{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-1527",
        "tracking": {
            "current_release_date": "2026-04-01T09:56:13.456179Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-1527",
            "initial_release_date": "2026-03-12T20:39:04.596348Z",
            "revision_history": [
                {
                    "date": "2026-03-12T20:39:04.596348Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T20:39:07.370604Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-12T21:42:49.301055Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T21:42:57.789805Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T00:28:32.694881Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (48).| Product Identifiers created (12).| Product Remediations created (48).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-13T00:28:47.230292Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T07:37:34.738637Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T14:33:58.563706Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-13T18:39:06.432227Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-13T18:43:40.540652Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (1)."
                },
                {
                    "date": "2026-03-13T18:43:43.218157Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T21:49:09.587219Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-13T21:49:15.365187Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T15:28:40.287189Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T10:10:55.385070Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T18:34:51.530547Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| Product Identifiers created (2).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T18:34:53.911607Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T12:05:56.175960Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (3)."
                },
                {
                    "date": "2026-03-31T12:05:57.917482Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-01T09:56:12.409451Z",
                    "number": "20",
                    "summary": "Products connected (1).| References created (1)."
                }
            ],
            "status": "interim",
            "version": "20"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<13.0.7.0",
                                "product": {
                                    "name": "vers:unknown/<13.0.7.0",
                                    "product_id": "CSAFPID-5963615"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "App Connect Enterprise"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1337760",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ibm:app_connect_enterprise:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "IBM App Connect Enterprise"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-2552001",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:cryostat:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Cryostat 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-2524222",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_lightspeed"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Lightspeed"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1919971",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Pipelines"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1508265",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:rhdh:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Developer Hub"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439302",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439304",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jbosseapxp"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-1441150",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_devspaces:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Dev Spaces"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-5486263",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_portal:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Self-service automation portal 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5486265"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-portal"
                            }
                        ],
                        "category": "product_family",
                        "name": "Self-service automation portal 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811032"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508266"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhdh-hub-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Developer Hub"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467450"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "code-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360369"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "code-sshd-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-4534155"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "openvsx-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Dev Spaces"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2698055"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "io.cryostat-cryostat"
                            }
                        ],
                        "category": "product_family",
                        "name": "Cryostat 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222662"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "lightspeed-console-plugin-pf5-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1851477"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "lightspeed-console-plugin-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Lightspeed"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1706524"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2652741"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5438677"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs22"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5438679"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs24"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1851478"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-dashboard-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068100"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-datascience-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068103"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-minimal-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068105"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-pytorch-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222767"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068108"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-pytorch-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068110"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-tensorflow-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5155537"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-tensorflow-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068114"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-codeserver-datascience-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068116"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-datascience-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068119"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-minimal-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068121"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-minimal-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068123"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-minimal-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068126"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-pytorch-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222780"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068128"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-pytorch-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068131"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-tensorflow-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5155538"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-tensorflow-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068134"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-trustyai-cpu-py312-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1837475"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "org.keycloak-keycloak-parent"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1837476"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "org.keycloak-keycloak-parent"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847200"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pipelines-console-plugin-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847201"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pipelines-console-plugin-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Pipelines"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1409017"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-undici"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<6.24.0",
                                "product": {
                                    "name": "vers:unknown/<6.24.0",
                                    "product_id": "CSAFPID-5873818",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=7.0.0|<7.24.0",
                                "product": {
                                    "name": "vers:unknown/>=7.0.0|<7.24.0",
                                    "product_id": "CSAFPID-5873819",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "undici"
                    }
                ],
                "category": "vendor",
                "name": "nodejs"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/6.24.0:7.24.0",
                                "product": {
                                    "name": "vers:unknown/6.24.0:7.24.0",
                                    "product_id": "CSAFPID-5810745"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<6.24.0;7.0.0<7.24.0",
                                "product": {
                                    "name": "vers:unknown/<6.24.0;7.0.0<7.24.0",
                                    "product_id": "CSAFPID-5810744"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "undici"
                    }
                ],
                "category": "vendor",
                "name": "undici"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-1527",
            "cwe": {
                "id": "CWE-93",
                "name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\\r\\n) to:\n\n  *  Inject arbitrary HTTP headers\n  *  Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch)\nThe vulnerability exists because undici writes the upgrade value directly to the socket without validating for invalid header characters:\n\n// lib/dispatcher/client-h1.js:1121\nif (upgrade) {\n  header += `connection: upgrade\\r\\nupgrade: ${upgrade}\\r\\n`\n}",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-1527"
                },
                {
                    "category": "description",
                    "text": "ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\\r\\n) to:\n\n  *  Inject arbitrary HTTP headers\n  *  Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch)\nThe vulnerability exists because undici writes the upgrade value directly to the socket without validating for invalid header characters:\n\n// lib/dispatcher/client-h1.js:1121\nif (upgrade) {\n  header += `connection: upgrade\\r\\nupgrade: ${upgrade}\\r\\n`\n}",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-1527"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in undici, a Node.js HTTP/1.1 client. This vulnerability allows a remote attacker to inject malicious data into HTTP headers or prematurely end HTTP requests by sending specially crafted input to the `upgrade` option of `client.request()`. This is possible because undici does not properly validate input for invalid header characters, which could lead to unauthorized information disclosure or bypassing of security controls.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-1527"
                },
                {
                    "category": "description",
                    "text": "ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\\r\\n) to:    *  Inject arbitrary HTTP headers   *  Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch) The vulnerability exists because undici writes the upgrade value directly to the socket without validating for invalid header characters:  // lib/dispatcher/client-h1.js:1121 if (upgrade) {   header += `connection: upgrade\\r\\nupgrade: ${upgrade}\\r\\n` }",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-1527"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\nWhen an application passes user-controlled input to the `upgrade` option of `client.request()`, an attacker can inject CRLF sequences (`\\r\\n`) to:\n\n1. Inject arbitrary HTTP headers\n2. Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch)\n\nThe vulnerability exists because undici writes the `upgrade` value directly to the socket without validating for invalid header characters:\n\n```javascript\n// lib/dispatcher/client-h1.js:1121\nif (upgrade) {\n  header += `connection: upgrade\\r\\nupgrade: ${upgrade}\\r\\n`\n}\n```\n\n### Patches\n\n Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.\n\n### Workarounds\n\nSanitize the `upgrade` option string before passing to undici:\n\n```javascript\nfunction sanitizeUpgrade(value) {\n  if (/[\\r\\n]/.test(value)) {\n    throw new Error('Invalid upgrade value')\n  }\n  return value\n}\n\nclient.request({\n  upgrade: sanitizeUpgrade(userInput)\n})\n```",
                    "title": "github - https://github.com/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\nWhen an application passes user-controlled input to the `upgrade` option of `client.request()`, an attacker can inject CRLF sequences (`\\r\\n`) to:\n\n1. Inject arbitrary HTTP headers\n2. Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch)\n\nThe vulnerability exists because undici writes the `upgrade` value directly to the socket without validating for invalid header characters:\n\n```javascript\n// lib/dispatcher/client-h1.js:1121\nif (upgrade) {\n  header += `connection: upgrade\\r\\nupgrade: ${upgrade}\\r\\n`\n}\n```\n\n### Patches\n\n Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.\n\n### Workarounds\n\nSanitize the `upgrade` option string before passing to undici:\n\n```javascript\nfunction sanitizeUpgrade(value) {\n  if (/[\\r\\n]/.test(value)) {\n    throw new Error('Invalid upgrade value')\n  }\n  return value\n}\n\nclient.request({\n  upgrade: sanitizeUpgrade(userInput)\n})\n```",
                    "title": "github - https://api.github.com/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "description",
                    "text": "ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\\r\\n) to:\n\n  *  Inject arbitrary HTTP headers\n  *  Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch)\nThe vulnerability exists because undici writes the upgrade value directly to the socket without validating for invalid header characters:\n\n// lib/dispatcher/client-h1.js:1121\nif (upgrade) {\n  header += `connection: upgrade\\r\\nupgrade: ${upgrade}\\r\\n`\n}",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-1527"
                },
                {
                    "category": "other",
                    "text": "0.00023",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5810744",
                    "CSAFPID-1439279",
                    "CSAFPID-1439302",
                    "CSAFPID-1439304",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1441150",
                    "CSAFPID-1508265",
                    "CSAFPID-1508266",
                    "CSAFPID-1706524",
                    "CSAFPID-1837475",
                    "CSAFPID-1837476",
                    "CSAFPID-1851477",
                    "CSAFPID-1851478",
                    "CSAFPID-1919971",
                    "CSAFPID-2467450",
                    "CSAFPID-2524222",
                    "CSAFPID-2552001",
                    "CSAFPID-2652741",
                    "CSAFPID-2698055",
                    "CSAFPID-2847200",
                    "CSAFPID-2847201",
                    "CSAFPID-2858634",
                    "CSAFPID-4534155",
                    "CSAFPID-5068100",
                    "CSAFPID-5068103",
                    "CSAFPID-5068105",
                    "CSAFPID-5068108",
                    "CSAFPID-5068110",
                    "CSAFPID-5068114",
                    "CSAFPID-5068116",
                    "CSAFPID-5068119",
                    "CSAFPID-5068121",
                    "CSAFPID-5068123",
                    "CSAFPID-5068126",
                    "CSAFPID-5068128",
                    "CSAFPID-5068131",
                    "CSAFPID-5068134",
                    "CSAFPID-5155537",
                    "CSAFPID-5155538",
                    "CSAFPID-5222662",
                    "CSAFPID-5222767",
                    "CSAFPID-5222780",
                    "CSAFPID-5360369",
                    "CSAFPID-5438677",
                    "CSAFPID-5438679",
                    "CSAFPID-5486263",
                    "CSAFPID-5486265",
                    "CSAFPID-5811032",
                    "CSAFPID-1409017",
                    "CSAFPID-5873818",
                    "CSAFPID-5873819",
                    "CSAFPID-5963615",
                    "CSAFPID-1337760"
                ],
                "known_not_affected": [
                    "CSAFPID-5810745"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/1xxx/CVE-2026-1527.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-1527.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0933.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://hackerone.com/reports/3487198"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://cna.openjsf.org/security-advisories.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1527"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-4992-7rv2-5pvq"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0933.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0933"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ibm.com/support/pages/node/7268023"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ibm.com/support/pages/node/7268166"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
                    "product_ids": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439302",
                        "CSAFPID-1439304",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1441150",
                        "CSAFPID-1508265",
                        "CSAFPID-1508266",
                        "CSAFPID-1706524",
                        "CSAFPID-1837475",
                        "CSAFPID-1837476",
                        "CSAFPID-1851477",
                        "CSAFPID-1851478",
                        "CSAFPID-1919971",
                        "CSAFPID-2467450",
                        "CSAFPID-2524222",
                        "CSAFPID-2552001",
                        "CSAFPID-2652741",
                        "CSAFPID-2698055",
                        "CSAFPID-2847200",
                        "CSAFPID-2847201",
                        "CSAFPID-2858634",
                        "CSAFPID-4534155",
                        "CSAFPID-5068100",
                        "CSAFPID-5068103",
                        "CSAFPID-5068105",
                        "CSAFPID-5068108",
                        "CSAFPID-5068110",
                        "CSAFPID-5068114",
                        "CSAFPID-5068116",
                        "CSAFPID-5068119",
                        "CSAFPID-5068121",
                        "CSAFPID-5068123",
                        "CSAFPID-5068126",
                        "CSAFPID-5068128",
                        "CSAFPID-5068131",
                        "CSAFPID-5068134",
                        "CSAFPID-5155537",
                        "CSAFPID-5155538",
                        "CSAFPID-5222662",
                        "CSAFPID-5222767",
                        "CSAFPID-5222780",
                        "CSAFPID-5360369",
                        "CSAFPID-5438677",
                        "CSAFPID-5438679",
                        "CSAFPID-5486263",
                        "CSAFPID-5486265",
                        "CSAFPID-5811032"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1337760",
                        "CSAFPID-1409017",
                        "CSAFPID-1439279",
                        "CSAFPID-1439302",
                        "CSAFPID-1439304",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1441150",
                        "CSAFPID-1508265",
                        "CSAFPID-1508266",
                        "CSAFPID-1706524",
                        "CSAFPID-1837475",
                        "CSAFPID-1837476",
                        "CSAFPID-1851477",
                        "CSAFPID-1851478",
                        "CSAFPID-1919971",
                        "CSAFPID-2467450",
                        "CSAFPID-2524222",
                        "CSAFPID-2552001",
                        "CSAFPID-2652741",
                        "CSAFPID-2698055",
                        "CSAFPID-2847200",
                        "CSAFPID-2847201",
                        "CSAFPID-2858634",
                        "CSAFPID-4534155",
                        "CSAFPID-5068100",
                        "CSAFPID-5068103",
                        "CSAFPID-5068105",
                        "CSAFPID-5068108",
                        "CSAFPID-5068110",
                        "CSAFPID-5068114",
                        "CSAFPID-5068116",
                        "CSAFPID-5068119",
                        "CSAFPID-5068121",
                        "CSAFPID-5068123",
                        "CSAFPID-5068126",
                        "CSAFPID-5068128",
                        "CSAFPID-5068131",
                        "CSAFPID-5068134",
                        "CSAFPID-5155537",
                        "CSAFPID-5155538",
                        "CSAFPID-5222662",
                        "CSAFPID-5222767",
                        "CSAFPID-5222780",
                        "CSAFPID-5360369",
                        "CSAFPID-5438677",
                        "CSAFPID-5438679",
                        "CSAFPID-5486263",
                        "CSAFPID-5486265",
                        "CSAFPID-5810744",
                        "CSAFPID-5811032",
                        "CSAFPID-5873818",
                        "CSAFPID-5873819",
                        "CSAFPID-5963615"
                    ]
                }
            ],
            "title": "CVE-2026-1527"
        }
    ]
}