{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://data.datagrok.ai/vex/core.json",
  "author": "Datagrok",
  "timestamp": "2026-09-07T01:06:28Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2015-9019"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2016-20013"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2016-2781"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2017-11164"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-1000021"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-10126"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-14628"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-5709"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2020-10735"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2020-25697"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2020-25720"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2021-20251"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2021-20316"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2021-31879"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2021-44141"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-1615"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-24975"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-27943"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-3219"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-32743"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-41409"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-4899"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-29383"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-31486"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-47039"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-50495"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-52355"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-10041"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-10524"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-2236"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-52005"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-56433"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-10911"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-11731"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12781"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-15366"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-15367"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-15649"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-5222"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-5278"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-59375"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-6141"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-64756"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-66382"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-0864"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-11940"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-11972"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-11979"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12087"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12912"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13149"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13221"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13595"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13757"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-14257"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-15308"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-15370"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-15534"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-15806"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-17084"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18503"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18938"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19487"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19672"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-23745"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-23950"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-24001"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-24842"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-26960"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-26996"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-27456"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-27903"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-27904"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-29786"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-31802"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-32776"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-32777"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-32778"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-33671"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-33672"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-33750"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-3446"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-36849"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-41080"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-41907"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42250"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42338"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42497"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42533"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-4360"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-45186"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-4739"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-4775"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48758"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48815"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48959"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48961"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48962"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-50219"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53613"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53615"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53655"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53910"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54369"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54370"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54371"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56131"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56132"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56391"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56392"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56403"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56404"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56405"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56406"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56407"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56408"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56409"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56410"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56411"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56412"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57062"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57432"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57433"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59843"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59844"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59845"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59846"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59847"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59848"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59849"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59850"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59851"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59871"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59873"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59874"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59875"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6368"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-66046"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-67422"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6791"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6879"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69152"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69192"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-7017"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-7210"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-72522"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-73566"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-75803"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-76641"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-76956"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-76957"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-8932"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9538"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9672"
      },
      "products": [
        {
          "@id": "pkg:oci/datagrok@sha256:52a34e25f3fde4d6b650df318ba5eb7b2d4252cdf1d654be7dd31602ac3c9f5e?tag=1.27.9"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2016-20013"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2016-2781"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2017-11164"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-5709"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-27943"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-3219"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-41409"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-4899"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-29383"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-31486"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-47039"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-50495"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-10041"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-2236"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-56433"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-6763"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "jetty-http HttpURI lenient authority parsing affects applications that use the HttpURI class programmatically for URI validation/redirect construction. Neither spark-java 2.9.4 route handling nor grok_connect code calls HttpURI (no redirects are ever issued); the fix exists only in jetty 12 (Java 17). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-15649"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-5278"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-59250"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "mssql-jdbc 12.10.2.jre8 (previously 12.8.2.jre8) is well past the fix wave; scanners mis-order the bare '12.10.2' from the jar's pom.properties against the '12.8.2.jre11' fixed-version string because the .jreN suffix breaks their version comparators (known Trivy/Grype issue: aquasecurity/trivy#9745, anchore/grype#3042). The jre11 artifact cannot be used on the Java-8 runtime. Applies to any X.Y.Z.jre8 >= 12.8.2."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-6141"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-10050"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "jetty-security Digest-authentication bypass (ISO-8859-1 encoding collision). Fixed only in jetty 12.0.36/12.1.10; 9.4 is EOL (NES-only backport) and jetty 10+ needs Java 11. Not in the execute path: grok_connect configures NO HTTP authentication â€” spark-java 2.9.4 wires no SecurityHandler/LoginService, so jetty's DigestAuthenticator is never instantiated; the service is cluster-internal with datlas as its only client. Re-review if HTTP auth is ever added or the spark/jetty stack changes. Verified 2026-08-12."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-10532"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "Same surface as CVE-2026-9828: object injection via the SimpleSocketServer/SimpleSSLSocketServer receivers, which grok_connect never runs (appender-only logback.xml, no receiver/server components). Fixed only in 1.5.34 (Java 11+). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12087"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-1225"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "logback-core config-processing ACE requires an attacker to MODIFY the logback configuration file. grok_connect's logback.xml is compiled into the read-only shaded jar (src/main/resources/logback.xml), the process runs as the non-root 'grok' user, and the entrypoint sets no -Dlogback.configurationFile override — there is no writable or externally-supplied config path. Fixed only in logback 1.5.25 (Java 11+); 1.3.x is the Java-8 ceiling. Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13221"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13595"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13757"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-15534"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18938"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19487"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-2332"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "jetty-http request smuggling via chunk-extension quoted-string parsing. No OSS fix exists on the Java-8-compatible jetty 9.4 line (9.4.58.v20250814 is the newest on Maven Central and is in the affected range; the advisory's 9.4.60 fix ships only in the HeroDevs NES fork; jetty 10+ needs Java 11). Not adversary-controllable in our topology: grok_connect listens cluster-internally on :1234 with datlas as its ONLY client, connecting directly with no HTTP intermediary (proxy/LB/cache) in between â€” request smuggling requires a parsing-differential between two HTTP hops, and user input reaches grok_connect solely inside JSON bodies of datlas-composed requests, never as raw protocol elements. Re-review if grok_connect is ever exposed through an ingress/proxy or the spark-java/jetty stack changes. Verified 2026-08-12."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-27456"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42250"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42497"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48959"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48961"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48962"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53613"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53615"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53910"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54369"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54370"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54371"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56391"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56392"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57062"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57432"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57433"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59949"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6368"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6790"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "jetty-server Host/authority desynchronization matters where authority selects behavior: virtual hosts, redirects, caches, reverse-proxy routing, request-log trust. grok_connect has none of these (single spark-java route set, no vhosts, no redirects, no cache) and is cluster-internal with datlas as its only client, connecting directly with no proxy hop whose routing could be confused. No fix on the Java-8-compatible jetty 9.4 line (9.4.58 is the newest on Maven Central; later 9.4.x numbers are the commercial NES fork). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6791"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-7017"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-75803"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9538"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9828"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect@sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "logback-core HardenedObjectInputStream object-injection is reachable only through the SimpleSocketServer/SimpleSSLSocketServer serialized-event receivers. grok_connect never instantiates them: logback.xml configures only ConsoleAppender, AsyncAppender and the in-process QueryStreamAppender (verified src/main/resources/logback.xml). Fixed only in 1.5.33 (Java 11+). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2010-4756"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-20796"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2019-1010022"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2019-1010023"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2019-1010024"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2019-1010025"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2019-9192"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-14456"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-14457"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18374"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18798"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19499"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19542"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-27171"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-5435"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-5450"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54874"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-5928"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6238"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63072"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63073"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63074"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63075"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-63076"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6368"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6791"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-75803"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-77117"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-80489"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_adbc@sha256:835f4e9c348186401747e85fd7c21191461cb48d09462c5c652902a40b4fafb0?tag=0.1.0"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2016-20013"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2016-2781"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2017-11164"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2018-5709"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2020-8908"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2021-35515"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2021-35516"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2021-35517"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2021-36090"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2021-39239"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2022-27943"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-3219"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-41409"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2022-4899"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-1370"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2023-29383"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-2976"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2023-31486"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-47039"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2023-50495"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-10041"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-21634"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-2236"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-25710"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-29025"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-29131"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-29133"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-47535"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-47554"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-56433"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2024-6763"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "jetty-http HttpURI lenient authority parsing affects applications that use the HttpURI class programmatically for URI validation/redirect construction. Neither spark-java 2.9.4 route handling nor grok_connect code calls HttpURI (no redirects are ever issued); the fix exists only in jetty 12 (Java 17). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-7254"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-15649"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-24970"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-25193"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-48734"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-48924"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-5278"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-52999"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-55163"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-58056"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-58057"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-59250"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "mssql-jdbc 12.10.2.jre8 (previously 12.8.2.jre8) is well past the fix wave; scanners mis-order the bare '12.10.2' from the jar's pom.properties against the '12.8.2.jre11' fixed-version string because the .jreN suffix breaks their version comparators (known Trivy/Grype issue: aquasecurity/trivy#9745, anchore/grype#3042). The jre11 artifact cannot be used on the Java-8 runtime. Applies to any X.Y.Z.jre8 >= 12.8.2."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-59419"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-6141"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2025-67735"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-68161"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-10050"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "jetty-security Digest-authentication bypass (ISO-8859-1 encoding collision). Fixed only in jetty 12.0.36/12.1.10; 9.4 is EOL (NES-only backport) and jetty 10+ needs Java 11. Not in the execute path: grok_connect configures NO HTTP authentication â€” spark-java 2.9.4 wires no SecurityHandler/LoginService, so jetty's DigestAuthenticator is never instantiated; the service is cluster-internal with datlas as its only client. Re-review if HTTP auth is ever added or the spark/jetty stack changes. Verified 2026-08-12."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-10532"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "Same surface as CVE-2026-9828: object injection via the SimpleSocketServer/SimpleSSLSocketServer receivers, which grok_connect never runs (appender-only logback.xml, no receiver/server components). Fixed only in 1.5.34 (Java 11+). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12087"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-1225"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "logback-core config-processing ACE requires an attacker to MODIFY the logback configuration file. grok_connect's logback.xml is compiled into the read-only shaded jar (src/main/resources/logback.xml), the process runs as the non-root 'grok' user, and the entrypoint sets no -Dlogback.configurationFile override — there is no writable or externally-supplied config path. Fixed only in logback 1.5.25 (Java 11+); 1.3.x is the Java-8 ceiling. Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13221"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13595"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-13757"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-15534"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-18938"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-19487"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-2332"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "jetty-http request smuggling via chunk-extension quoted-string parsing. No OSS fix exists on the Java-8-compatible jetty 9.4 line (9.4.58.v20250814 is the newest on Maven Central and is in the affected range; the advisory's 9.4.60 fix ships only in the HeroDevs NES fork; jetty 10+ needs Java 11). Not adversary-controllable in our topology: grok_connect listens cluster-internally on :1234 with datlas as its ONLY client, connecting directly with no HTTP intermediary (proxy/LB/cache) in between â€” request smuggling requires a parsing-differential between two HTTP hops, and user input reaches grok_connect solely inside JSON bodies of datlas-composed requests, never as raw protocol elements. Re-review if grok_connect is ever exposed through an ingress/proxy or the spark-java/jetty stack changes. Verified 2026-08-12."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-27456"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-33870"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-33871"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-34477"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-34480"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-41417"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42250"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42497"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42578"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42579"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42580"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42581"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42583"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42584"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42585"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42586"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-42587"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-44248"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-44249"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-44250"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-44890"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-44891"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-44893"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-45205"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-45416"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-45536"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-45673"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-45674"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-46340"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-47244"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-47691"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48006"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48043"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48059"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48959"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48961"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-48962"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-49844"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-50010"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-50011"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-50020"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-50193"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-50560"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53613"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53615"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-53910"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54369"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54370"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54371"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54399"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54428"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54512"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54513"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54514"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54515"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-55831"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-55833"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-55851"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56391"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56392"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56745"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56746"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56817"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56818"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56819"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56820"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56821"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-56822"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57062"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57432"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-57433"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59898"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59899"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59900"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59901"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59902"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59903"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59919"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59920"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59921"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59949"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6368"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-64607"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6790"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "jetty-server Host/authority desynchronization matters where authority selects behavior: virtual hosts, redirects, caches, reverse-proxy routing, request-log trust. grok_connect has none of these (single spark-java route set, no vhosts, no redirects, no cache) and is cluster-internal with datlas as its only client, connecting directly with no proxy hop whose routing could be confused. No fix on the Java-8-compatible jetty 9.4 line (9.4.58 is the newest on Maven Central; later 9.4.x numbers are the commercial NES fork). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6791"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-7017"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-73507"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-73508"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-75803"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9538"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9828"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "logback-core HardenedObjectInputStream object-injection is reachable only through the SimpleSocketServer/SimpleSSLSocketServer serialized-event receivers. grok_connect never instantiates them: logback.xml configures only ConsoleAppender, AsyncAppender and the in-process QueryStreamAppender (verified src/main/resources/logback.xml). Fixed only in 1.5.33 (Java 11+). Verified 2026-08-13."
    },
    {
      "vulnerability": {
        "name": "GHSA-r7wm-3cxj-wff9"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_connect_extended@sha256:0d818c930f6793b045805525527d9b4ae371b30b91d69cbea078937a0f44a0be?tag=2.8.4"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-4873"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-5545"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-5773"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6253"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6276"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-6429"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-7009"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-7168"
      },
      "products": [
        {
          "@id": "pkg:oci/grok_registry_proxy@sha256:af3e0f2bb1d1e37b5737b5211d6928588f630d1961a7fade39c4e79507a21200?tag=1.30.2"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-41907"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_nodejs@sha256:f8b23babf6685f4beefd957fda0691a7445c21daac3df5b5175e207dc356e07c?tag=1.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2024-55459"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "keras 2.15 is the last Keras-2 release; every fix for this advisory is Keras-3-only, and the kernel keeps Keras 2 while efficientnet and tf.keras (Keras-2 API) user scripts depend on it. Exploitation requires the kernel to load an attacker-supplied model/config file � in this image the only actor able to do that is the script author, who already executes arbitrary code in the same kernel process by design (server-side scripting), so no privilege boundary is crossed."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12058"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12060"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-3000"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-9906"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-0994"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "python-protobuf is capped <5 by tensorflow 2.15 (kept for the Keras-2 API). The parse-time resource exhaustion can only be triggered by input the script author feeds their own kernel process, which they can already terminate directly; no other principal parses protobuf here."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-11816"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12479"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12480"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12481"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12482"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12484"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-1462"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9335"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design � same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2018-10237"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_r@sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "guava 19.0 is vendored inside the r2pmml CRAN package's bundled Java converter jar (inst/java). The image ships no Java runtime, so the jar can never be loaded; r2pmml's Java conversion path is inert in this image."
    },
    {
      "vulnerability": {
        "name": "CVE-2020-8908"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_r@sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "guava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237."
    },
    {
      "vulnerability": {
        "name": "CVE-2023-2976"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_r@sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "guava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237."
    }
  ]
}
