File tree Expand file tree Collapse file tree
advisories/github-reviewed/2026/04/GHSA-qc22-xmq4-qg46 Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-qc22-xmq4-qg46" ,
4+ "modified" : " 2026-04-01T20:47:06Z" ,
5+ "published" : " 2026-04-01T20:47:06Z" ,
6+ "aliases" : [],
7+ "summary" : " c2cciutils affected by CVE-2022-40896 " ,
8+ "details" : " Pinned vulnerable version of Pygment [CVE-2022-40896](https://nvd.nist.gov/vuln/detail/CVE-2022-40896)" ,
9+ "severity" : [
10+ {
11+ "type" : " CVSS_V4" ,
12+ "score" : " CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
13+ }
14+ ],
15+ "affected" : [
16+ {
17+ "package" : {
18+ "ecosystem" : " PyPI" ,
19+ "name" : " c2cciutils"
20+ },
21+ "ranges" : [
22+ {
23+ "type" : " ECOSYSTEM" ,
24+ "events" : [
25+ {
26+ "introduced" : " 0"
27+ },
28+ {
29+ "fixed" : " 1.1.67"
30+ }
31+ ]
32+ }
33+ ],
34+ "database_specific" : {
35+ "last_known_affected_version_range" : " <= 1.1.66"
36+ }
37+ }
38+ ],
39+ "references" : [
40+ {
41+ "type" : " WEB" ,
42+ "url" : " https://github.com/camptocamp/c2cciutils/security/advisories/GHSA-qc22-xmq4-qg46"
43+ },
44+ {
45+ "type" : " WEB" ,
46+ "url" : " https://github.com/camptocamp/c2cciutils/commit/9d54eab73fcf24d492b339137040400da7ef4076"
47+ },
48+ {
49+ "type" : " ADVISORY" ,
50+ "url" : " https://github.com/advisories/GHSA-mrwq-x4v8-fh7p"
51+ },
52+ {
53+ "type" : " PACKAGE" ,
54+ "url" : " https://github.com/camptocamp/c2cciutils"
55+ }
56+ ],
57+ "database_specific" : {
58+ "cwe_ids" : [
59+ " CWE-434"
60+ ],
61+ "severity" : " MODERATE" ,
62+ "github_reviewed" : true ,
63+ "github_reviewed_at" : " 2026-04-01T20:47:06Z" ,
64+ "nvd_published_at" : null
65+ }
66+ }
You can’t perform that action at this time.
0 commit comments