Every change, newest first
What a record said when it was published, what it says now, and the commit that changed it.
5,026 advisory changes · newest first · grouped by day
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Advisory, Which advisory was edited, by its GHSA id. | Package, The package the advisory names, and the registry it comes from. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Thu 12 Mar 2026· 3 changes | |||||
| 2026-03-12published 2026-03-10 | Package added to advisory | GHSA-hhfx-wfvq-7g9cCVE-2026-26118 | high | not named as affected when the advisory was published, now names msmcp-azure | Time to revision 2 days |
| 2026-03-12published 2026-01-22 | Advisory severity changed | GHSA-hx9q-6w63-j58vCVE-2025-67221 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 49 days |
| 2026-03-12published 2026-03-12 | Advisory severity changed | GHSA-g5xx-pwrp-g3fvCVE-2026-31860 | whole advisorymoderate | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 0 days |
| Wed 11 Mar 2026· 3 changes | |||||
| 2026-03-11published 2026-03-11 | Advisory severity changed | GHSA-gv8f-wpm2-m5wrCVE-2026-31975 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 1 days |
| 2026-03-11published 2026-03-11 | Advisory severity changed | GHSA-fvwq-45qv-xvhvCVE-2026-31859 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 1 days |
| 2026-03-11published 2026-02-20 | Advisory severity changed | GHSA-gv8r-9rw9-9697 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Time to revision 19 days |
| Tue 10 Mar 2026· 3 changes | |||||
| 2026-03-10published 2026-02-17 | Advisory severity changed | GHSA-qrq5-wjgg-rvqwCVE-2026-28447 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 21 days |
| 2026-03-10published 2026-02-18 | Advisory severity changed | GHSA-v773-r54f-q32wCVE-2026-28392 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Time to revision 21 days |
| 2026-03-10published 2026-03-09 | Advisory severity changed | GHSA-726g-59wr-cj4cCVE-2026-25041 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 1 days |
| Mon 9 Mar 2026· 1 change | |||||
| 2026-03-09published 2026-03-06 | Advisory fix version moved | GHSA-ccj6-79j6-cq5qCVE-2026-30855 | gogithub.com/tencent/weknora critical | stated at publication 0.3.1, now states 0.3.2 | Time to revision 3 days |
| Fri 6 Mar 2026· 16 changes | |||||
| 2026-03-06published 2025-07-10 | Package added to advisory | high | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | Time to revision 239 days | |
| 2026-03-06published 2025-07-10 | same kind of change as the line above | GHSA-wr62-c79q-cv37CVE-2025-52520 | same package registry as the line abovehigh | same change as the line above | Time to revision 239 days |
| 2026-03-06published 2025-07-10 | same kind of change as the line above | GHSA-25xr-qj8w-c4vfCVE-2025-53506 | same package registry as the line abovehigh | same change as the line above | Time to revision 239 days |
| 2026-03-06published 2025-07-10 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 239 days | |
| 2026-03-06published 2025-07-10 | same kind of change as the line above | GHSA-wr62-c79q-cv37CVE-2025-52520 | same package and registry as the line abovehigh | same change as the line above | Time to revision 239 days |
| 2026-03-06published 2025-07-10 | same kind of change as the line above | GHSA-25xr-qj8w-c4vfCVE-2025-53506 | same package and registry as the line abovehigh | same change as the line above | Time to revision 239 days |
| 2026-03-06published 2026-02-24 | Advisory severity changed | GHSA-78qv-3mpx-9cqqCVE-2026-27156 | whole advisorymoderate | stated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 10 days |
| 2026-03-06published 2026-01-09 to 2026-03-05 | Advisory severity changed | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 to 56 days | |
| 2026-03-06published 2026-03-05 | same kind of change as the line above | GHSA-595m-wc8g-6qgcCVE-2026-30247 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 1 days |
| 2026-03-06published 2026-01-09 | same kind of change as the line above | GHSA-pcwc-3fw3-8cqvCVE-2026-22687 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 56 days |
| 2026-03-06published 2026-02-17 to 2026-03-02 | Advisory severity changed | whole advisorymoderate | stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same. | Time to revision 3 to 16 days | |
| 2026-03-06published 2026-03-02 | same kind of change as the line above | GHSA-xw4p-pw82-hqr7CVE-2026-28457 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 3 days |
| 2026-03-06published 2026-02-17 | same kind of change as the line above | GHSA-7vwx-582j-j332CVE-2026-28481 | same package and registry as the line abovemoderate | same change as the line above | Time to revision 16 days |
| 2026-03-06published 2026-02-17 to 2026-03-03 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Time to revision 2 to 16 days | |
| 2026-03-06published 2026-03-02 | same kind of change as the line above | GHSA-jmm5-fvh5-gf4pCVE-2026-28464 | same package and registry as the line abovehigh | same change as the line above | Time to revision 3 days |
| 2026-03-06published 2026-02-19 | same kind of change as the line above | GHSA-fh3f-q9qw-93j9CVE-2026-28479 | same package and registry as the line abovehigh | same change as the line above | Time to revision 14 days |
| 2026-03-06published 2026-02-18 | same kind of change as the line above | GHSA-5xfq-5mr7-426qCVE-2026-28482 | same package and registry as the line abovehigh | same change as the line above | Time to revision 16 days |
| 2026-03-06published 2026-02-18 | same kind of change as the line above | GHSA-xvhf-x56f-2hppCVE-2026-28463 | same package and registry as the line abovehigh | same change as the line above | Time to revision 16 days |
| 2026-03-06published 2026-03-03 | same kind of change as the line above | GHSA-7xhj-55q9-pc3mCVE-2026-28393 | same package and registry as the line abovehigh | same change as the line above | Time to revision 2 days |
| 2026-03-06published 2026-02-17 | same kind of change as the line above | GHSA-3m3q-x3gj-f79xCVE-2026-28465 | same package and registry as the line abovehigh | same change as the line above | Time to revision 16 days |
| 2026-03-06published 2026-02-17 | same kind of change as the line above | GHSA-xc7w-v5x6-cc87CVE-2026-29613 | same package and registry as the line abovehigh | same change as the line above | Time to revision 16 days |
| Thu 5 Mar 2026· 1 change | |||||
| 2026-03-05published 2026-03-04 | Advisory severity changed | GHSA-79pf-vx4x-7jmmCVE-2026-29188 | whole advisorycritical | stated at publication MODERATE, now states CRITICALCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 1 days |
| Wed 4 Mar 2026· 1 change | |||||
| 2026-03-04published 2025-12-30 | Advisory severity changed | GHSA-6rw7-vpxm-498pCVE-2025-15284 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 64 days |
| Fri 27 Feb 2026· 2 changes | |||||
| 2026-02-27published 2026-02-12 | Advisory severity changed | GHSA-435g-fcv3-8j26 | whole advisorylow | stated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version. | Time to revision 15 days |
| 2026-02-27published 2025-07-31 | Advisory severity changed | GHSA-2x45-7fc3-mxwqCVE-2025-45769 | whole advisorylow | stated at publication HIGH, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 211 days |
| Tue 24 Feb 2026· 1 change | |||||
| 2026-02-24published 2025-03-20 | Package added to advisory | GHSA-j3wr-m6xh-64hgCVE-2024-12704 | high | not named as affected when the advisory was published, now names llama-index-core | Time to revision 341 days |
| Thu 19 Feb 2026· 2 changes | |||||
| 2026-02-19published 2026-02-13 | Package added to advisory | GHSA-rp46-r563-jrc7CVE-2025-33042 | moderate | not named as affected when the advisory was published, now names org.apache.avro:avro-compiler | Time to revision 6 days |
| 2026-02-19published 2025-10-16 | Package added to advisory | GHSA-fwxx-wv44-7qfgCVE-2025-41253 | high | not named as affected when the advisory was published, now names org.springframework.cloud:spring-cloud-gateway-server | Time to revision 126 days |
| Wed 18 Feb 2026· 2 changes | |||||
| 2026-02-18published 2026-02-06 | Advisory fix version moved | GHSA-2ww3-72rp-wpp4CVE-2026-25592 | nugetmicrosoft.semantickernel.core critical | stated at publication 1.70.0, now states 1.71.0 | Time to revision 12 days |
| 2026-02-18published 2026-02-12 | Advisory withdrawn | GHSA-gfmx-qqqh-f38q | whole advisoryhigh | withdrawn 2026-02-18 | Time to revision 7 days |
| Tue 17 Feb 2026· 10 changes | |||||
| 2026-02-17published 2025-12-04 | Package added to advisory | GHSA-2cgv-28vr-rv6j | high | not named as affected when the advisory was published, now names libcrux-ml-dsa and 1 more | Time to revision 75 days |
| 2026-02-17published 2025-12-04 | same kind of change as the line above | GHSA-2cgv-28vr-rv6j | same package registry as the line abovehigh | not named as affected when the advisory was published, now names libcrux-ml-dsa | Time to revision 75 days |
| 2026-02-17published 2025-12-04 | same kind of change as the line above | GHSA-2cgv-28vr-rv6j | same package registry as the line abovehigh | not named as affected when the advisory was published, now names libcrux-ml-kem | Time to revision 75 days |
| 2026-02-17published 2024-02-13 to 2024-03-06 | Advisory severity changed | whole advisoryhigh | stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 713 to 735 days | |
| 2026-02-17published 2024-03-06 | same kind of change as the line above | GHSA-c2f9-4jmm-v45mCVE-2024-27917 | same package and registry as the line abovehigh | same change as the line above | Time to revision 713 days |
| 2026-02-17published 2024-02-13 | same kind of change as the line above | GHSA-g74q-5xw3-j7q9CVE-2024-21386 | same package and registry as the line abovehigh | same change as the line above | Time to revision 735 days |
| 2026-02-17published 2024-03-06 | same kind of change as the line above | GHSA-f6g2-h7qv-3m5vCVE-2024-27923 | same package and registry as the line abovehigh | same change as the line above | Time to revision 713 days |
| 2026-02-17published 2024-09-27 | Advisory severity changed | GHSA-9h9q-qhxg-89xrCVE-2024-47186 | whole advisorymoderate | stated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 508 days |
| 2026-02-17published 2024-03-06 | Advisory severity changed | whole advisoryhigh | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 713 to 713 days | |
| 2026-02-17published 2024-03-06 | same kind of change as the line above | GHSA-5pf6-2qwx-pxm2CVE-2024-28110 | same package and registry as the line abovehigh | same change as the line above | Time to revision 713 days |
| 2026-02-17published 2024-03-06 | same kind of change as the line above | GHSA-cgqf-3cq5-wvcjCVE-2024-28101 | same package and registry as the line abovehigh | same change as the line above | Time to revision 713 days |
| 2026-02-17published 2024-03-06 | same kind of change as the line above | GHSA-3j27-563v-28wfCVE-2024-27934 | same package and registry as the line abovehigh | same change as the line above | Time to revision 713 days |
| 2026-02-17published 2024-06-18 | Advisory severity changed | GHSA-x4gp-pqpj-f43qCVE-2024-58262 | whole advisorylow | stated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version. | Time to revision 609 days |
| Fri 13 Feb 2026· 2 changes | |||||
| 2026-02-13published 2026-02-03 | Advisory severity changed | GHSA-6426-9fv3-65x8CVE-2026-1312 | whole advisorymoderate | stated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 10 days |
| 2026-02-13published 2025-03-04 | Advisory withdrawn | GHSA-3jxr-23ph-c89g | whole advisoryhigh | withdrawn 2026-02-13 | Time to revision 346 days |
| Thu 12 Feb 2026· 4 changes | |||||
| 2026-02-12published 2026-01-20 | Advisory fix version moved | GHSA-r8w2-w357-9pjvCVE-2025-64087 | mavenfr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker critical | stated at publication 2.1.0, now states 2.2.0 | Time to revision 8 days |
| 2026-02-12published 2025-12-01 | Advisory severity changed | GHSA-rcmh-qjqh-p98vCVE-2025-14874 | whole advisoryhigh | stated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 73 days |
| 2026-02-12published 2026-01-16 | Advisory severity changed | GHSA-vx9w-5cx4-9796CVE-2026-26217 | whole advisorycritical | stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same. | Time to revision 27 days |
| 2026-02-12published 2026-02-10 | Advisory severity changed | GHSA-qvhc-9v3j-5rfwCVE-2026-21218 | whole advisoryhigh | stated at publication LOW, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 2 days |
| Wed 11 Feb 2026· 1 change | |||||
| 2026-02-11published 2019-06-06 | Advisory severity changed | GHSA-w7q7-vjp8-7jv4 | whole advisorycritical | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | Duration unknown |
| Mon 9 Feb 2026· 1 change | |||||
| 2026-02-09published 2026-02-09 | Advisory severity changed | GHSA-9f5h-mmq6-2x78CVE-2026-25496 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 0 days |
| Sat 7 Feb 2026· 1 change | |||||
| 2026-02-07published 2026-02-05 | Advisory severity changed | GHSA-x39w-8vm5-5m3pCVE-2026-25533 | whole advisorymoderate | stated at publication CRITICAL, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 1 days |
| Fri 6 Feb 2026· 1 change | |||||
| 2026-02-06published 2026-01-23 | Advisory withdrawn | GHSA-3966-f6p6-2qr9CVE-2026-0775 | whole advisoryhigh | withdrawn 2026-02-06 | Time to revision 15 days |
| Thu 5 Feb 2026· 2 changes | |||||
| 2026-02-05published 2026-01-20 | Advisory severity changed | GHSA-4gpc-rhpj-9443CVE-2026-23733 | whole advisorycritical | stated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 16 days |
| 2026-02-05published 2026-02-04 | Advisory severity changed | GHSA-8wpc-j9q9-j5m2CVE-2026-25538 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version. | Time to revision 0 days |
| Wed 4 Feb 2026· 2 changes | |||||
| 2026-02-04published 2024-06-11 | Advisory severity changed | GHSA-v5gf-r78h-55q6CVE-2024-37301 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 603 days |
| 2026-02-04published 2026-02-03 | Advisory severity changed | GHSA-7h2j-956f-4vf2CVE-2026-25547 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 days |
| Tue 3 Feb 2026· 16 changes | |||||
| 2026-02-03published 2026-02-02 | Advisory fix version moved | GHSA-gc24-px2r-5qmfCVE-2026-25505 | pypibambuddy critical | stated at publication 0.1.6.2, now states 0.1.7 | Time to revision 1 days |
| 2026-02-03published 2021-03-11 | Advisory severity changed | GHSA-gmrf-99gw-vvwjCVE-2021-46876 | whole advisorymoderate | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | Duration unknown |
| 2026-02-03published 2019-06-03 to 2026-01-26 | Advisory withdrawn | whole advisory4 bands | withdrawn 2026-02-03 | Time to revision 8 to 2,437 days | |
| 2026-02-03published 2022-02-11 | same kind of change as the line above | GHSA-76wf-9vgp-pj7w | same package and registry as the line abovemoderate | withdrawn 2026-02-03 | Time to revision 1,453 days |
| 2026-02-03published 2022-06-17 | same kind of change as the line above | GHSA-6692-8qqf-79jc | same package and registry as the line abovehigh | withdrawn 2026-02-03 | Time to revision 1,328 days |
| 2026-02-03published 2019-06-03 | same kind of change as the line above | GHSA-3fc5-9x9m-vqc4 | same package and registry as the line abovecritical | withdrawn 2026-02-03 | Time to revision 2,437 days |
| 2026-02-03published 2024-05-30 | same kind of change as the line above | GHSA-75mx-chcf-2q32 | same package and registry as the line abovemoderate | withdrawn 2026-02-03 | Time to revision 614 days |
| 2026-02-03published 2023-12-20 | same kind of change as the line above | GHSA-mhpq-9638-x6pw | same package and registry as the line abovemoderate | withdrawn 2026-02-03 | Time to revision 776 days |
| 2026-02-03published 2020-09-03 | same kind of change as the line above | GHSA-4xf9-pgvv-xx67 | same package and registry as the line abovemoderate | withdrawn 2026-02-03 | Time to revision 1,979 days |
| 2026-02-03published 2019-06-06 | same kind of change as the line above | GHSA-g95f-p29q-9xw4 | same package and registry as the line abovelow | withdrawn 2026-02-03 | Time to revision 2,434 days |
| 2026-02-03published 2026-01-26 | same kind of change as the line above | GHSA-p5wg-g6qr-c7cgCVE-2025-50537 | same package and registry as the line abovemoderate | withdrawn 2026-02-03 | Time to revision 8 days |
| 6 more rows in this change are not listed here. Open all 14 rows → | |||||
| Mon 2 Feb 2026· 6 changes | |||||
| 2026-02-02published 2024-03-15 | Package added to advisory | GHSA-qmgx-j96g-4428CVE-2024-28752 | critical | not named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-databinding-aegis | Time to revision 689 days |
| 2026-02-02published 2025-12-12 | Package added to advisory | GHSA-vx9q-rhv9-3jvgCVE-2025-67721 | high | not named as affected when the advisory was published, now names io.airlift:aircompressor | Time to revision 52 days |
| 2026-02-02published 2021-09-08 to 2024-06-04 | Advisory withdrawn | whole advisory3 bands | withdrawn 2026-02-02 | Time to revision 608 to 1,608 days | |
| 2026-02-02published 2024-06-04 | same kind of change as the line above | GHSA-2hfw-w739-p7x5 | same package and registry as the line abovecritical | withdrawn 2026-02-02 | Time to revision 608 days |
| 2026-02-02published 2021-09-08 | same kind of change as the line above | GHSA-c7vg-w8q8-c3wf | same package and registry as the line abovemoderate | withdrawn 2026-02-02 | Time to revision 1,608 days |
| 2026-02-02published 2022-12-28 | same kind of change as the line above | GHSA-4348-x292-h437 | same package and registry as the line abovelow | withdrawn 2026-02-02 | Time to revision 1,133 days |
| 2026-02-02published 2023-03-12 | same kind of change as the line above | GHSA-c737-jhwr-fqxj | same package and registry as the line abovemoderate | withdrawn 2026-02-02 | Time to revision 1,059 days |
| Thu 29 Jan 2026· 2 changes | |||||
| 2026-01-29published 2026-01-29 | Advisory severity changed | GHSA-r277-3xc5-c79vCVE-2026-24780 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 0 days |
| 2026-01-29published 2025-10-16 | Advisory severity changed | GHSA-9329-mxxw-qwf8CVE-2025-53092 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 104 days |
| Fri 23 Jan 2026· 18 changes | |||||
| 2026-01-23published 2026-01-22 | Advisory fix version moved | GHSA-j8hf-cp34-g4j7CVE-2026-24124 | god7y.io/dragonfly/v2 high | stated at publication 2.4.0, now states 2.4.1 | Time to revision 1 days |
| 2026-01-23published 2021-06-23 | Advisory severity changed | GHSA-5gjg-jgh4-gppmCVE-2021-4236 | whole advisorycritical | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | Duration unknown |
| 2026-01-23published 2022-02-10 | Advisory severity changed | GHSA-v3mr-gp7j-pw5w | whole advisorycritical | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | Duration unknown |
| 2026-01-23published 2019-05-29 to 2025-11-13 | Advisory withdrawn | whole advisory3 bands | withdrawn 2026-01-23 | Time to revision 71 to 2,431 days | |
| 2026-01-23published 2025-11-13 | same kind of change as the line above | GHSA-4249-gjr8-jpq3 | same package and registry as the line abovehigh | withdrawn 2026-01-23 | Time to revision 71 days |
| 2026-01-23published 2021-08-25 | same kind of change as the line above | GHSA-gq4h-f254-7cw9 | same package and registry as the line abovehigh | withdrawn 2026-01-23 | Time to revision 1,612 days |
| 2026-01-23published 2024-05-30 | same kind of change as the line above | GHSA-7fpj-wc8v-9cgc | same package and registry as the line abovecritical | withdrawn 2026-01-23 | Time to revision 603 days |
| 2026-01-23published 2024-05-28 | same kind of change as the line above | GHSA-fjr2-r2mp-484p | same package and registry as the line abovecritical | withdrawn 2026-01-23 | Time to revision 605 days |
| 2026-01-23published 2021-08-25 | same kind of change as the line above | GHSA-r88h-6987-g79f | same package and registry as the line abovehigh | withdrawn 2026-01-23 | Time to revision 1,612 days |
| 2026-01-23published 2022-12-28 | same kind of change as the line above | GHSA-3839-6r69-m497 | same package and registry as the line abovecritical | withdrawn 2026-01-23 | Time to revision 1,123 days |
| 2026-01-23published 2019-05-29 | same kind of change as the line above | GHSA-qr32-j4j6-3m7rCVE-2017-16087 | same package and registry as the line abovehigh | withdrawn 2026-01-23 | Time to revision 2,431 days |
| 2026-01-23published 2020-09-03 | same kind of change as the line above | GHSA-8whr-v3gm-w8h9 | same package and registry as the line abovehigh | withdrawn 2026-01-23 | Time to revision 1,968 days |
| 7 more rows in this change are not listed here. Open all 15 rows → | |||||
| Thu 22 Jan 2026· 17 changes | |||||
| 2026-01-22published 2022-04-12 | Advisory severity changed | GHSA-2xxx-fhc8-9qvqCVE-2017-20166 | whole advisorycritical | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | Duration unknown |
| 2026-01-22published 2026-01-14 | Advisory severity changed | GHSA-g9mf-h72j-4rw9CVE-2026-22036 | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 8 days |
| 2026-01-22published 2021-05-10 to 2024-01-20 | Advisory withdrawn | whole advisory3 bands | withdrawn 2026-01-22 | Time to revision 734 to 1,718 days | |
| 2026-01-22published 2021-08-30 | same kind of change as the line above | GHSA-6gvc-4jvj-pwq4 | same package and registry as the line abovemoderate | withdrawn 2026-01-22 | Time to revision 1,606 days |
| 2026-01-22published 2022-05-24 | same kind of change as the line above | GHSA-j7j6-7hfx-5522 | same package and registry as the line abovehigh | withdrawn 2026-01-22 | Time to revision 1,339 days |
| 2026-01-22published 2021-05-10 | same kind of change as the line above | GHSA-r2gr-fhmr-66c5 | same package and registry as the line abovehigh | withdrawn 2026-01-22 | Time to revision 1,718 days |
| 2026-01-22published 2024-01-19 | same kind of change as the line above | GHSA-hj55-9jmv-9jrj | same package and registry as the line abovehigh | withdrawn 2026-01-22 | Time to revision 734 days |
| 2026-01-22published 2024-01-19 | same kind of change as the line above | GHSA-hfj8-63c8-rmfw | same package and registry as the line abovehigh | withdrawn 2026-01-22 | Time to revision 734 days |
| 2026-01-22published 2024-01-19 | same kind of change as the line above | GHSA-gvc7-gjrw-hj65 | same package and registry as the line abovemoderate | withdrawn 2026-01-22 | Time to revision 734 days |
| 2026-01-22published 2024-01-19 | same kind of change as the line above | GHSA-4hrp-m3f2-643j | same package and registry as the line abovecritical | withdrawn 2026-01-22 | Time to revision 734 days |
| 2026-01-22published 2023-09-28 | same kind of change as the line above | GHSA-9xfq-8j3r-xp5g | same package and registry as the line abovecritical | withdrawn 2026-01-22 | Time to revision 848 days |
| 7 more rows in this change are not listed here. Open all 15 rows → | |||||
| Wed 21 Jan 2026· 3 changes | |||||
| 2026-01-21published 2025-05-07 | Package added to advisory | GHSA-72qj-48g4-5xgxCVE-2025-46551 | moderate | not named as affected when the advisory was published, now names jruby-openssl | Time to revision 259 days |
| 2026-01-21published 2026-01-20 | Advisory severity changed | GHSA-gfpw-jgvr-cw4jCVE-2026-22808 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 days |
| 2026-01-21published 2026-01-21 | Advisory severity changed | GHSA-2762-657x-v979CVE-2026-23885 | whole advisorymoderate | stated at publication CRITICAL, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 1 days |
| Fri 16 Jan 2026· 1 change | |||||
| 2026-01-16published 2025-10-21 | Package added to advisory | GHSA-j5gw-2vrg-8fgxCVE-2025-62518 | high | not named as affected when the advisory was published, now names tokio-tar | Time to revision 87 days |
| Thu 8 Jan 2026· 1 change | |||||
| 2026-01-08published 2026-01-07 | Advisory severity changed | GHSA-5f29-2333-h9c7CVE-2026-22244 | whole advisoryhigh | stated at publication CRITICAL, now states HIGHA CVSS version was added; the existing vectors stayed the same. | Time to revision 1 days |
| Wed 7 Jan 2026· 1 change | |||||
| 2026-01-07published 2025-11-07 | Advisory fix version moved | GHSA-f83h-ghpp-7wccCVE-2025-70559 | pypipdfminer.six high | stated at publication 20251107, now states 20251230 | Time to revision 7 days |
| Tue 6 Jan 2026· 3 changes | |||||
| 2026-01-06published 2025-12-17 | Advisory fix version moved | GHSA-3677-xxcr-wjqvCVE-2024-29371 | mavenorg.bitbucket.b_c:jose4j high | stated at publication 0.9.5, now states 0.9.6 | Time to revision 20 days |
| 2026-01-06published 2025-12-31 | Package added to advisory | GHSA-mrfv-m5wm-5w6w | moderate | not named as affected when the advisory was published, now names hdwallet and 1 more | Time to revision 7 days |
| 2026-01-06published 2025-12-31 | same kind of change as the line above | GHSA-mrfv-m5wm-5w6wCVE-2025-69277 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names hdwallet | Time to revision 7 days |
| 2026-01-06published 2025-12-31 | same kind of change as the line above | GHSA-mrfv-m5wm-5w6wCVE-2025-69277 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names pynacl | Time to revision 7 days |
| Mon 5 Jan 2026· 1 change | |||||
| 2026-01-05published 2026-01-02 | Package added to advisory | GHSA-c5cp-vx83-jhqxCVE-2026-21445 | high | not named as affected when the advisory was published, now names langflow | Time to revision 2 days |
| Fri 2 Jan 2026· 1 change | |||||
| 2026-01-02published 2025-12-30 | Advisory severity changed | GHSA-95qg-89c2-w5hjCVE-2025-69257 | whole advisoryhigh | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 3 days |
| Thu 1 Jan 2026· 1 change | |||||
| 2026-01-01published 2025-12-20 | Advisory severity changed | GHSA-83jg-m2pm-4jxjCVE-2025-34469 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same. | Time to revision 11 days |
| Mon 29 Dec 2025· 4 changes | |||||
| 2025-12-29published 2021-12-10 to 2025-12-08 | Advisory withdrawn | whole advisory3 bands | withdrawn 2025-12-29 | Time to revision 21 to 1,480 days | |
| 2025-12-29published 2024-10-02 | same kind of change as the line above | GHSA-r2jw-c95q-rj29 | same package and registry as the line abovemoderate | withdrawn 2025-12-29 | Time to revision 454 days |
| 2025-12-29published 2025-05-09 | same kind of change as the line above | GHSA-c86p-w88r-qvqr | same package and registry as the line abovemoderate | withdrawn 2025-12-29 | Time to revision 234 days |
| 2025-12-29published 2025-12-08 | same kind of change as the line above | GHSA-95fv-5gfj-2r84CVE-2025-64113 | same package and registry as the line abovecritical | withdrawn 2025-12-29 | Time to revision 21 days |
| 2025-12-29published 2021-12-10 | same kind of change as the line above | GHSA-49vv-6q7q-w5cf | same package and registry as the line abovehigh | withdrawn 2025-12-29 | Time to revision 1,480 days |
| Tue 23 Dec 2025· 1 change | |||||
| 2025-12-23published 2025-12-23 | Advisory severity changed | GHSA-pp3g-xmm4-5cw9CVE-2025-65713 | whole advisorymoderate | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 0 days |
| Mon 22 Dec 2025· 3 changes | |||||
| 2025-12-22published 2025-06-23 | Advisory fix version moved | GHSA-9623-mj7j-p9v4CVE-2025-49574 | mavenio.quarkus:quarkus-vertx moderate | stated at publication 3.24.0, now states 3.24.1 | Time to revision 182 days |
| 2025-12-22published 2022-01-06 | Package added to advisory | GHSA-x8rq-rc7x-5fg5CVE-2022-0086 | high | not named as affected when the advisory was published, now names @uppy/companion | Duration unknown |
| 2025-12-22published 2025-12-15 | Advisory withdrawn | GHSA-vr6p-vq2p-6j74 | whole advisorycritical | withdrawn 2025-12-22 | Time to revision 7 days |
| Fri 19 Dec 2025· 1 change | |||||
| 2025-12-19published 2025-11-25 | Advisory withdrawn | GHSA-93vm-mqpw-8wh3 | whole advisorymoderate | withdrawn 2025-12-19 | Time to revision 24 days |
| Thu 18 Dec 2025· 5 changes | |||||
| 2025-12-18published 2022-11-01 | Package added to advisory | GHSA-43xg-8wmj-cw8h | moderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10 and 4 more | Duration unknown |
| 2025-12-18published 2022-11-01 | same kind of change as the line above | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.10 | Duration unknown |
| 2025-12-18published 2022-11-01 | same kind of change as the line above | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.11 | Duration unknown |
| 2025-12-18published 2022-11-01 | same kind of change as the line above | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.12 | Duration unknown |
| 2025-12-18published 2022-11-01 | same kind of change as the line above | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.13 | Duration unknown |
| 2025-12-18published 2022-11-01 | same kind of change as the line above | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.apache.spark:spark-core_2.9.3 | Duration unknown |
| Tue 16 Dec 2025· 18 changes | |||||
| 2025-12-16published 2022-01-06 | Package added to advisory | GHSA-vc89-hccf-rq55 | moderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25 and 17 more | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.25 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_0.27 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.10 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.11 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.12 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-m5 | Duration unknown |
| 2025-12-16published 2022-01-06 | same kind of change as the line above | GHSA-vc89-hccf-rq55CVE-2022-21653 | same package registry as the line abovemoderate | not named as affected when the advisory was published, now names org.typelevel:jawn-parser_2.13.0-rc1 | Duration unknown |
| 10 more rows in this change are not listed here. Open all 18 rows → | |||||
| Thu 11 Dec 2025· 34 changes | |||||
| 2025-12-11published 2021-09-02 to 2025-06-10 | Package added to advisory | 32 rows, one per advisory and package | 2 bands | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.10 and 22 more | Time to revision 185 to 1,070 days |
| 2025-12-11published 2021-09-02 | same kind of change as the line above | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.10 | Duration unknown |
| 2025-12-11published 2021-09-02 | same kind of change as the line above | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.11 | Duration unknown |
| 2025-12-11published 2021-09-02 | same kind of change as the line above | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.12 | Duration unknown |
| 2025-12-11published 2021-09-02 | same kind of change as the line above | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.13 | Duration unknown |
| 2025-12-11published 2021-09-02 | same kind of change as the line above | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_2.13.0-m5 | Duration unknown |
| 2025-12-11published 2021-09-02 | same kind of change as the line above | GHSA-52cf-226f-rhr6CVE-2021-39185 | same package registry as the line abovecritical | not named as affected when the advisory was published, now names org.http4s:http4s-server_3 | Duration unknown |
| 2025-12-11published 2021-09-22 | same kind of change as the line above | GHSA-5vcm-3xc3-w7x3CVE-2021-41084 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.http4s:http4s-client_2.12 | Duration unknown |
| 2025-12-11published 2021-09-22 | same kind of change as the line above | GHSA-5vcm-3xc3-w7x3CVE-2021-41084 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.http4s:http4s-client_2.13 | Duration unknown |
| 24 more rows in this change are not listed here. Open all 32 rows → | |||||
| 2025-12-11published 2025-12-10 | Advisory severity changed | GHSA-wqv2-4wpg-8hc9CVE-2025-67713 | whole advisorymoderate | stated at publication LOW, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 1 days |
| 2025-12-11published 2025-12-03 | Advisory withdrawn | GHSA-q3hc-j9x5-mp9mCVE-2025-65955 | whole advisorymoderate | withdrawn 2025-12-11 | Time to revision 8 days |
| Tue 9 Dec 2025· 3 changes | |||||
| 2025-12-09published 2025-02-24 to 2025-10-09 | Advisory severity changed | whole advisoryhigh | stated at publication CRITICAL, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 61 to 288 days | |
| 2025-12-09published 2025-02-24 | same kind of change as the line above | GHSA-vp58-j275-797x | same package and registry as the line abovehigh | same change as the line above | Time to revision 288 days |
| 2025-12-09published 2025-10-09 | same kind of change as the line above | GHSA-99h5-pjcv-gr6vCVE-2025-61928 | same package and registry as the line abovehigh | same change as the line above | Time to revision 61 days |
| 2025-12-09published 2025-02-05 | Advisory severity changed | GHSA-9x4v-xfq5-m8x5 | whole advisorymoderate | stated at publication CRITICAL, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | Time to revision 307 days |
| Fri 5 Dec 2025· 1 change | |||||
| 2025-12-05published 2025-12-04 | Advisory fix version moved | GHSA-8ggh-xwr9-3373CVE-2025-14010 | pypiansible moderate | stated at publication 12.0.0, now states 12.2.0 | Time to revision 1 days |
| Thu 4 Dec 2025· 2 changes | |||||
| 2025-12-04published 2022-05-17 | Package added to advisory | GHSA-wwq7-pxwc-p4rcCVE-2012-5785 | moderate | not named as affected when the advisory was published, now names org.apache.axis2:axis2-transport-http | Duration unknown |
| 2025-12-04published 2024-02-29 | Advisory severity changed | GHSA-9vx6-7xxf-x967CVE-2024-27094 | whole advisorymoderate | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | Time to revision 644 days |
| Tue 2 Dec 2025· 4 changes | |||||
| 2025-12-02published 2025-10-28 to 2025-12-01 | Advisory withdrawn | whole advisory3 bands | withdrawn 2025-12-02 | Time to revision 1 to 35 days | |
| 2025-12-02published 2025-12-01 | same kind of change as the line above | GHSA-pj86-cfqh-vqx6CVE-2024-51999 | same package and registry as the line abovelow | withdrawn 2025-12-02 | Time to revision 1 days |
| 2025-12-02published 2025-10-28 | same kind of change as the line above | GHSA-c6cm-5gc7-c3f4 | same package and registry as the line abovelow | withdrawn 2025-12-02 | Time to revision 35 days |
| 2025-12-02published 2025-10-30 | same kind of change as the line above | GHSA-28jp-44vh-q42h | same package and registry as the line abovehigh | withdrawn 2025-12-02 | Time to revision 32 days |
| 2025-12-02published 2025-11-13 | same kind of change as the line above | GHSA-7m9g-pmxf-m9m8 | same package and registry as the line abovemoderate | withdrawn 2025-12-02 | Time to revision 18 days |
| Mon 1 Dec 2025· 1 change | |||||
| 2025-12-01published 2025-12-01 | Advisory fix version moved | GHSA-pj86-cfqh-vqx6CVE-2024-51999 | npmexpress low | stated at publication 5.1.0, now states 5.2.0 | Time to revision 0 days |
| Thu 20 Nov 2025· 1 change | |||||
| 2025-11-20published 2025-09-24 | Advisory withdrawn | GHSA-ffrw-9mx8-89p8CVE-2025-57319 | whole advisorylow | withdrawn 2025-11-20 | Time to revision 57 days |
| Tue 18 Nov 2025· 1 change | |||||
| 2025-11-18published 2025-11-13 | Package added to advisory | GHSA-3g2j-vm47-x4mj | high | not named as affected when the advisory was published, now names github.com/canonical/lxd | Time to revision 5 days |
| Mon 17 Nov 2025· 5 changes | |||||
| 2025-11-17published 2025-11-06 | Package added to advisory | moderate | not named as affected when the advisory was published, now names kubevirt.io/kubevirt | Time to revision 11 days | |
| 2025-11-17published 2025-11-06 | same kind of change as the line above | GHSA-7xgm-5prm-v5gcCVE-2025-64436 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-06 | same kind of change as the line above | GHSA-9m94-w2vq-hcf9CVE-2025-64435 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-06 | same kind of change as the line above | GHSA-2r4r-5x78-mvqfCVE-2025-64437 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-06 | same kind of change as the line above | GHSA-qw6q-3pgr-5cwqCVE-2025-64433 | same package registry as the line abovemoderate | same change as the line above | Time to revision 11 days |
| 2025-11-17published 2025-11-04 | Advisory severity changed | GHSA-5pmx-7r6r-wfqq | whole advisorymoderate | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | Time to revision 13 days |
| Sat 15 Nov 2025· 3 changes | |||||
| 2025-11-15published 2025-11-07 | Package added to advisory | GHSA-46xp-26xh-hpqhCVE-2025-64324 | high | not named as affected when the advisory was published, now names kubevirt.io/kubevirt | Time to revision 7 days |
| 2025-11-15published 2025-10-30 | Advisory severity changed | GHSA-cf57-c578-7jvvCVE-2025-64716 | whole advisorymoderate | stated at publication LOW, now states MODERATEA CVSS version was added; the existing vectors stayed the same. | Time to revision 15 days |
| 2025-11-15published 2019-10-07 | Advisory severity changed | GHSA-85rf-xh54-whp3CVE-2024-22050 | whole advisoryhigh | stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version. | Duration unknown |
| Thu 13 Nov 2025· 2 changes | |||||
| 2025-11-13published 2025-11-03 | Package added to advisory | GHSA-399j-vxmf-hjvrCVE-2025-11953 | critical | not named as affected when the advisory was published, now names @react-native-community/cli-server-api | Time to revision 10 days |
| 2025-11-13published 2025-07-30 | Package added to advisory | GHSA-cx25-xg7c-xfm5CVE-2025-54656 | moderate | not named as affected when the advisory was published, now names struts:struts | Time to revision 106 days |
| Mon 10 Nov 2025· 1 change | |||||
| 2025-11-10published 2025-11-07 | Advisory withdrawn | GHSA-vfpf-xmwh-8m65 | whole advisoryhigh | withdrawn 2025-11-10 | Time to revision 3 days |
| Fri 7 Nov 2025· 1 change | |||||
| 2025-11-07published 2025-10-31 | Package added to advisory | GHSA-2qfp-q593-8484CVE-2025-6176 | high | not named as affected when the advisory was published, now names scrapy | Time to revision 8 days |
| Tue 4 Nov 2025· 2 changes | |||||
| 2025-11-04published 2023-12-01 | Package added to advisory | GHSA-qw4h-3xjj-84cc | high | not named as affected when the advisory was published, now names org.apache.struts:struts-tiles and 1 more | Time to revision 705 days |
| 2025-11-04published 2023-12-01 | same kind of change as the line above | GHSA-qw4h-3xjj-84ccCVE-2023-49735 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names org.apache.struts:struts-tiles | Time to revision 705 days |
| 2025-11-04published 2023-12-01 | same kind of change as the line above | GHSA-qw4h-3xjj-84ccCVE-2023-49735 | same package registry as the line abovehigh | not named as affected when the advisory was published, now names struts:struts | Time to revision 705 days |
Counted in advisories, never added to the CVE and KEV figures. Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
What this page cannot see
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →
Paste your closed CVE tickets and see which of these changes hit them →