Skip to content

Advisory severity changed

What a record said when it was published, what it says now, and the commit that changed it.

8 advisory changes · newest first · grouped by day

SinceClear all
ChangedSourceRows
Counted changes of "Advisory severity changed" from the last 30 days, newest first, one line per change to a GHSA advisory, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Advisory, Which advisory was edited, by its GHSA id.Package, The package the advisory names, and the registry it comes from.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 1 Sep 2026· 1 change
2026-09-01published 2025-12-01GHSA-569q-mpph-wgwwCVE-2025-71401whole advisoryhighstated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 274 days
Fri 28 Aug 2026· 2 changes
2026-08-28published 2026-06-12GHSA-9r4w-jg96-92mvCVE-2026-12681whole advisoryhighstated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.Time to revision 77 days
2026-08-28published 2026-07-02GHSA-77pv-3w4q-vrj5CVE-2026-53834whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 57 days
Wed 26 Aug 2026· 1 change
2026-08-26published 2026-02-25GHSA-wfx3-6g53-9fgcCVE-2026-56368whole advisorymoderatestated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same.Time to revision 182 days
Tue 25 Aug 2026· 1 change
2026-08-25published 2026-07-02GHSA-83w9-h5wv-j9xmCVE-2026-53838whole advisorymoderatestated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 54 days
Fri 21 Aug 2026· 2 changes
2026-08-21published 2026-07-24 to 2026-08-20whole advisoryhighstated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.Time to revision 1 to 28 days
2026-08-21published 2026-08-20GHSA-fm29-4mq3-phg6same package and registry as the line abovehighsame change as the line aboveTime to revision 1 days
2026-08-21published 2026-07-24GHSA-r292-9mhp-454mCVE-2026-73566same package and registry as the line abovehighsame change as the line aboveTime to revision 28 days
Tue 11 Aug 2026· 1 change
2026-08-11published 2026-06-26GHSA-4c3c-r6p8-c863CVE-2026-48813whole advisoryhighstated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored.Time to revision 46 days

Counted in advisories, never added to the CVE and KEV figures. This kind is counted once per advisory, so changes and advisories are the same number here. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
4,561 record edits in the 52 weeks to 2026-09-07. Scroll for earlier dates.fewermore

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →