{"id":"CGA-q6g8-5m5p-c2gr","modified":"2026-10-06T04:31:49.980422766Z","published":"2026-10-06T01:45:48Z","upstream":["CVE-2026-54875","GHSA-q4gq-r6f8-q6q9"],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54875.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260929.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"}],"affected":[{"package":{"name":"openssl-provider-fips-3.4.0","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/openssl-provider-fips-3.4.0?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2026-10-06T01:45:48Z","component_name":"openssl-provider-fips-3.4.0","component_version":"3.4.0-r5","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/openssl-provider-fips-3.4.0@3.4.0-r5","latest_event_status":"detection"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-q6g8-5m5p-c2gr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}