{"id":"UBUNTU-CVE-2026-58212","details":"Rejected reason: Further research determined the issue is not a vulnerability based on CNA Rule 4.1.12 The act of updating Product dependencies MUST NOT be determined to be a Vulnerability, regardless of whether the dependencies have Vulnerabilities.","modified":"2026-07-15T19:47:48.501057352Z","published":"2026-07-08T20:16:00Z","upstream":["CVE-2026-58212"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58212"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-58212"},{"type":"REPORT","url":"https://github.com/nats-io/nats-server/security/advisories/GHSA-g33f-6538-grxh"}],"affected":[{"package":{"name":"golang-github-nats-io-nkeys","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/golang-github-nats-io-nkeys?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.4.10-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.4.10-1","binary_name":"golang-github-nats-io-nkeys-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58212.json"}},{"package":{"name":"nats-server","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/nats-server?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.10.24-1","2.10.27-1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-nats-io-nats-server-dev","binary_version":"2.10.27-1"},{"binary_name":"nats-server","binary_version":"2.10.27-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58212.json"}}],"schema_version":"1.7.5","severity":[{"type":"Ubuntu","score":"medium"}]}