{"id":"CGA-7m63-cpg7-46mj","modified":"2026-09-07T01:28:43.239938802Z","published":"2026-07-02T02:06:57Z","upstream":["CVE-2023-28155","GHSA-p8p7-x288-28g6"],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28155"},{"type":"WEB","url":"https://github.com/request/request/issues/3442"},{"type":"WEB","url":"https://github.com/cypress-io/request/pull/28"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/2500"},{"type":"WEB","url":"https://github.com/request/request/pull/3444"},{"type":"WEB","url":"https://github.com/cypress-io/request/commit/c5bcf21d40fb61feaff21a0e5a2b3934a440024f"},{"type":"WEB","url":"https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf"},{"type":"WEB","url":"https://github.com/cypress-io/request/blob/master/lib/redirect.js#L116"},{"type":"WEB","url":"https://github.com/cypress-io/request/releases/tag/v3.0.0"},{"type":"PACKAGE","url":"https://github.com/request/request"},{"type":"WEB","url":"https://github.com/request/request/blob/master/lib/redirect.js#L111"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230413-0007"}],"affected":[{"package":{"name":"py3.12-captum","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/py3.12-captum?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r1"}]}],"ecosystem_specific":{"components":[{"latest_event_status":"fixed","latest_event_timestamp":"2026-07-08T14:16:59Z","component_name":"request","component_version":"2.88.2","component_type":"npm","component_location":"/usr/lib/python3.12/site-packages/website/yarn.lock","component_purl":"pkg:npm/request@2.88.2"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-7m63-cpg7-46mj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}