Skip to content

Commit 0f76ecf

Browse files

File tree

5 files changed

+58
-14
lines changed

5 files changed

+58
-14
lines changed

advisories/github-reviewed/2025/09/GHSA-5xf2-f6ch-6p8r/GHSA-5xf2-f6ch-6p8r.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-5xf2-f6ch-6p8r",
4-
"modified": "2025-09-22T18:04:21Z",
4+
"modified": "2025-10-29T14:48:34Z",
55
"published": "2025-09-22T18:04:20Z",
66
"aliases": [
77
"CVE-2025-40843"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/Ericsson/codechecker/security/advisories/GHSA-5xf2-f6ch-6p8r"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40843"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/Ericsson/codechecker/commit/4122eb1b43d00c880e4f0747d2ca0a674feb7a50"
@@ -59,6 +63,6 @@
5963
"severity": "MODERATE",
6064
"github_reviewed": true,
6165
"github_reviewed_at": "2025-09-22T18:04:20Z",
62-
"nvd_published_at": null
66+
"nvd_published_at": "2025-10-28T19:15:41Z"
6367
}
6468
}

advisories/github-reviewed/2025/10/GHSA-7f5h-v6xp-fcq8/GHSA-7f5h-v6xp-fcq8.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-7f5h-v6xp-fcq8",
4-
"modified": "2025-10-28T20:38:01Z",
4+
"modified": "2025-10-29T14:48:52Z",
55
"published": "2025-10-28T20:38:01Z",
66
"aliases": [
77
"CVE-2025-62727"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/Kludex/starlette/security/advisories/GHSA-7f5h-v6xp-fcq8"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62727"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/Kludex/starlette/commit/4ea6e22b489ec388d6004cfbca52dd5b147127c5"
@@ -64,6 +68,6 @@
6468
"severity": "HIGH",
6569
"github_reviewed": true,
6670
"github_reviewed_at": "2025-10-28T20:38:01Z",
67-
"nvd_published_at": null
71+
"nvd_published_at": "2025-10-28T21:15:40Z"
6872
}
6973
}

advisories/github-reviewed/2025/10/GHSA-867c-p784-5q6g/GHSA-867c-p784-5q6g.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-867c-p784-5q6g",
4-
"modified": "2025-10-28T20:14:09Z",
4+
"modified": "2025-10-29T14:48:58Z",
55
"published": "2025-10-28T20:14:09Z",
66
"aliases": [
77
"CVE-2025-62796"
@@ -40,6 +40,14 @@
4040
"type": "WEB",
4141
"url": "https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-867c-p784-5q6g"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62796"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/PrivateBin/PrivateBin/pull/1550"
50+
},
4351
{
4452
"type": "WEB",
4553
"url": "https://github.com/PrivateBin/PrivateBin/commit/c4f8482b3072be7ae012cace1b3f5658dcc3b42e"
@@ -57,6 +65,6 @@
5765
"severity": "MODERATE",
5866
"github_reviewed": true,
5967
"github_reviewed_at": "2025-10-28T20:14:09Z",
60-
"nvd_published_at": null
68+
"nvd_published_at": "2025-10-28T21:15:40Z"
6169
}
6270
}

advisories/github-reviewed/2025/10/GHSA-q8j9-34qf-7vq7/GHSA-q8j9-34qf-7vq7.json

Lines changed: 16 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-q8j9-34qf-7vq7",
4-
"modified": "2025-10-28T17:31:32Z",
4+
"modified": "2025-10-29T14:47:34Z",
55
"published": "2025-10-28T17:31:32Z",
66
"aliases": [
77
"CVE-2025-27093"
@@ -18,7 +18,7 @@
1818
{
1919
"package": {
2020
"ecosystem": "Go",
21-
"name": "github.com/bishopfox/sliver"
21+
"name": "github.com/BishopFox/sliver"
2222
},
2323
"ranges": [
2424
{
@@ -28,22 +28,33 @@
2828
"introduced": "0"
2929
},
3030
{
31-
"last_affected": "1.5.43"
31+
"fixed": "1.5.44"
3232
}
3333
]
3434
}
35-
]
35+
],
36+
"database_specific": {
37+
"last_known_affected_version_range": "<= 1.5.43"
38+
}
3639
}
3740
],
3841
"references": [
3942
{
4043
"type": "WEB",
4144
"url": "https://github.com/BishopFox/sliver/security/advisories/GHSA-q8j9-34qf-7vq7"
4245
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27093"
49+
},
4350
{
4451
"type": "WEB",
4552
"url": "https://github.com/BishopFox/sliver/commit/8e5c5f14506d6d60ebb3362e6b9857ab1e0d76ff"
4653
},
54+
{
55+
"type": "WEB",
56+
"url": "https://github.com/BishopFox/sliver/commit/9122878cbbcae543eb8210f616550382af2065fd"
57+
},
4758
{
4859
"type": "PACKAGE",
4960
"url": "https://github.com/BishopFox/sliver"
@@ -56,6 +67,6 @@
5667
"severity": "MODERATE",
5768
"github_reviewed": true,
5869
"github_reviewed_at": "2025-10-28T17:31:32Z",
59-
"nvd_published_at": null
70+
"nvd_published_at": "2025-10-28T20:15:47Z"
6071
}
6172
}

advisories/github-reviewed/2025/10/GHSA-qcpr-679q-rhm2/GHSA-qcpr-679q-rhm2.json

Lines changed: 20 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,19 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-qcpr-679q-rhm2",
4-
"modified": "2025-10-28T17:45:05Z",
4+
"modified": "2025-10-29T14:48:45Z",
55
"published": "2025-10-28T17:45:04Z",
66
"aliases": [
77
"CVE-2025-59837"
88
],
99
"summary": "Astro's bypass of image proxy domain validation leads to SSRF and potential XSS",
1010
"details": "### Summary\n\nThis is a patch bypass of CVE-2025-58179 in commit [9ecf359](https://github.com/withastro/astro/commit/9ecf3598e2b29dd74614328fde3047ea90e67252). The fix blocks `http://`, `https://` and `//`, but can be bypassed using backslashes (`\\`) - the endpoint still issues a server-side fetch.\n\n### PoC\n[https://astro.build/_image?href=\\\\raw.githubusercontent.com/projectdiscovery/nuclei-templates/refs/heads/main/helpers/payloads/retool-xss.svg&f=svg](https://astro.build/_image?href=%5C%5Craw.githubusercontent.com/projectdiscovery/nuclei-templates/refs/heads/main/helpers/payloads/retool-xss.svg&f=svg)",
11-
"severity": [],
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
15+
}
16+
],
1217
"affected": [
1318
{
1419
"package": {
@@ -35,6 +40,18 @@
3540
"type": "WEB",
3641
"url": "https://github.com/withastro/astro/security/advisories/GHSA-qcpr-679q-rhm2"
3742
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59837"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/withastro/astro/commit/1e2499e8ea83ebfa233a18a7499e1ccf169e56f4"
50+
},
51+
{
52+
"type": "WEB",
53+
"url": "https://github.com/withastro/astro/commit/9ecf3598e2b29dd74614328fde3047ea90e67252"
54+
},
3855
{
3956
"type": "PACKAGE",
4057
"url": "https://github.com/withastro/astro"
@@ -48,6 +65,6 @@
4865
"severity": "HIGH",
4966
"github_reviewed": true,
5067
"github_reviewed_at": "2025-10-28T17:45:04Z",
51-
"nvd_published_at": null
68+
"nvd_published_at": "2025-10-28T20:15:49Z"
5269
}
5370
}

0 commit comments

Comments
 (0)