Skip to content

[GHSA-66cv-5wq4-p78m] Add finder credit and affected package range (CVE-2026-81829) - #9648

Open
ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9648from
ByteHackr:cve-2026-81829-credit-GHSA-66cv-5wq4-p78m
Open

ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9648from
ByteHackr:cve-2026-81829-credit-GHSA-66cv-5wq4-p78m

Conversation

@ByteHackr

@ByteHackr ByteHackr commented Sep 20, 2026

Copy link
Copy Markdown

Adds a credits entry crediting Sandipan Roy (@ByteHackr) as FINDER, and fills in the empty affected field with a verified Maven package range, plus supporting references.

1. Finder credit

Public evidence supporting this credit:

The credits structure follows the OSV schema and the convention already used in this repository (e.g. merged PR #7190).

2. Affected package range

affected was empty; populated with io.smallrye:smallrye-jwt (Maven), range >= 4.3.0, < 4.6.4 — all versions verified against upstream sources:

These coordinates align this entry with repository security advisory GHSA-7x9g-wc63-whmg for the same CVE.


Per CONTRIBUTING.md this PR touches exactly one advisory. Happy to adjust the range or details as the curation team sees fit — and if appropriate, would this advisory be a candidate for review given the package mapping and existing RSA for the same CVE? Thanks!

@github-actions
github-actions Bot changed the base branch from main to ByteHackr/advisory-improvement-9648 September 20, 2026 19:04
@ByteHackr

Copy link
Copy Markdown
Author

Thanks! Aside from the credit, would the curation team be able to consider this advisory for review (i.e., upgrade it from the NVD mirror entry to a reviewed advisory)? Note that a repository security advisory for this vulnerability already exists in smallrye/smallrye-jwt (GHSA-7x9g-wc63-whmg, published by the maintainer), and this database entry affects Maven ecosystem packages (io.smallrye:smallrye-jwt, quarkus-smallrye-jwt). Happy to help with any additional information to make the review possible.

@ByteHackr

Copy link
Copy Markdown
Author

Updating this PR with the affected package range so the advisory can be considered for review. All versions verified against upstream sources:

Affected package: io.smallrye:smallrye-jwt (Maven) — artifact containing the vulnerable AwsAlbKeyResolver class.

Affected range: >= 4.3.0, < 4.6.4 — evidence:

Also added WEB references for the fix PR and the patched release. These coordinates should align this entry with repository security advisory GHSA-7x9g-wc63-whmg for the same CVE.

@ByteHackr
ByteHackr force-pushed the cve-2026-81829-credit-GHSA-66cv-5wq4-p78m branch from 839355b to e3ebfce Compare September 20, 2026 19:54
@ByteHackr ByteHackr changed the title Add finder credit for GHSA-66cv-5wq4-p78m [GHSA-66cv-5wq4-p78m] Add finder credit and affected package range (CVE-2026-81829) Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant