Add alias CVE-2025-55182 to GHSA-9qr9-h5gf-34mp#6496
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates the security advisory GHSA-9qr9-h5gf-34mp to replace a rejected CVE ID with the active one. CVE-2025-66478 was rejected by NVD as a duplicate of CVE-2025-55182, so both IDs are now listed as aliases to ensure proper vulnerability tracking.
Key changes:
- Added CVE-2025-55182 to the aliases array
- Retained CVE-2025-66478 for reference
- Updated the modification timestamp
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Per the OSV schema, https://ossf.github.io/osv-schema/#aliases-field
|
|
@mswilson Thanks for the comment! |
|
As long as |
|
Hi @tockn and @mswilson, I'm removing CVE-2025-66478 as a CVE ID and changing the reference link https://nvd.nist.gov/vuln/detail/CVE-2025-66478 to https://nvd.nist.gov/vuln/detail/CVE-2025-55182 to clarify that GHSA-9qr9-h5gf-34mp refers to CVE-2025-55182. However, I can't add CVE-2025-55182 as an alias to GHSA-9qr9-h5gf-34mp because CVE-2025-55182 is already attached to GHSA-fv66-9v8q-g76r in the database backend. |
0b6dad6
into
github:tockn/advisory-improvement-6496
|
Hi @tockn! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Summary
This PR adds
CVE-2025-55182as an alias to this advisory.Details
According to NVD,
CVE-2025-66478has been REJECTED as a duplicate ofCVE-2025-55182.This change adds the active CVE ID to the aliases to correctly map this vulnerability.
References