{"id":"CGA-8582-mxmr-6462","modified":"2026-09-07T01:29:20.170886180Z","published":"2026-01-26T20:04:01Z","upstream":["CVE-2015-2156","GHSA-xfv3-rrfm-f2rv"],"references":[{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159379.html"},{"type":"ADVISORY","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159166.html"},{"type":"ADVISORY","url":"http://netty.io/news/2015/05/08/3-9-8-Final-and-3.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/05/17/1"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/74704"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1222923"},{"type":"ADVISORY","url":"https://github.com/netty/netty/pull/3754"},{"type":"ADVISORY","url":"https://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2015/05/17/1"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1222923"},{"type":"WEB","url":"https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/a19bb1003b0d6cd22475ba83c019b4fc7facfef2a9e13f71132529d3%40%3Ccommits.cassandra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/dc1275aef115bda172851a231c76c0932d973f9ffd8bc375c4aba769%40%3Ccommits.cassandra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E"}],"affected":[{"package":{"name":"hadoop-fips-3.4.2","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/hadoop-fips-3.4.2?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_name":"netty","component_version":"3.5.2.Final","component_type":"java-archive","component_location":"/usr/share/m2/repository/io/netty/netty/3.5.2.Final/netty-3.5.2.Final.jar","component_purl":"pkg:maven/netty@3.5.2.Final","latest_event_status":"detection","latest_event_timestamp":"2026-01-26T20:04:01Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-8582-mxmr-6462.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}