Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

5,026 advisory changes · newest first · grouped by day

SinceClear the filter
ChangedSourceRows
Counted changes, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindAdvisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 6 May 2026· 22 advisory changes
2026-05-06published 2026-04-18Advisory fix version movedGHSA-8m29-fpq5-89jjCVE-2026-41583
crates.iozebra-script
critical
stated at publication 5.0.1, now states 5.0.2Days to revision 19
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/auth-helpersDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/aws-secrets-managerDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/federated-authDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/iamDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/mysql-driverDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/oktaDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/otlpDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/pgx-driverDays to revision 174
2026-05-06published 2025-11-13Package added to advisoryGHSA-7wq2-32h4-9hc9highnot named as affected when the advisory was published, now names github.com/aws/aws-advanced-go-wrapper/xrayDays to revision 174
2026-05-06published 2026-04-03Advisory severity changedGHSA-6336-qqw9-v6x6CVE-2026-41341whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03Advisory severity changedGHSA-rvvf-6vh3-9j43CVE-2026-41348whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03Advisory severity changedGHSA-37v6-fxx8-xjmxCVE-2026-41351whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03Advisory severity changedGHSA-mhr7-2xmv-4c4qCVE-2026-41347whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-02Advisory severity changedGHSA-89r3-6x4j-v7wfCVE-2026-41337whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03Advisory severity changedGHSA-cg7q-fg22-4g98CVE-2026-41369whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-02Advisory severity changedGHSA-fv94-qvg8-xqpwCVE-2026-41364whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-06published 2026-04-03Advisory severity changedGHSA-p464-m8x6-vhv8CVE-2026-41405whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 33
2026-05-06published 2026-03-31Advisory severity changedGHSA-j7p2-qcwm-94v4CVE-2026-41387whole advisoryhighstated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 35
2026-05-06published 2026-01-15Advisory withdrawnGHSA-xfhx-r7ww-5995whole advisoryhighwithdrawn 2026-05-06Days to revision 111
2026-05-06published 2026-05-06Advisory withdrawnGHSA-hjph-f4mc-wx4cwhole advisoryhighwithdrawn 2026-05-06Days to revision 0
2026-05-06published 2024-03-02Advisory withdrawnGHSA-hg35-mp25-qf6hwhole advisoryhighwithdrawn 2026-05-06Days to revision 796
Tue 5 May 2026· 12 advisory changes
2026-05-05published 2025-05-27Advisory fix version movedGHSA-8r88-6cj9-9fh5CVE-2025-48370
npm@supabase/auth-js
low
stated at publication 2.69.1, now states 2.70.0Days to revision 343
2026-05-05published 2025-09-03Package added to advisoryGHSA-qww7-89xh-x7m7CVE-2025-55747criticalnot named as affected when the advisory was published, now names org.xwiki.platform:xwiki-platform-webjarsDays to revision 244
2026-05-05published 2026-04-18Advisory severity changedGHSA-6ffj-2wg2-w45jCVE-2026-25917whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
2026-05-05published 2026-04-23Advisory severity changedGHSA-q2pw-xx38-p64jCVE-2026-29051whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2026-05-05published 2026-04-23Advisory severity changedGHSA-9mv3-2cwr-p262CVE-2026-40372whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 12
2026-05-05published 2026-04-15Advisory severity changedGHSA-hv5g-26jg-pc45CVE-2026-6290whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 20
2026-05-05published 2026-04-10Advisory severity changedGHSA-2rhw-gw3f-477jCVE-2026-40306whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 25
2026-05-05published 2026-04-02Advisory severity changedGHSA-v569-hp3g-36wrCVE-2026-34230whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 33
2026-05-05published 2026-04-02Advisory severity changedGHSA-vgpv-f759-9wx3CVE-2026-26961whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 33
2026-05-05published 2026-04-01Advisory severity changedGHSA-gcfj-cf7j-vwgjCVE-2026-34561whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 34
2026-05-05published 2026-03-30Advisory severity changedGHSA-66m2-v9v9-95c3CVE-2026-27599whole advisorycriticalstated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 36
2026-05-05published 2025-07-28Advisory withdrawnGHSA-c2fv-2fmj-9xrxwhole advisoryhighwithdrawn 2026-05-05Days to revision 282
Thu 30 Apr 2026· 1 advisory change
2026-04-30published 2026-03-27Advisory withdrawnGHSA-cw7v-45wm-mcf2CVE-2026-29905whole advisorymoderatewithdrawn 2026-04-30Days to revision 34
Tue 28 Apr 2026· 2 advisory changes
2026-04-28published 2026-04-09Package added to advisoryGHSA-563x-q5rq-57qpCVE-2026-24880highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 18
2026-04-28published 2022-02-08Package added to advisoryGHSA-vf77-8h7g-gghpCVE-2020-13934highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyotenot dated
Fri 24 Apr 2026· 2 advisory changes
2026-04-24published 2026-04-08Advisory severity changedGHSA-pr46-2v3c-5356CVE-2026-39847whole advisoryhighstated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
2026-04-24published 2026-04-07Advisory severity changedGHSA-hfpq-x728-986jCVE-2026-35406whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 17
Wed 22 Apr 2026· 1 advisory change
2026-04-22published 2026-02-19Package added to advisoryGHSA-4hfh-fch3-5q7pCVE-2026-27120moderatenot named as affected when the advisory was published, now names github.com/vapor/leaf-kitDays to revision 62
Sat 18 Apr 2026· 5 advisory changes
2026-04-18published 2026-03-26Advisory severity changedGHSA-mp66-rf4f-mhh8CVE-2026-35622whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2026-04-18published 2026-03-26Advisory severity changedGHSA-xhq5-45pm-2gjrCVE-2026-35624whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 22
2026-04-18published 2026-03-29Advisory severity changedGHSA-52q4-3xjc-6778CVE-2026-35617whole advisorylowstated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version.Days to revision 19
2026-04-18published 2026-03-29Advisory severity changedGHSA-h4jx-hjr3-fhgcCVE-2026-35645whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 19
2026-04-18published 2026-03-26Advisory severity changedGHSA-7xr2-q9vf-x4r5CVE-2026-35632whole advisorymoderatestated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Days to revision 22
Fri 17 Apr 2026· 2 advisory changes
2026-04-17published 2022-05-14Package added to advisoryGHSA-6r5v-hp32-fjqwCVE-2015-0227moderatenot named as affected when the advisory was published, now names wss4j:wss4jnot dated
2026-04-17published 2024-05-03Package added to advisoryGHSA-4h8f-2wvx-gg5wCVE-2024-34447moderatenot named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15onDays to revision 714
Thu 16 Apr 2026· 6 advisory changes
2026-04-16published 2022-04-22Package added to advisoryGHSA-4qqf-hmv6-r6whCVE-2011-2487moderatenot named as affected when the advisory was published, now names wss4j:wss4jnot dated
2026-04-16published 2025-07-21Package added to advisoryGHSA-9342-92gg-6v29CVE-2025-7962moderatenot named as affected when the advisory was published, now names com.sun.mail:jakarta.mailDays to revision 269
2026-04-16published 2024-10-04Package added to advisoryGHSA-wwcp-26wc-3fxmCVE-2024-47855moderatenot named as affected when the advisory was published, now names net.sf.json-lib:json-libDays to revision 560
2026-04-16published 2022-05-13Package added to advisoryGHSA-jwwr-fjgh-cv2xCVE-2014-3004moderatenot named as affected when the advisory was published, now names castor:castornot dated
2026-04-16published 2026-04-10Advisory severity changedGHSA-fvcv-3m26-pcqxCVE-2026-40175whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
2026-04-16published 2026-04-09Advisory severity changedGHSA-3p68-rc4w-qgx5CVE-2025-62718whole advisorymoderatestated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 7
Wed 15 Apr 2026· 6 advisory changes
2026-04-15published 2026-04-09Advisory fix version movedGHSA-h468-7pvh-8vr8CVE-2026-29146
mavenorg.apache.tomcat:tomcat
high
stated at publication 11.0.19, now states 11.0.20Days to revision 6
2026-04-15published 2026-04-09Package added to advisoryGHSA-8mc5-53m5-3qj2CVE-2026-32990moderatenot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyoteDays to revision 6
2026-04-15published 2026-04-09Package added to advisoryGHSA-69r9-qgr7-g2wjCVE-2026-34486highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesDays to revision 6
2026-04-15published 2026-04-09Package added to advisoryGHSA-h468-7pvh-8vr8CVE-2026-29146highnot named as affected when the advisory was published, now names org.apache.tomcat:tomcat-tribesDays to revision 6
2026-04-15published 2026-04-14Advisory severity changedGHSA-37gx-xxp4-5rgxCVE-2026-33116whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
2026-04-15published 2026-04-14Advisory severity changedGHSA-w3x6-4m5h-cxqfCVE-2026-26171whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 1
Tue 14 Apr 2026· 2 advisory changes
2026-04-14published 2026-03-30Advisory withdrawnGHSA-qqrv-2hch-83q4whole advisorymoderatewithdrawn 2026-04-14Days to revision 15
2026-04-14published 2026-04-08Advisory withdrawnGHSA-gc59-r5jq-98qwwhole advisoryhighwithdrawn 2026-04-14Days to revision 5
Mon 13 Apr 2026· 1 advisory change
2026-04-13published 2026-04-06Advisory withdrawnGHSA-6jwv-w5xf-7j27CVE-2026-33817whole advisorymoderatewithdrawn 2026-04-13Days to revision 7
Fri 10 Apr 2026· 5 advisory changes
2026-04-10published 2026-03-11Package added to advisoryGHSA-fvcw-9w9r-pxc7CVE-2026-31829highnot named as affected when the advisory was published, now names flowise-componentsDays to revision 31
2026-04-10published 2026-03-26Advisory severity changedGHSA-wv46-v6xc-2qhfCVE-2026-35670whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 15
2026-04-10published 2026-03-26Advisory severity changedGHSA-74wf-h43j-vvmjCVE-2026-35655whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 15
2026-04-10published 2026-03-26Advisory severity changedGHSA-wj55-88gf-x564CVE-2026-35648whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 15
2026-04-10published 2026-01-29Advisory severity changedGHSA-h5qv-qjv4-pc5mCVE-2026-40036whole advisoryhighstated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.Days to revision 71
Wed 8 Apr 2026· 3 advisory changes
2026-04-08published 2026-04-03Advisory fix version movedGHSA-rp9m-7r4c-75qgCVE-2026-35039
npmfast-jwt
critical
stated at publication 6.1.0, now states 6.2.0Days to revision 5
2026-04-08published 2026-03-20Package added to advisoryGHSA-687q-32c6-8x68CVE-2026-33478criticalnot named as affected when the advisory was published, now names wwbn/avideoDays to revision 19
2026-04-08published 2026-03-03Advisory severity changedGHSA-8fmp-37rc-p5g7CVE-2026-22177whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 36
Tue 7 Apr 2026· 1 advisory change
2026-04-07published 2022-05-17Advisory severity changedGHSA-qvpr-qm6w-6rccCVE-2012-5571whole advisorymoderatestated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 1,422
Mon 6 Apr 2026· 3 advisory changes
2026-04-06published 2026-03-30Package added to advisoryGHSA-jjwv-57xh-xr6rCVE-2026-27018highnot named as affected when the advisory was published, now names github.com/gotenberg/gotenberg/v7Days to revision 7
2026-04-06published 2026-03-31Advisory severity changedGHSA-hc5h-pmr3-3497CVE-2026-33579whole advisorycriticalstated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 6
2026-04-06published 2026-03-31Advisory severity changedGHSA-8prr-286p-4w7jCVE-2026-34400whole advisorymoderatestated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.Days to revision 6
Wed 1 Apr 2026· 1 advisory change
2026-04-01published 2024-11-12Advisory withdrawnGHSA-g5vp-j278-8pjhwhole advisoryhighwithdrawn 2026-04-01Days to revision 504
Mon 30 Mar 2026· 16 advisory changes
2026-03-30published 2025-06-28Advisory severity changedGHSA-m964-fjrh-xxq2CVE-2025-32897whole advisorylowstated at publication CRITICAL, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored.Days to revision 275
2026-03-30published 2026-03-03Advisory severity changedGHSA-h9xm-j4qg-fvpgCVE-2026-32007whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 27
2026-03-30published 2026-03-03Advisory severity changedGHSA-25gx-x37c-7pphCVE-2026-32064whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-02Advisory severity changedGHSA-hwpq-rrpf-pgcqCVE-2026-32065whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 28
2026-03-30published 2026-03-03Advisory severity changedGHSA-vvgp-4c28-m3jmCVE-2026-32057whole advisorymoderatestated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-02Advisory severity changedGHSA-hjvp-qhm6-wrh2CVE-2026-32058whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 28
2026-03-30published 2026-03-03Advisory severity changedGHSA-6rcp-vxwf-3mfpCVE-2026-32052whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-03Advisory severity changedGHSA-mwcg-wfq3-4gjcCVE-2026-32043whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-02Advisory severity changedGHSA-rxxp-482v-7mrhCVE-2026-32049whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 28
2026-03-30published 2026-03-09Advisory severity changedGHSA-r6qf-8968-wj9qCVE-2026-27183whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 21
2026-03-30published 2026-03-03Advisory severity changedGHSA-v865-p3gq-hw6mCVE-2026-32004whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-03Advisory severity changedGHSA-2ww6-868g-2c56CVE-2026-32040whole advisorylowstated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-03Advisory severity changedGHSA-2fgq-7j6h-9rm4CVE-2026-32003whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Days to revision 28
2026-03-30published 2026-03-02Advisory severity changedGHSA-vpj2-69hf-rppwCVE-2026-32041whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 28
2026-03-30published 2026-03-03Advisory severity changedGHSA-4gc7-qcvf-38wgCVE-2026-32010whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 27
2026-03-30published 2026-03-19Advisory withdrawnGHSA-x6gf-mpr2-68h6CVE-2026-4427whole advisoryhighwithdrawn 2026-03-30Days to revision 11
Fri 27 Mar 2026· 8 advisory changes
2026-03-27published 2026-03-24Advisory fix version movedGHSA-x4ff-q6h8-v7gwCVE-2026-32948
mavenorg.scala-sbt:sbt
moderate
stated at publication 1.12.7, now states 1.12.8Days to revision 3
2026-03-27published 2026-03-13Package added to advisoryGHSA-q926-c743-49qjlownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3Days to revision 14
2026-03-27published 2026-03-13Package added to advisoryGHSA-q926-c743-49qjlownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4Days to revision 14
2026-03-27published 2026-03-13Package added to advisoryGHSA-q926-c743-49qjlownot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5Days to revision 14
2026-03-27published 2026-03-13Package added to advisoryGHSA-j77h-rr39-c552CVE-2026-32301criticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v3Days to revision 14
2026-03-27published 2026-03-13Package added to advisoryGHSA-j77h-rr39-c552CVE-2026-32301criticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v4Days to revision 14
2026-03-27published 2026-03-13Package added to advisoryGHSA-j77h-rr39-c552CVE-2026-32301criticalnot named as affected when the advisory was published, now names github.com/centrifugal/centrifugo/v5Days to revision 14
2026-03-27published 2026-02-28Advisory severity changedGHSA-72hv-8253-57qqCVE-2026-18401whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Days to revision 28
Wed 25 Mar 2026· 1 advisory change
2026-03-25published 2026-03-01Advisory fix version movedGHSA-cpv7-q2wx-m8rwCVE-2026-28425
packagiststatamic/cms
high
stated at publication 5.73.11, now states 5.73.16Days to revision 25

Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none.

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →