{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-2808",
        "tracking": {
            "current_release_date": "2026-03-29T03:14:34.853325Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-2808",
            "initial_release_date": "2026-03-11T23:38:51.779409Z",
            "revision_history": [
                {
                    "date": "2026-03-11T23:38:51.779409Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T23:38:53.525317Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-12T00:24:49.069650Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T00:24:53.133745Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T14:38:59.752995Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-12T15:00:48.644042Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-12T15:00:56.563030Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T17:41:15.397989Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T17:41:18.930667Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T18:42:53.157881Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (1)."
                },
                {
                    "date": "2026-03-12T18:43:03.526737Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T00:28:57.447964Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (45).| Product Identifiers created (15).| Products created (5).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-14T06:05:41.486714Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (2)."
                },
                {
                    "date": "2026-03-19T15:30:36.964526Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T09:38:34.626264Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:38:37.221309Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T22:23:19.758900Z",
                    "number": "17",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-25T11:23:07.133950Z",
                    "number": "18",
                    "summary": "References removed (1)."
                },
                {
                    "date": "2026-03-25T14:54:47.065025Z",
                    "number": "19",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-25T18:13:56.892781Z",
                    "number": "20",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (3).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-29T03:14:27.396915Z",
                    "number": "21",
                    "summary": "References removed (1)."
                }
            ],
            "status": "interim",
            "version": "21"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<1.22.5",
                                "product": {
                                    "name": "vers:semver/<1.22.5",
                                    "product_id": "CSAFPID-5804366"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<1.18.21",
                                "product": {
                                    "name": "vers:unknown/>=0|<1.18.21",
                                    "product_id": "CSAFPID-5907272"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.19.0|<1.21.11",
                                "product": {
                                    "name": "vers:unknown/>=1.19.0|<1.21.11",
                                    "product_id": "CSAFPID-5907274"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.22.0-rc1|<1.22.5",
                                "product": {
                                    "name": "vers:unknown/>=1.22.0-rc1|<1.22.5",
                                    "product_id": "CSAFPID-5907273"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Consul"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<1.22.5",
                                "product": {
                                    "name": "vers:semver/<1.22.5",
                                    "product_id": "CSAFPID-5804367"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Consul Enterprise"
                    }
                ],
                "category": "vendor",
                "name": "HashiCorp"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/5",
                                "product": {
                                    "name": "vers:rpm/5",
                                    "product_id": "CSAFPID-1459353",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:logging:5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1455864",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:logging:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Logging Subsystem for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-2552008",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:multicluster_globalhub"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Multicluster Global Hub"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441076",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:serverless:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Serverless"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1488100",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_mesh:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Service Mesh 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1441080",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:acm:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Advanced Cluster Management for Kubernetes 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1508257",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-5496487",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:edge_manager:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Edge Manager 1"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439328",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-1441150",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_devspaces:3:"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Dev Spaces"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1439281",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_gitops:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift GitOps"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-1496375",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift distributed tracing 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/18.0",
                                "product": {
                                    "name": "vers:rpm/18.0",
                                    "product_id": "CSAFPID-1441197",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openstack:18.0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenStack Platform 18.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914772"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "acm-grafana-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914783"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kube-state-metrics-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2858774"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "prometheus-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Advanced Cluster Management for Kubernetes 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1439282"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "argocd-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847218"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "argocd-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift GitOps"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496488"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496490"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-alert-exporter-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496491"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-alertmanager-proxy-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496492"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-api-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496494"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-cli-artifacts-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496495"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-db-setup-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496497"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-pam-issuer-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496498"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-periodic-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496499"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-telemetry-gateway-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496501"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-userinfo-proxy-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5496502"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "flightctl-worker-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Edge Manager 1"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914752"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-rhel8-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Service Mesh 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5414320"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kn-plugin-event-sender-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Serverless"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455865"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "logging-loki-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2485094"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "loki-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "Logging Subsystem for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914734"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "multicluster-globalhub-grafana-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Multicluster Global Hub"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2257522"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "oc-mirror-plugin-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2563059"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ose-kube-state-metrics-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2485290"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ose-prometheus"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847229"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ose-prometheus-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2915064"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "openstack-operator-bundle"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenStack Platform 18.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914842"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "opentelemetry-collector"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1919998"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "opentelemetry-collector"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811465"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "opentelemetry-collector-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811466"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "opentelemetry-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811468"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "opentelemetry-target-allocator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811469"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tempo-query-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811470"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tempo-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift distributed tracing 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914803"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "platform-operator-bundle"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2485335"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "traefik-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Dev Spaces"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<1.22.5",
                                "product": {
                                    "name": "vers:unknown/>=0|<1.22.5",
                                    "product_id": "CSAFPID-5827044"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "consul"
                    }
                ],
                "category": "vendor",
                "name": "Bitnami"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1392098"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "consul"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-2808",
            "cwe": {
                "id": "CWE-59",
                "name": "Improper Link Resolution Before File Access ('Link Following')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-2808"
                },
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-2808"
                },
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "github - https://github.com/advisories/GHSA-cpfq-66p2-336j"
                },
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-2808"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in HashiCorp Consul. When configured with Kubernetes authentication, a highly privileged attacker can exploit this vulnerability to perform arbitrary file reads. This could lead to the disclosure of sensitive information from the system.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-2808"
                },
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-consul-2026-2808.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "github - https://api.github.com/advisories/GHSA-cpfq-66p2-336j"
                },
                {
                    "category": "description",
                    "text": "HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-cpfq-66p2-336j.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00071",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "3.8",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5804366",
                    "CSAFPID-5804367",
                    "CSAFPID-1392098",
                    "CSAFPID-5827044",
                    "CSAFPID-5907272",
                    "CSAFPID-5907273",
                    "CSAFPID-5907274"
                ],
                "known_not_affected": [
                    "CSAFPID-1439281",
                    "CSAFPID-1439282",
                    "CSAFPID-1439319",
                    "CSAFPID-1439328",
                    "CSAFPID-1441076",
                    "CSAFPID-1441080",
                    "CSAFPID-1441150",
                    "CSAFPID-1441197",
                    "CSAFPID-1455864",
                    "CSAFPID-1455865",
                    "CSAFPID-1459353",
                    "CSAFPID-1488100",
                    "CSAFPID-1496375",
                    "CSAFPID-1508257",
                    "CSAFPID-1919998",
                    "CSAFPID-2257522",
                    "CSAFPID-2485094",
                    "CSAFPID-2485290",
                    "CSAFPID-2485335",
                    "CSAFPID-2552008",
                    "CSAFPID-2563059",
                    "CSAFPID-2847218",
                    "CSAFPID-2847229",
                    "CSAFPID-2858634",
                    "CSAFPID-2858774",
                    "CSAFPID-2914734",
                    "CSAFPID-2914752",
                    "CSAFPID-2914772",
                    "CSAFPID-2914783",
                    "CSAFPID-2914803",
                    "CSAFPID-2914842",
                    "CSAFPID-2915064",
                    "CSAFPID-5414320",
                    "CSAFPID-5496487",
                    "CSAFPID-5496488",
                    "CSAFPID-5496490",
                    "CSAFPID-5496491",
                    "CSAFPID-5496492",
                    "CSAFPID-5496494",
                    "CSAFPID-5496495",
                    "CSAFPID-5496497",
                    "CSAFPID-5496498",
                    "CSAFPID-5496499",
                    "CSAFPID-5496501",
                    "CSAFPID-5496502",
                    "CSAFPID-5811465",
                    "CSAFPID-5811466",
                    "CSAFPID-5811468",
                    "CSAFPID-5811469",
                    "CSAFPID-5811470"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/2xxx/CVE-2026-2808.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-cpfq-66p2-336j"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-cpfq-66p2-336j"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-2808.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-consul-2026-2808.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-cpfq-66p2-336j"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-cpfq-66p2-336j.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://discuss.hashicorp.com/t/hcsec-2026-02-consul-vulnerable-to-arbitrary-file-reads-through-the-vault-kubernetes-authentication-provider/77232"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-cpfq-66p2-336j"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-2808"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://pkg.go.dev/vuln/GO-2026-4690"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1392098",
                        "CSAFPID-5804366",
                        "CSAFPID-5804367",
                        "CSAFPID-5827044",
                        "CSAFPID-5907272",
                        "CSAFPID-5907273",
                        "CSAFPID-5907274"
                    ]
                }
            ],
            "title": "CVE-2026-2808"
        }
    ]
}