CVSSv4",
                    "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-34479&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N&version=3.1"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "cwes": [
                116
            ],
            "description": "The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.\n\nTwo groups of users are affected:\n\n  *  Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.\n  *  Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.\n\n\nUsers are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue.\n\nNote: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the  Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.",
            "published": "2026-04-10T16:16:31Z",
            "updated": "2026-05-06T18:21:34Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "The affected classes are Log4j1XmlLayout and CMLLayout (via the log4j1 compatibility layer). Neither of these classes is present or referenced within our codebase. Furthermore, there are no Log4j XML configurations or properties that could trigger or activate the vulnerable layout path.",
                "firstIssued": "2026-05-18T08:18:18Z",
                "lastUpdated": "2026-05-18T08:18:18Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-570"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-964592"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-49844",
            "id": "CVE-2026-49844",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49844"
            },
            "ratings": [
                {
                    "source": {
                        "name": "security@apache.org"
                    },
                    "score": 6.3,
                    "severity": "medium",
                    "method": "CVSSv4",
                    "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
                },
                {
                    "source": {
                        "name": "NVD",
                        "url": "https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2026-49844&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N&version=3.1"
                    },
                    "score": 5.9,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
                }
            ],
            "cwes": [
                116
            ],
            "description": "Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.",
            "published": "2026-07-10T22:16:42Z",
            "updated": "2026-07-14T20:03:09Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "RTI Code Generator does not use MapMessage, JsonTemplateLayout, or JsonLayout; all logging is done via plain Logger calls only.",
                "firstIssued": "2026-08-20T11:13:24Z",
                "lastUpdated": "2026-08-20T11:13:24Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-645"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1051434"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-54874",
            "id": "CVE-2026-54874",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54874"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/54xxx/CVE-2026-54874.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                405
            ],
            "description": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
            "published": "2026-08-25T13:19:24Z",
            "updated": "2026-08-28T19:46:29Z",
            "recommendation": "Update to a Connext Professional release that does not include the vulnerable version of this third-party software.",
            "analysis": {
                "state": "exploitable",
                "detail": "The Secure WAN Transport is affected by product issue COREPLG-778, which has a maximum CVSS 3.1 score of 7.5.",
                "firstIssued": "2026-08-28T22:44:05Z",
                "lastUpdated": "2026-08-28T22:44:05Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061116"
                },
                {
                    "name": "rti_vulnerability_id",
                    "value": "COREPLG-778"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-63072",
            "id": "CVE-2026-63072",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63072"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/63xxx/CVE-2026-63072.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                787
            ],
            "description": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
            "published": "2026-08-25T13:19:26Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not invoke CMS_decrypt.",
                "firstIssued": "2026-08-29T00:04:40Z",
                "lastUpdated": "2026-08-29T00:04:40Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061167"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-63073",
            "id": "CVE-2026-63073",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63073"
            },
            "cwes": [
                134
            ],
            "description": "Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
            "published": "2026-08-25T13:19:26Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the Certificate Management Protocol.",
                "firstIssued": "2026-08-28T23:58:56Z",
                "lastUpdated": "2026-08-28T23:58:56Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061123"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-63074",
            "id": "CVE-2026-63074",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63074"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/63xxx/CVE-2026-63074.json"
                    },
                    "score": 5.9,
                    "severity": "medium",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                770
            ],
            "description": "Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
            "published": "2026-08-25T13:19:26Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the Certificate Management Protocol.",
                "firstIssued": "2026-08-28T23:57:20Z",
                "lastUpdated": "2026-08-28T23:57:20Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061119"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-63075",
            "id": "CVE-2026-63075",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63075"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/63xxx/CVE-2026-63075.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                770
            ],
            "description": "Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.",
            "published": "2026-08-25T13:19:26Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the QUIC protocol.",
                "firstIssued": "2026-08-29T00:02:54Z",
                "lastUpdated": "2026-08-29T00:02:54Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061131"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-63076",
            "id": "CVE-2026-63076",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63076"
            },
            "ratings": [
                {
                    "source": {
                        "name": "CISA-ADP",
                        "url": "https://github.com/cisagov/vulnrichment/blob/develop/2026/63xxx/CVE-2026-63076.json"
                    },
                    "score": 7.5,
                    "severity": "high",
                    "method": "CVSSv31",
                    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                }
            ],
            "cwes": [
                476
            ],
            "description": "Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
            "published": "2026-08-25T13:19:26Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not use the Certificate Management Protocol.",
                "firstIssued": "2026-08-29T00:00:36Z",
                "lastUpdated": "2026-08-29T00:00:36Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061127"
                }
            ]
        },
        {
            "bom-ref": "CVE-2026-75803",
            "id": "CVE-2026-75803",
            "source": {
                "name": "NVD",
                "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75803"
            },
            "cwes": [
                354
            ],
            "description": "Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.",
            "published": "2026-08-25T13:19:29Z",
            "updated": "2026-08-28T19:46:29Z",
            "analysis": {
                "state": "not_affected",
                "justification": "code_not_reachable",
                "detail": "Connext does not invoke EVP_Cipher.",
                "firstIssued": "2026-08-29T00:07:28Z",
                "lastUpdated": "2026-08-29T00:07:28Z"
            },
            "affects": [
                {
                    "ref": "Connext Pro"
                }
            ],
            "properties": [
                {
                    "name": "rti_id",
                    "value": "THIRDPARTY-648"
                },
                {
                    "name": "xray_id",
                    "value": "XRAY-1061184"
                }
            ]
        }
    ]
}