Skip to content

[GHSA-f88m-g3jw-g9cj] Add CVE-2026-69242 inherited from libvips - #9252

Open
SirHegel wants to merge 1 commit into
github:SirHegel/advisory-improvement-9252from
SirHegel:sirhegel-GHSA-f88m-g3jw-g9cj
Open

[GHSA-f88m-g3jw-g9cj] Add CVE-2026-69242 inherited from libvips#9252
SirHegel wants to merge 1 commit into
github:SirHegel/advisory-improvement-9252from
SirHegel:sirhegel-GHSA-f88m-g3jw-g9cj

Conversation

@SirHegel

Copy link
Copy Markdown

Summary

Updates the existing sharp advisory to reflect the upstream addition of CVE-2026-69242.

The source advisory was updated on 2026-08-14. It now lists three High-severity inherited libvips vulnerabilities and uses the new highest CVSS v4 score of 8.4.

This pull request:

  • adds CVE-2026-69242 to the summary
  • updates “two” to “three” High-severity vulnerabilities
  • updates the CVSS v4 vector to the upstream 8.4 vector
  • adds the primary libvips advisory reference
  • updates modified to the source advisory timestamp

It does not change the affected sharp range, patched version, aliases, CWE, or qualitative severity.

Public sources

Validation

  • one advisory and one JSON file only
  • jq parse and semantic assertions: pass
  • git diff --check: pass
  • check-jsonschema 0.38.0 against the upstream OSSF OSV schema: pass
  • exact GHSA and CVE search found no existing issue or pull request in this repository

AI assistance disclosure

AI assistance was used to compare already-public upstream records and prepare validation commands. The JSON diff, timestamps, CVSS vector and every cited source were reviewed directly before submission.

@github-actions
github-actions Bot changed the base branch from main to SirHegel/advisory-improvement-9252 August 27, 2026 23:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant