Skip to content

Conversation

@jlsec-bot
Copy link
Contributor

This action searched recent NVD/EUVD changes/publications, checking 690 (+0) advisories from NVD and 708 (+159) from EUVD for advisories that pertain here. It identified 5 advisories as being related to the Julia package(s): XSLT_jll, XML2_jll, OpenSSH_jll, and LibArchive_jll.

5 advisories found concrete vulnerable ranges

  • CVE-2024-55549 for packages: XSLT_jll
    • XSLT_jll computed ["< 1.1.43+0"]. Its latest version (1.1.43+0) has components: {libxslt = "1.1.43"}
  • CVE-2025-24855 for packages: XSLT_jll
    • XSLT_jll computed ["< 1.1.43+0"]. Its latest version (1.1.43+0) has components: {libxslt = "1.1.43"}
  • CVE-2025-26465 for packages: OpenSSH_jll
    • OpenSSH_jll computed [">= 9.3.2+0, < 9.9.1+0"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}
  • CVE-2025-5914 for packages: LibArchive_jll
    • LibArchive_jll computed ["< 3.8.0+0"]. Its latest version (3.8.2+0) has components: {libarchive = "3.8.2"}
  • CVE-2025-6021 for packages: XML2_jll
    • XML2_jll computed ["< 2.14.4+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants