{
  "attestation_mode": "local-ledger",
  "blockchain": false,
  "entries": [
    {
      "affected_refs": {
        "label": "eclipse / theia",
        "product": "theia",
        "products": [
          {
            "canonicalProduct": "theia",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "theia",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-12609.json": "1b7e9e16efc9af5b90f73e3cf965869538daa9dde5b4e1ec5a308dc8f5097e74"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "b3346078009ebea03be92cd5f6a9ffd8e8b49be695280cc7dbcbdd929efd0c22",
      "entry_id": "vsr:vuln:CVE-2026-12609:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.3374,
          "score": 0.00409
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 75.3374
        },
        "severity": {
          "cvss_score": 7.5,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-12609",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48",
          "canonical_url_hash": "405b4020b06e9a006d7c5ae5c6f67a5daa834f351149b97d47fda42ff3501063",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-qmm6-p8q4-2g48",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "405b4020b06e9a006d7c5ae5c6f67a5daa834f351149b97d47fda42ff3501063"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133",
          "canonical_url_hash": "ce1c0fb099f7487a269e725c3a1c1e0353a3102abfa5c9ebaceb57c77c06b2fa",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/133",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "ce1c0fb099f7487a269e725c3a1c1e0353a3102abfa5c9ebaceb57c77c06b2fa"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524",
          "canonical_url_hash": "3566d98e37746e6e37477945a87458f8fe629daf8b507a30e5ba213b3527a019",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/524",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "3566d98e37746e6e37477945a87458f8fe629daf8b507a30e5ba213b3527a019"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12609",
          "canonical_url_hash": "7ade0ff53da90bf73bb7703e1a34eaa73012035e7fcce60de66ac8c850c88b95",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12609",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "7ade0ff53da90bf73bb7703e1a34eaa73012035e7fcce60de66ac8c850c88b95"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-12609",
          "canonical_url_hash": "8083d2cfe1a4ac66bbf6c37f74faa55797a6306751ac9647054e60d2956d3972",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-12609",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "8083d2cfe1a4ac66bbf6c37f74faa55797a6306751ac9647054e60d2956d3972"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "eclipse / accessibility_tools_framework",
        "product": "accessibility_tools_framework",
        "products": [
          {
            "canonicalProduct": "accessibility_tools_framework",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:accessibility_tools_framework:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "accessibility_tools_framework",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          },
          {
            "canonicalProduct": "michecker",
            "canonicalVendor": "soumu",
            "cpe": "cpe:2.3:a:soumu:michecker:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "michecker",
            "purl": null,
            "vendor": "soumu",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-14304.json": "d426b75664834f36b4534db76d8313e3ae0bcb39c593ea6567d6fcacd25b98cb"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "875f9108f6083502b2f938921f67ad911d62d0ec3a34a62b5153642a1a8c3804",
      "entry_id": "vsr:vuln:CVE-2026-14304:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.06863,
          "score": 0.00172
        },
        "kev": false,
        "priority": {
          "label": "Routine monitoring candidate",
          "reasons": [
            "advisory available",
            "affected product present"
          ],
          "score": 46.06863
        },
        "severity": {
          "cvss_score": 4.6,
          "cvss_severity": "MEDIUM",
          "defensive_priority": "Routine monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-14304",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html",
          "canonical_url_hash": "26245f59088e039be503be30019debe776cd4ef518485388f4bd326fff18a618",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "26245f59088e039be503be30019debe776cd4ef518485388f4bd326fff18a618"
        },
        {
          "canonical_url": "https://github.com/eclipse-actf/org.eclipse.actf",
          "canonical_url_hash": "0237649499a997307718e915dc4a60b2bd48134af9aab254170010e6f5da9e34",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/eclipse-actf/org.eclipse.actf",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "0237649499a997307718e915dc4a60b2bd48134af9aab254170010e6f5da9e34"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151",
          "canonical_url_hash": "087335bd2a2af9ccf087b0ed317b403f0f8ade22e740dbd80394a21cb7579c62",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "087335bd2a2af9ccf087b0ed317b403f0f8ade22e740dbd80394a21cb7579c62"
        },
        {
          "canonical_url": "https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/",
          "canonical_url_hash": "fd24ae7fbfaff5b1d58f7e7dbec236c05d4bf9e906a58b884f5178bfa8f8883a",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "fd24ae7fbfaff5b1d58f7e7dbec236c05d4bf9e906a58b884f5178bfa8f8883a"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14304",
          "canonical_url_hash": "7bb33f872fb24d3a16a885598f838d8d9b5e0c3b6c3b574184010ce26ec72e87",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14304",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "7bb33f872fb24d3a16a885598f838d8d9b5e0c3b6c3b574184010ce26ec72e87"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-14304",
          "canonical_url_hash": "6098a6fcd3df79e74f8e5f9dc7b656bad2a950feb541bf4bee308a2173bf6c95",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-14304",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "6098a6fcd3df79e74f8e5f9dc7b656bad2a950feb541bf4bee308a2173bf6c95"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "eclipse / theia",
        "product": "theia",
        "products": [
          {
            "canonicalProduct": "theia",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "theia",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-14574.json": "9dc8bcd2a76f967bba3f65c809e1a1c8ebf688d3d0e14b7c97aa869d201c7672"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "b63a4a9cbdf071acd8c076c3a4f31498a6677e631e784bc8d4f06ec400793241",
      "entry_id": "vsr:vuln:CVE-2026-14574:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.20449,
          "score": 0.00282
        },
        "kev": false,
        "priority": {
          "label": "Routine monitoring candidate",
          "reasons": [
            "advisory available",
            "affected product present"
          ],
          "score": 57.20449
        },
        "severity": {
          "cvss_score": 5.7,
          "cvss_severity": "MEDIUM",
          "defensive_priority": "Routine monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-14574",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32",
          "canonical_url_hash": "9de044c2419c04e809b90c45be8fa6cc4e94efb5c4782e5121e81f7a2f3b4661",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-f3w9-qfw3-xr32",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "9de044c2419c04e809b90c45be8fa6cc4e94efb5c4782e5121e81f7a2f3b4661"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157",
          "canonical_url_hash": "cc25d186bc2c759a3a880ba9e4178945bbe0ade7a7796c278826dfc427ec27d5",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/157",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "cc25d186bc2c759a3a880ba9e4178945bbe0ade7a7796c278826dfc427ec27d5"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567",
          "canonical_url_hash": "ef7cf0ff803e9c208d200a2d660fc545ffc7b8f52354b5e4e31b65f287933daa",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/567",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "ef7cf0ff803e9c208d200a2d660fc545ffc7b8f52354b5e4e31b65f287933daa"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567",
          "canonical_url_hash": "de4c2ab07c99a9bcc1df219ae34b8bd9399516b43f0ec8d6448e1c6da2fe1f27",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/567",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "de4c2ab07c99a9bcc1df219ae34b8bd9399516b43f0ec8d6448e1c6da2fe1f27"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14574",
          "canonical_url_hash": "37cf90842c266e7bd61b6ebb8543e78ae2a0928157b545de0d9a06898a0da6e7",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14574",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "37cf90842c266e7bd61b6ebb8543e78ae2a0928157b545de0d9a06898a0da6e7"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-14574",
          "canonical_url_hash": "65d9b0524b73b8c3e18b236311354f697c2f96e860c68a9ba7ce6cf818f98e4d",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-14574",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "65d9b0524b73b8c3e18b236311354f697c2f96e860c68a9ba7ce6cf818f98e4d"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-17578.json": "51df5ebc5749ff28fb474986175b5b88dbffbbf1408de0f51201ed36df93c15e"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "6413749abc3ea1626400552b324240af8afb4f0012844c2ca244dbfc464d0aa3",
      "entry_id": "vsr:vuln:CVE-2026-17578:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.04712,
          "score": 0.0015
        },
        "kev": false,
        "priority": {
          "label": "Routine monitoring candidate",
          "reasons": [
            "advisory available",
            "affected product present"
          ],
          "score": 23.04712
        },
        "severity": {
          "cvss_score": 2.3,
          "cvss_severity": "LOW",
          "defensive_priority": "Routine monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-17578",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://developer.konghq.com/event-gateway/changelog/",
          "canonical_url_hash": "0bbbb0e3a3cb49e01dd952f1a18aa0f92858c90b20c600570df49c65a59e4a30",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://developer.konghq.com/event-gateway/changelog/",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "0bbbb0e3a3cb49e01dd952f1a18aa0f92858c90b20c600570df49c65a59e4a30"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17578",
          "canonical_url_hash": "9c5fb05a550e02ac262cac46e9757cf8b4daf1ca05e236bdf7f8698b8c4ef917",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17578",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "9c5fb05a550e02ac262cac46e9757cf8b4daf1ca05e236bdf7f8698b8c4ef917"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "eclipse / theia",
        "product": "theia",
        "products": [
          {
            "canonicalProduct": "theia",
            "canonicalVendor": "eclipse",
            "cpe": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
            "ecosystem": null,
            "packageName": null,
            "product": "theia",
            "purl": null,
            "vendor": "eclipse",
            "version": null
          }
        ],
        "vendor": "eclipse"
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-60009.json": "1bf9130dbd99166f543a031312214a0b2529de386e6acb5a8f39866a19185e49"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "7dabcf4a4d6130ae2921a8a374f3623e59142ee3fc57d81052d05bdddce79e85",
      "entry_id": "vsr:vuln:CVE-2026-60009:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.24854,
          "score": 0.00323
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 88.24854
        },
        "severity": {
          "cvss_score": 8.8,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-60009",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3",
          "canonical_url_hash": "4f0ad0dc99d233da2c9d0190793ed7b43485197d7276494aa2da514245dd5d71",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "4f0ad0dc99d233da2c9d0190793ed7b43485197d7276494aa2da514245dd5d71"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177",
          "canonical_url_hash": "1779a51a2891f1f2a46baae63c2cbe396c364cc0ccb443a357516cd96680fd1f",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "1779a51a2891f1f2a46baae63c2cbe396c364cc0ccb443a357516cd96680fd1f"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595",
          "canonical_url_hash": "22a14eb86eb06be6c8a64d0c606a34a387998edbc72f542ab6ad692f37e1922c",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "22a14eb86eb06be6c8a64d0c606a34a387998edbc72f542ab6ad692f37e1922c"
        },
        {
          "canonical_url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595",
          "canonical_url_hash": "cb07533f88a567f39e26013da9f98d1954c6c5ba07b762bfab5e69c093d5cd0d",
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "cb07533f88a567f39e26013da9f98d1954c6c5ba07b762bfab5e69c093d5cd0d"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60009",
          "canonical_url_hash": "d5e4b0f17b609c4812f763f2ae5be39bfe7ff2fdc3d01a4b16b1223bf777f68d",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60009",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "d5e4b0f17b609c4812f763f2ae5be39bfe7ff2fdc3d01a4b16b1223bf777f68d"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-60009",
          "canonical_url_hash": "d6de68a4b77d6ab7936f4b8b417aece7de780e2171324393c629b23308de8618",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-60009",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "d6de68a4b77d6ab7936f4b8b417aece7de780e2171324393c629b23308de8618"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-66747.json": "2540bcbdf4cafa6b9487047b843e1d4092faa82bd89cb869721022419f926465"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "820ed463f66dee5780819655d67ab8413d0b0898776957e088d4e3ab09345a78",
      "entry_id": "vsr:vuln:CVE-2026-66747:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.44552,
          "score": 0.00579
        },
        "kev": false,
        "priority": {
          "label": "Priority review candidate",
          "reasons": [
            "CVSS CRITICAL",
            "advisory available",
            "affected product present"
          ],
          "score": 93.44552
        },
        "severity": {
          "cvss_score": 9.3,
          "cvss_severity": "CRITICAL",
          "defensive_priority": "Priority review candidate"
        }
      },
      "signal_id": "CVE-2026-66747",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/ycsunjane/rctl",
          "canonical_url_hash": "5d01f27c751af05b07fc41348b53ca2cc0c9b37b317a5e31009e8f01fc5c48af",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/ycsunjane/rctl",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "5d01f27c751af05b07fc41348b53ca2cc0c9b37b317a5e31009e8f01fc5c48af"
        },
        {
          "canonical_url": "https://www.vulncheck.com/advisories/zbt-endlessdoors",
          "canonical_url_hash": "bcb14c6c115eb3f488176f363ed4397d1f8d566e412ff5a2887a244624296880",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://www.vulncheck.com/advisories/zbt-endlessdoors",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "bcb14c6c115eb3f488176f363ed4397d1f8d566e412ff5a2887a244624296880"
        },
        {
          "canonical_url": "https://www.vulncheck.com/blog/zbt-endlessdoors",
          "canonical_url_hash": "0de6e8ffad49ea45dcf9d70a9fef575e283d806bcaeeb7579bf95368d9bb66a8",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://www.vulncheck.com/blog/zbt-endlessdoors",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "0de6e8ffad49ea45dcf9d70a9fef575e283d806bcaeeb7579bf95368d9bb66a8"
        },
        {
          "canonical_url": "https://www.zbtlink.com/pages/zbt-router-firmware-download",
          "canonical_url_hash": "8c2b25d089abc18b5f66aeaf634b5052d93bd95af2dd8d13113d84fe245a8dd5",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://www.zbtlink.com/pages/zbt-router-firmware-download",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "8c2b25d089abc18b5f66aeaf634b5052d93bd95af2dd8d13113d84fe245a8dd5"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66747",
          "canonical_url_hash": "829ec1cb1b1a8fb863a656d632b3cfbe89f3aa74f48b13ca815d109bcbab567a",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66747",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "829ec1cb1b1a8fb863a656d632b3cfbe89f3aa74f48b13ca815d109bcbab567a"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71231.json": "67dd2b049df6417c2e077e374d71f6a55a8ae5d87b3018f8d554f72117923223"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "63791d6c17387be73da5d9e3061b7a1cce6ea7e9e69f33f4087b4791ab01a51e",
      "entry_id": "vsr:vuln:CVE-2026-71231:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.28595,
          "score": 0.00358
        },
        "kev": false,
        "priority": {
          "label": "Priority review candidate",
          "reasons": [
            "CVSS CRITICAL",
            "advisory available",
            "affected product present"
          ],
          "score": 98.28595
        },
        "severity": {
          "cvss_score": 9.8,
          "cvss_severity": "CRITICAL",
          "defensive_priority": "Priority review candidate"
        }
      },
      "signal_id": "CVE-2026-71231",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/thebradleysanders/IOTSmartHome",
          "canonical_url_hash": "7f99206343dd5477b4f6eb3d70ef5833658b3eaa73bb4b5512c148f4dd767c78",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/thebradleysanders/IOTSmartHome",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "7f99206343dd5477b4f6eb3d70ef5833658b3eaa73bb4b5512c148f4dd767c78"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71231",
          "canonical_url_hash": "444b4d8eb6a07ad6a6c24be5afd702804023441b6b4cb8d748f1377a215a3460",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71231",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "444b4d8eb6a07ad6a6c24be5afd702804023441b6b4cb8d748f1377a215a3460"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71232.json": "eb0736347cc272b8cbec4dd192692a55d30d839eb23f0f549e4e94d52c21ce1a"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "d39273303c5ff5bb436544af33fc6419b84372589448df45b6c99024d7bb2202",
      "entry_id": "vsr:vuln:CVE-2026-71232:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.22368,
          "score": 0.003
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 72.22368
        },
        "severity": {
          "cvss_score": 7.2,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71232",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0",
          "canonical_url_hash": "38a3b67576303bcc50a2f8d69356876b1da149ce72af1088f21834c1ab02782f",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "38a3b67576303bcc50a2f8d69356876b1da149ce72af1088f21834c1ab02782f"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71232",
          "canonical_url_hash": "2ddc242eb6a0ba4082efeca8876122ff8a872b6ed3968746e4d97f17fbab7a4b",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71232",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "2ddc242eb6a0ba4082efeca8876122ff8a872b6ed3968746e4d97f17fbab7a4b"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-71232",
          "canonical_url_hash": "2fe911260330a5191ea4f9dced07ac89100253ac931353a25b8d0a2036c83628",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-71232",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "2fe911260330a5191ea4f9dced07ac89100253ac931353a25b8d0a2036c83628"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71233.json": "fa0ef73f39e8a9138bded41cfeb68e6dc377884b7ae6ae114d01435e78c9453d"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "5479494cd938fdf063384535ab4b27d3986b1a763d5ae5c3d347803f314e64ee",
      "entry_id": "vsr:vuln:CVE-2026-71233:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.0994,
          "score": 0.00199
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 87.0994
        },
        "severity": {
          "cvss_score": 8.7,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71233",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/invoiceninja/invoiceninja",
          "canonical_url_hash": "955f5da4cabba27273095e9a9f90a56d64757f182a51ffea5fb67fee3c49949e",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/invoiceninja/invoiceninja",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "955f5da4cabba27273095e9a9f90a56d64757f182a51ffea5fb67fee3c49949e"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71233",
          "canonical_url_hash": "72ef6cfb80b0c8ab7754eb626ab6ab1991699c886c8ffc13d1497c609eea8767",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71233",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "72ef6cfb80b0c8ab7754eb626ab6ab1991699c886c8ffc13d1497c609eea8767"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71234.json": "1a8a99339c61ddf245ed10a7105aec3eddf74877f4735dee58b40a36c9cffa1b"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "8b18eaa3bb6bcc6f3386d57e473853e5aebd8e1c193499cdbbeb91c66733f704",
      "entry_id": "vsr:vuln:CVE-2026-71234:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.15873,
          "score": 0.00245
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 75.15873
        },
        "severity": {
          "cvss_score": 7.5,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71234",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/documize/community",
          "canonical_url_hash": "c5324dde153e2a4ce49535b40e58c01b8bf94254f46ff3b52110803a572b3919",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/documize/community",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "c5324dde153e2a4ce49535b40e58c01b8bf94254f46ff3b52110803a572b3919"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71234",
          "canonical_url_hash": "c46430e8d88436831032178aa43bfdb6ce308d18195962511347b1ab9d31d244",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71234",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "c46430e8d88436831032178aa43bfdb6ce308d18195962511347b1ab9d31d244"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71235.json": "a2016f7da2a12aa73b3a4c7a96f5c63d7460bb2771e80b7489b7440e4e3e42ab"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "e0c156f553b38f1152929e990a97095f71dac283fcea4ad2cd21fc504fdb5852",
      "entry_id": "vsr:vuln:CVE-2026-71235:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.21126,
          "score": 0.00288
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 88.21126
        },
        "severity": {
          "cvss_score": 8.8,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71235",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/absmach/magistrala",
          "canonical_url_hash": "c09abb5f37dcd64de3dad4940b16ff63e80d6826e6e01e797a708c3cf9380aa9",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/absmach/magistrala",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "c09abb5f37dcd64de3dad4940b16ff63e80d6826e6e01e797a708c3cf9380aa9"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71235",
          "canonical_url_hash": "880c7adcd06995b3f4eca479a16e7cb49a7b4b60c07aa7ebfd2c7d2634c49180",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71235",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "880c7adcd06995b3f4eca479a16e7cb49a7b4b60c07aa7ebfd2c7d2634c49180"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71236.json": "70c4b746b28978277a81c5cd3b154297f51da324323f004943e7a86807766d72"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "993e785afd61b55ad97c5ffce70aaedaa410c2a0ae40382a62b6a9674de3a9ce",
      "entry_id": "vsr:vuln:CVE-2026-71236:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.0994,
          "score": 0.00199
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 87.0994
        },
        "severity": {
          "cvss_score": 8.7,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71236",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/grocy/grocy",
          "canonical_url_hash": "921363e5e96660e711e322e2d54c75f7452a6c199c1ed1931bcea3e6547a1fc6",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/grocy/grocy",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "921363e5e96660e711e322e2d54c75f7452a6c199c1ed1931bcea3e6547a1fc6"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71236",
          "canonical_url_hash": "5624d536e5336aeda91ab42abcca79a97a33041602c8515a2f9e17cdb42a4a95",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71236",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "5624d536e5336aeda91ab42abcca79a97a33041602c8515a2f9e17cdb42a4a95"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71237.json": "f0bbefe53e094cad4bdaae0476866b94f2a2518dafb95eb52922bcb66c728df5"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "7d5e6a5ce4bd2608bff5c4629a63d3cf25b0fdd452f081c4acd1cee92cde7243",
      "entry_id": "vsr:vuln:CVE-2026-71237:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.34766,
          "score": 0.0042
        },
        "kev": false,
        "priority": {
          "label": "Priority review candidate",
          "reasons": [
            "CVSS CRITICAL",
            "advisory available",
            "affected product present"
          ],
          "score": 98.34766
        },
        "severity": {
          "cvss_score": 9.8,
          "cvss_severity": "CRITICAL",
          "defensive_priority": "Priority review candidate"
        }
      },
      "signal_id": "CVE-2026-71237",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/Miantang/IoT-PHP",
          "canonical_url_hash": "2c4b5aa732ec542ce1fb5739eba1a57e538aec952356683145fef06f633e54fb",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/Miantang/IoT-PHP",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "2c4b5aa732ec542ce1fb5739eba1a57e538aec952356683145fef06f633e54fb"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71237",
          "canonical_url_hash": "26e7f6398d2b67600f62a6cbbd5a5071ee22a76d40a7a224a21e68b5f86c627a",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71237",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "26e7f6398d2b67600f62a6cbbd5a5071ee22a76d40a7a224a21e68b5f86c627a"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71238.json": "a82d9e1bfef78331e61c635dda9ba971d72eadf52fe737319aeb513479f30bdf"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "461fba95f9cb00776f1a1f0872467402fa57743be6db85539e0214efd37e023a",
      "entry_id": "vsr:vuln:CVE-2026-71238:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.23765,
          "score": 0.00313
        },
        "kev": false,
        "priority": {
          "label": "Priority review candidate",
          "reasons": [
            "CVSS CRITICAL",
            "advisory available",
            "affected product present"
          ],
          "score": 91.23765
        },
        "severity": {
          "cvss_score": 9.1,
          "cvss_severity": "CRITICAL",
          "defensive_priority": "Priority review candidate"
        }
      },
      "signal_id": "CVE-2026-71238",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/DjangoCRM/django-crm",
          "canonical_url_hash": "bf88b14a7e9502a9dfca6c5e651ca0e297cbb1c11cf275394c4ae294aa684ed0",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/DjangoCRM/django-crm",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "bf88b14a7e9502a9dfca6c5e651ca0e297cbb1c11cf275394c4ae294aa684ed0"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71238",
          "canonical_url_hash": "93521bfe979632f5cad89e8959f9533940ab3b2ffed35bd8c2626e71537335ab",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71238",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "93521bfe979632f5cad89e8959f9533940ab3b2ffed35bd8c2626e71537335ab"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71239.json": "766262a2f45063828adf498f509e45da12bfe73829c516c28236ff8f1e397df5"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "1b91b981d5cfff9efdbe241c66313c6ebf4a15b1ae5501c6389cfa7bc425a51e",
      "entry_id": "vsr:vuln:CVE-2026-71239:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.13231,
          "score": 0.00225
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 81.13231
        },
        "severity": {
          "cvss_score": 8.1,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71239",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/DjangoCRM/django-crm",
          "canonical_url_hash": "bf88b14a7e9502a9dfca6c5e651ca0e297cbb1c11cf275394c4ae294aa684ed0",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/DjangoCRM/django-crm",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "bf88b14a7e9502a9dfca6c5e651ca0e297cbb1c11cf275394c4ae294aa684ed0"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71239",
          "canonical_url_hash": "8eb406b3372ab4171bc9b21d12cbeac00fdbb1d2f8f78c5a5cb9e143c8c03a34",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71239",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "8eb406b3372ab4171bc9b21d12cbeac00fdbb1d2f8f78c5a5cb9e143c8c03a34"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71240.json": "6b3348e6b83fe8e5f234914c772d59fa0dc6176634c11ba4071bcfa64e570f40"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "e9492be7af5319dfa2686a569c56b1c2f18c9af2939c21215b97c728f5bc4f48",
      "entry_id": "vsr:vuln:CVE-2026-71240:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.08769,
          "score": 0.00189
        },
        "kev": false,
        "priority": {
          "label": "Routine monitoring candidate",
          "reasons": [
            "advisory available",
            "affected product present"
          ],
          "score": 43.08769
        },
        "severity": {
          "cvss_score": 4.3,
          "cvss_severity": "MEDIUM",
          "defensive_priority": "Routine monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71240",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/DjangoCRM/django-crm",
          "canonical_url_hash": "bf88b14a7e9502a9dfca6c5e651ca0e297cbb1c11cf275394c4ae294aa684ed0",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/DjangoCRM/django-crm",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "bf88b14a7e9502a9dfca6c5e651ca0e297cbb1c11cf275394c4ae294aa684ed0"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71240",
          "canonical_url_hash": "517296f0075c91bb88fc5521c59e7cc1ad86fdc12c222ffc724b5468a9536efe",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71240",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "517296f0075c91bb88fc5521c59e7cc1ad86fdc12c222ffc724b5468a9536efe"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71241.json": "739dc29e66c34eb041d2aa070a789996b27848b8a8631ca16232039e6a1f7c84"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "b967c903e12317f5884724cdb75b2ef16cd3e7212411cbbf56264ba095c0937c",
      "entry_id": "vsr:vuln:CVE-2026-71241:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.20477,
          "score": 0.00282
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 75.20477
        },
        "severity": {
          "cvss_score": 7.5,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71241",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/lyric777/Book-Management-System",
          "canonical_url_hash": "4e234a90466dcd6ff19782501464d4c71b234e5ac1550d755a13e2f720fc8fa2",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/lyric777/Book-Management-System",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "4e234a90466dcd6ff19782501464d4c71b234e5ac1550d755a13e2f720fc8fa2"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71241",
          "canonical_url_hash": "3e1572b5d550f6ad04b101c5bfcee7266ca25d6ed085847dc1d965a401c72cf5",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71241",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "3e1572b5d550f6ad04b101c5bfcee7266ca25d6ed085847dc1d965a401c72cf5"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71242.json": "f1415519f96bb59321c0c97dd2ddf37891dcbfe55abc1c9cfa9439f1753032ae"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "bd396eb9746847493b89380d98fe09b2285c8e29c04f82b6ec68dd00d7888026",
      "entry_id": "vsr:vuln:CVE-2026-71242:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.12013,
          "score": 0.00215
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 83.12013
        },
        "severity": {
          "cvss_score": 8.3,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71242",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/crater-invoice/crater",
          "canonical_url_hash": "5505578e808ce89e2bef5ee93e6a7fdb3a3c689c93e01b34e6938c2c75a31db5",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/crater-invoice/crater",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "5505578e808ce89e2bef5ee93e6a7fdb3a3c689c93e01b34e6938c2c75a31db5"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71242",
          "canonical_url_hash": "091769dc325f4cb9a7612186af01cb0c039819ba2bb91741a6693917d0b392e4",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71242",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "091769dc325f4cb9a7612186af01cb0c039819ba2bb91741a6693917d0b392e4"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-71242",
          "canonical_url_hash": "3b71e868874d9c741b631d6242fffa2bade66deeb0836055adac1a37b1ceab95",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-71242",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "3b71e868874d9c741b631d6242fffa2bade66deeb0836055adac1a37b1ceab95"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71243.json": "3317b15631e12b000364b6b6a6cd2a69ce2d1c35a598f8dc5332694bbfe66046"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "ddd7ddd19c3e369d0338860a3819572a94eed9760741ce6f9686f5eb16574b5e",
      "entry_id": "vsr:vuln:CVE-2026-71243:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.21081,
          "score": 0.00288
        },
        "kev": false,
        "priority": {
          "label": "Continuous monitoring candidate",
          "reasons": [
            "CVSS HIGH",
            "advisory available",
            "affected product present"
          ],
          "score": 88.21081
        },
        "severity": {
          "cvss_score": 8.8,
          "cvss_severity": "HIGH",
          "defensive_priority": "Continuous monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71243",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "OSV",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/adaltas/node-backmeup",
          "canonical_url_hash": "cd7d6661698ae9d8ec2a84e785f8ad7be622d3292c303764dce3be869dabb0f9",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/adaltas/node-backmeup",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "cd7d6661698ae9d8ec2a84e785f8ad7be622d3292c303764dce3be869dabb0f9"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71243",
          "canonical_url_hash": "c5e59c691d661929602935a4aa65052ea71a4d6142d285f7d16f6df8fe22ec7a",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71243",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "c5e59c691d661929602935a4aa65052ea71a4d6142d285f7d16f6df8fe22ec7a"
        },
        {
          "canonical_url": "https://osv.dev/vulnerability/CVE-2026-71243",
          "canonical_url_hash": "16f72cbb391e6bf4d830d5e91a8e215e41979ccf97073bb39c47c33f3f6d32f7",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://osv.dev/vulnerability/CVE-2026-71243",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "16f72cbb391e6bf4d830d5e91a8e215e41979ccf97073bb39c47c33f3f6d32f7"
        }
      ]
    },
    {
      "affected_refs": {
        "label": "-",
        "product": null,
        "products": [],
        "vendor": null
      },
      "artifact_hashes": {
        "/data/v1/latest.json": "9e9bfb525652fe1fde933d3341ef98c34764161f98f8289e10d8a14d7c865f30",
        "/data/v1/priority-queue.json": "61ce0017d466619b383f85aa0efafecbf246e3d6e30e214c64b813b7a4ffec69",
        "/data/vuln/items/CVE-2026-71244.json": "fc72b768584eed9a3fcee275b8cb90af83d17a105e45c57ea4b244cd0cb4246f"
      },
      "attestation_mode": "local-ledger",
      "defensive_use_only": true,
      "eas": {
        "attestation_uid": null,
        "mode": "reserved_offchain",
        "schema_uid": null,
        "status": "not_enabled"
      },
      "entry_canonicalization_profile": "json-sort-keys-no-whitespace-v0",
      "entry_hash": "62e429084cd1e4931516d5fc1029ce468f24ed2ac666571b1a1e95120d48dbce",
      "entry_id": "vsr:vuln:CVE-2026-71244:2026-08-12T10:39:32.977657+00:00",
      "observed_at": "2026-08-12T10:29:37.194110+00:00",
      "public_safe": true,
      "remediation": {
        "proof_ref": null,
        "status": "not_enabled"
      },
      "risk_refs": {
        "epss": {
          "percentile": 0.10156,
          "score": 0.00201
        },
        "kev": false,
        "priority": {
          "label": "Routine monitoring candidate",
          "reasons": [
            "advisory available",
            "affected product present"
          ],
          "score": 65.10156
        },
        "severity": {
          "cvss_score": 6.5,
          "cvss_severity": "MEDIUM",
          "defensive_priority": "Routine monitoring candidate"
        }
      },
      "signal_id": "CVE-2026-71244",
      "signal_type": "vulnerability_signal",
      "signature": {
        "mode": null,
        "note": "signatures are reserved for a future Trust Layer version",
        "status": "not_enabled"
      },
      "source_refs": [
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "NVD",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": null,
          "canonical_url_hash": null,
          "name": "Vendor Advisory",
          "public_allowed": true,
          "source_type": null,
          "url": null,
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": null
        },
        {
          "canonical_url": "https://github.com/paperless-ngx/paperless-ngx",
          "canonical_url_hash": "e8cd7111f3678ea8f97cd5f1c87ac7599aefdc35542dc0ab9548a1477a5ebfa0",
          "name": "Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://github.com/paperless-ngx/paperless-ngx",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "e8cd7111f3678ea8f97cd5f1c87ac7599aefdc35542dc0ab9548a1477a5ebfa0"
        },
        {
          "canonical_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71244",
          "canonical_url_hash": "f75d38067409688387745858f8230c87a8fd91ad50bfa765027c1f683c795ef2",
          "name": "Official Reference",
          "public_allowed": true,
          "source_type": "reference",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71244",
          "url_canonicalization_profile": "url-trim-no-fragment-strip-utm-lower-host-v0",
          "url_hash": "f75d38067409688387745858f8230c87a8fd91ad50bfa765027c1f683c795ef2"
        }
      ]
    }
  ],
  "entry_count": 20,
  "generated_at": "2026-08-12T10:39:32.977657+00:00",
  "ledger_type": "public_json_ledger",
  "radar": "vuln",
  "safety": {
    "attack_steps_included": false,
    "auto_remediation_allowed": false,
    "blockchain_claimed": false,
    "certification_claimed": false,
    "defensive_use_only": true,
    "exploit_detail_included": false,
    "external_execution_allowed": false,
    "public_safe_only": true,
    "read_only_static_data": true,
    "signature_claimed": false,
    "weaponized_detail_included": false
  },
  "schema_version": "vsr-attestation-ledger-v0",
  "trust_layer_version": "0.1"
}