{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-28407",
        "tracking": {
            "current_release_date": "2026-03-30T18:48:32.049039Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-28407",
            "initial_release_date": "2026-02-27T21:38:41.021699Z",
            "revision_history": [
                {
                    "date": "2026-02-27T21:38:41.021699Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T21:38:52.236227Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-27T22:25:34.274521Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T22:25:42.615989Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T03:39:42.028787Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-02-28T03:39:50.089860Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T07:34:46.663016Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T12:12:51.972903Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-28T12:13:04.234211Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T14:13:41.049867Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-28T14:13:44.749925Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T15:40:37.192879Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (93).| Products created (3).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-02T22:38:59.272512Z",
                    "number": "13",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-02T22:39:01.635518Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T18:25:09.214116Z",
                    "number": "15",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-03T18:25:12.383272Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:37:36.098590Z",
                    "number": "17",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:37:38.388522Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T18:15:29.380077Z",
                    "number": "19",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (4)."
                },
                {
                    "date": "2026-03-30T18:47:49.762115Z",
                    "number": "20",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (6).| CWES updated (1)."
                }
            ],
            "status": "interim",
            "version": "20"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.21.0",
                                "product": {
                                    "name": "vers:unknown/1.21.0",
                                    "product_id": "CSAFPID-5965568"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.21.0",
                                "product": {
                                    "name": "vers:unknown/<1.21.0",
                                    "product_id": "CSAFPID-5965569"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "go/github.com/chainguard-dev/malcontent"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.21.0",
                                "product": {
                                    "name": "vers:unknown/<1.21.0",
                                    "product_id": "CSAFPID-5736455"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<1.21.0",
                                "product": {
                                    "name": "vers:unknown/>=0|<1.21.0",
                                    "product_id": "CSAFPID-5748749"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0",
                                "product": {
                                    "name": "vers:unknown/v0.1.0",
                                    "product_id": "CSAFPID-5643341"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.10.0",
                                "product": {
                                    "name": "vers:unknown/v0.10.0",
                                    "product_id": "CSAFPID-5493202"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.0",
                                "product": {
                                    "name": "vers:unknown/v0.11.0",
                                    "product_id": "CSAFPID-5493203"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.12.0",
                                "product": {
                                    "name": "vers:unknown/v0.12.0",
                                    "product_id": "CSAFPID-5493204"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.13.0",
                                "product": {
                                    "name": "vers:unknown/v0.13.0",
                                    "product_id": "CSAFPID-5493205"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.13.1",
                                "product": {
                                    "name": "vers:unknown/v0.13.1",
                                    "product_id": "CSAFPID-5493206"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.13.2",
                                "product": {
                                    "name": "vers:unknown/v0.13.2",
                                    "product_id": "CSAFPID-5493207"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.14.0",
                                "product": {
                                    "name": "vers:unknown/v0.14.0",
                                    "product_id": "CSAFPID-5493208"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.15.0",
                                "product": {
                                    "name": "vers:unknown/v0.15.0",
                                    "product_id": "CSAFPID-5493209"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.15.1",
                                "product": {
                                    "name": "vers:unknown/v0.15.1",
                                    "product_id": "CSAFPID-5493210"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.16.0",
                                "product": {
                                    "name": "vers:unknown/v0.16.0",
                                    "product_id": "CSAFPID-5493211"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.16.1",
                                "product": {
                                    "name": "vers:unknown/v0.16.1",
                                    "product_id": "CSAFPID-5493212"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.16.2",
                                "product": {
                                    "name": "vers:unknown/v0.16.2",
                                    "product_id": "CSAFPID-5493213"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.17.0",
                                "product": {
                                    "name": "vers:unknown/v0.17.0",
                                    "product_id": "CSAFPID-5493214"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.17.1",
                                "product": {
                                    "name": "vers:unknown/v0.17.1",
                                    "product_id": "CSAFPID-5493215"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.18.0",
                                "product": {
                                    "name": "vers:unknown/v0.18.0",
                                    "product_id": "CSAFPID-5493216"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.18.1",
                                "product": {
                                    "name": "vers:unknown/v0.18.1",
                                    "product_id": "CSAFPID-5493217"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.18.2",
                                "product": {
                                    "name": "vers:unknown/v0.18.2",
                                    "product_id": "CSAFPID-5493218"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.19.0",
                                "product": {
                                    "name": "vers:unknown/v0.19.0",
                                    "product_id": "CSAFPID-5493219"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.2.0",
                                "product": {
                                    "name": "vers:unknown/v0.2.0",
                                    "product_id": "CSAFPID-5643342"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.3.0",
                                "product": {
                                    "name": "vers:unknown/v0.3.0",
                                    "product_id": "CSAFPID-5643343"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.4.0",
                                "product": {
                                    "name": "vers:unknown/v0.4.0",
                                    "product_id": "CSAFPID-5643344"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.4.1",
                                "product": {
                                    "name": "vers:unknown/v0.4.1",
                                    "product_id": "CSAFPID-5643345"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.5.0",
                                "product": {
                                    "name": "vers:unknown/v0.5.0",
                                    "product_id": "CSAFPID-5643346"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.0",
                                "product": {
                                    "name": "vers:unknown/v0.6.0",
                                    "product_id": "CSAFPID-5643347"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.0",
                                "product": {
                                    "name": "vers:unknown/v0.7.0",
                                    "product_id": "CSAFPID-5643348"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.0",
                                "product": {
                                    "name": "vers:unknown/v0.8.0",
                                    "product_id": "CSAFPID-5643349"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.9.0",
                                "product": {
                                    "name": "vers:unknown/v0.9.0",
                                    "product_id": "CSAFPID-5643350"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0",
                                "product": {
                                    "name": "vers:unknown/v1.0.0",
                                    "product_id": "CSAFPID-5493220"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.1",
                                "product": {
                                    "name": "vers:unknown/v1.0.1",
                                    "product_id": "CSAFPID-5493221"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0",
                                "product": {
                                    "name": "vers:unknown/v1.1.0",
                                    "product_id": "CSAFPID-5493222"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.1",
                                "product": {
                                    "name": "vers:unknown/v1.1.1",
                                    "product_id": "CSAFPID-5493223"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.10.0",
                                "product": {
                                    "name": "vers:unknown/v1.10.0",
                                    "product_id": "CSAFPID-5493149"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.10.1",
                                "product": {
                                    "name": "vers:unknown/v1.10.1",
                                    "product_id": "CSAFPID-5493150"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.10.2",
                                "product": {
                                    "name": "vers:unknown/v1.10.2",
                                    "product_id": "CSAFPID-5493151"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.10.3",
                                "product": {
                                    "name": "vers:unknown/v1.10.3",
                                    "product_id": "CSAFPID-5493152"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.10.4",
                                "product": {
                                    "name": "vers:unknown/v1.10.4",
                                    "product_id": "CSAFPID-5493153"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.11.0",
                                "product": {
                                    "name": "vers:unknown/v1.11.0",
                                    "product_id": "CSAFPID-5493154"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.11.1",
                                "product": {
                                    "name": "vers:unknown/v1.11.1",
                                    "product_id": "CSAFPID-5493155"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.11.2",
                                "product": {
                                    "name": "vers:unknown/v1.11.2",
                                    "product_id": "CSAFPID-5493156"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.11.3",
                                "product": {
                                    "name": "vers:unknown/v1.11.3",
                                    "product_id": "CSAFPID-5493157"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.12.0",
                                "product": {
                                    "name": "vers:unknown/v1.12.0",
                                    "product_id": "CSAFPID-5493158"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.12.1",
                                "product": {
                                    "name": "vers:unknown/v1.12.1",
                                    "product_id": "CSAFPID-5493159"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.12.2",
                                "product": {
                                    "name": "vers:unknown/v1.12.2",
                                    "product_id": "CSAFPID-5493160"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.13.0",
                                "product": {
                                    "name": "vers:unknown/v1.13.0",
                                    "product_id": "CSAFPID-5493161"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.13.1",
                                "product": {
                                    "name": "vers:unknown/v1.13.1",
                                    "product_id": "CSAFPID-5493162"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.14.0",
                                "product": {
                                    "name": "vers:unknown/v1.14.0",
                                    "product_id": "CSAFPID-5493163"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.14.1",
                                "product": {
                                    "name": "vers:unknown/v1.14.1",
                                    "product_id": "CSAFPID-5493164"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.15.0",
                                "product": {
                                    "name": "vers:unknown/v1.15.0",
                                    "product_id": "CSAFPID-5493165"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.15.1",
                                "product": {
                                    "name": "vers:unknown/v1.15.1",
                                    "product_id": "CSAFPID-5493166"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.0",
                                "product": {
                                    "name": "vers:unknown/v1.16.0",
                                    "product_id": "CSAFPID-5493167"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.1",
                                "product": {
                                    "name": "vers:unknown/v1.16.1",
                                    "product_id": "CSAFPID-5493168"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.2",
                                "product": {
                                    "name": "vers:unknown/v1.16.2",
                                    "product_id": "CSAFPID-5493169"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.3",
                                "product": {
                                    "name": "vers:unknown/v1.16.3",
                                    "product_id": "CSAFPID-5493170"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.4",
                                "product": {
                                    "name": "vers:unknown/v1.16.4",
                                    "product_id": "CSAFPID-5493171"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.5",
                                "product": {
                                    "name": "vers:unknown/v1.16.5",
                                    "product_id": "CSAFPID-5493172"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.6",
                                "product": {
                                    "name": "vers:unknown/v1.16.6",
                                    "product_id": "CSAFPID-5493173"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.0",
                                "product": {
                                    "name": "vers:unknown/v1.17.0",
                                    "product_id": "CSAFPID-5493174"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.1",
                                "product": {
                                    "name": "vers:unknown/v1.17.1",
                                    "product_id": "CSAFPID-5493175"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.2",
                                "product": {
                                    "name": "vers:unknown/v1.17.2",
                                    "product_id": "CSAFPID-5493176"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.3",
                                "product": {
                                    "name": "vers:unknown/v1.17.3",
                                    "product_id": "CSAFPID-5493177"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.4",
                                "product": {
                                    "name": "vers:unknown/v1.17.4",
                                    "product_id": "CSAFPID-5493178"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.5",
                                "product": {
                                    "name": "vers:unknown/v1.17.5",
                                    "product_id": "CSAFPID-5493179"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.18.0",
                                "product": {
                                    "name": "vers:unknown/v1.18.0",
                                    "product_id": "CSAFPID-5493180"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.18.1",
                                "product": {
                                    "name": "vers:unknown/v1.18.1",
                                    "product_id": "CSAFPID-5493181"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.18.2",
                                "product": {
                                    "name": "vers:unknown/v1.18.2",
                                    "product_id": "CSAFPID-5493182"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.18.3",
                                "product": {
                                    "name": "vers:unknown/v1.18.3",
                                    "product_id": "CSAFPID-5493183"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.19.0",
                                "product": {
                                    "name": "vers:unknown/v1.19.0",
                                    "product_id": "CSAFPID-5493184"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.19.1",
                                "product": {
                                    "name": "vers:unknown/v1.19.1",
                                    "product_id": "CSAFPID-5493185"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.19.2",
                                "product": {
                                    "name": "vers:unknown/v1.19.2",
                                    "product_id": "CSAFPID-5493186"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.19.3",
                                "product": {
                                    "name": "vers:unknown/v1.19.3",
                                    "product_id": "CSAFPID-5493187"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.19.4",
                                "product": {
                                    "name": "vers:unknown/v1.19.4",
                                    "product_id": "CSAFPID-5493188"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0",
                                "product": {
                                    "name": "vers:unknown/v1.2.0",
                                    "product_id": "CSAFPID-5493224"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.20.0",
                                "product": {
                                    "name": "vers:unknown/v1.20.0",
                                    "product_id": "CSAFPID-5493189"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.20.1",
                                "product": {
                                    "name": "vers:unknown/v1.20.1",
                                    "product_id": "CSAFPID-5493190"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.20.2",
                                "product": {
                                    "name": "vers:unknown/v1.20.2",
                                    "product_id": "CSAFPID-5493191"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.20.3",
                                "product": {
                                    "name": "vers:unknown/v1.20.3",
                                    "product_id": "CSAFPID-5750050"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.20.4",
                                "product": {
                                    "name": "vers:unknown/v1.20.4",
                                    "product_id": "CSAFPID-5750051"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.20.5",
                                "product": {
                                    "name": "vers:unknown/v1.20.5",
                                    "product_id": "CSAFPID-5750052"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.0",
                                "product": {
                                    "name": "vers:unknown/v1.3.0",
                                    "product_id": "CSAFPID-5493225"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.0",
                                "product": {
                                    "name": "vers:unknown/v1.4.0",
                                    "product_id": "CSAFPID-5493226"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5.0",
                                "product": {
                                    "name": "vers:unknown/v1.5.0",
                                    "product_id": "CSAFPID-5493227"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.5.1",
                                "product": {
                                    "name": "vers:unknown/v1.5.1",
                                    "product_id": "CSAFPID-5493228"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.6.0",
                                "product": {
                                    "name": "vers:unknown/v1.6.0",
                                    "product_id": "CSAFPID-5493229"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.7.0",
                                "product": {
                                    "name": "vers:unknown/v1.7.0",
                                    "product_id": "CSAFPID-5493230"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.7.1",
                                "product": {
                                    "name": "vers:unknown/v1.7.1",
                                    "product_id": "CSAFPID-5493231"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.0",
                                "product": {
                                    "name": "vers:unknown/v1.8.0",
                                    "product_id": "CSAFPID-5493192"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.1",
                                "product": {
                                    "name": "vers:unknown/v1.8.1",
                                    "product_id": "CSAFPID-5493193"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.2",
                                "product": {
                                    "name": "vers:unknown/v1.8.2",
                                    "product_id": "CSAFPID-5493194"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.3",
                                "product": {
                                    "name": "vers:unknown/v1.8.3",
                                    "product_id": "CSAFPID-5493195"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.4",
                                "product": {
                                    "name": "vers:unknown/v1.8.4",
                                    "product_id": "CSAFPID-5493196"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.5",
                                "product": {
                                    "name": "vers:unknown/v1.8.5",
                                    "product_id": "CSAFPID-5493197"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.6",
                                "product": {
                                    "name": "vers:unknown/v1.8.6",
                                    "product_id": "CSAFPID-5493198"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.7",
                                "product": {
                                    "name": "vers:unknown/v1.8.7",
                                    "product_id": "CSAFPID-5493199"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.8.8",
                                "product": {
                                    "name": "vers:unknown/v1.8.8",
                                    "product_id": "CSAFPID-5493200"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.9.0",
                                "product": {
                                    "name": "vers:unknown/v1.9.0",
                                    "product_id": "CSAFPID-5493201"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "malcontent"
                    }
                ],
                "category": "vendor",
                "name": "chainguard-dev"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.21.0",
                                "product": {
                                    "name": "vers:unknown/<1.21.0",
                                    "product_id": "CSAFPID-5757048",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:chainguard:malcontent:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "malcontent"
                    }
                ],
                "category": "vendor",
                "name": "chainguard"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-28407",
            "notes": [
                {
                    "category": "description",
                    "text": "malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-28407"
                },
                {
                    "category": "description",
                    "text": "malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-28407"
                },
                {
                    "category": "description",
                    "text": "Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.\n\n**Fix**:  https://github.com/chainguard-dev/malcontent/pull/1383\n\n**Acknowledgements**\n\nmalcontent thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.",
                    "title": "github - https://github.com/advisories/GHSA-945p-3jhm-6rcp"
                },
                {
                    "category": "description",
                    "text": "Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.\n\n**Fix**:  https://github.com/chainguard-dev/malcontent/pull/1383\n\n**Acknowledgements**\n\nmalcontent thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-945p-3jhm-6rcp.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28407.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "malcontent: Nested archive extraction failure can drop content from scan inputs in github.com/chainguard-dev/malcontent",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4577.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.\n\n**Fix**:  https://github.com/chainguard-dev/malcontent/pull/1383\n\n**Acknowledgements**\n\nmalcontent thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.",
                    "title": "gitlab - https://gitlab.com/api/v4/projects/25847700/repository/files/go%2Fgithub.com%2Fchainguard-dev%2Fmalcontent%2FCVE-2026-28407.yml/raw"
                },
                {
                    "category": "other",
                    "text": "0.00032",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "6.9",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.7",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5965568"
                ],
                "known_affected": [
                    "CSAFPID-5736455",
                    "CSAFPID-5748749",
                    "CSAFPID-5493149",
                    "CSAFPID-5493150",
                    "CSAFPID-5493151",
                    "CSAFPID-5493152",
                    "CSAFPID-5493153",
                    "CSAFPID-5493154",
                    "CSAFPID-5493155",
                    "CSAFPID-5493156",
                    "CSAFPID-5493157",
                    "CSAFPID-5493158",
                    "CSAFPID-5493159",
                    "CSAFPID-5493160",
                    "CSAFPID-5493161",
                    "CSAFPID-5493162",
                    "CSAFPID-5493163",
                    "CSAFPID-5493164",
                    "CSAFPID-5493165",
                    "CSAFPID-5493166",
                    "CSAFPID-5493167",
                    "CSAFPID-5493168",
                    "CSAFPID-5493169",
                    "CSAFPID-5493170",
                    "CSAFPID-5493171",
                    "CSAFPID-5493172",
                    "CSAFPID-5493173",
                    "CSAFPID-5493174",
                    "CSAFPID-5493175",
                    "CSAFPID-5493176",
                    "CSAFPID-5493177",
                    "CSAFPID-5493178",
                    "CSAFPID-5493179",
                    "CSAFPID-5493180",
                    "CSAFPID-5493181",
                    "CSAFPID-5493182",
                    "CSAFPID-5493183",
                    "CSAFPID-5493184",
                    "CSAFPID-5493185",
                    "CSAFPID-5493186",
                    "CSAFPID-5493187",
                    "CSAFPID-5493188",
                    "CSAFPID-5493189",
                    "CSAFPID-5493190",
                    "CSAFPID-5493191",
                    "CSAFPID-5493192",
                    "CSAFPID-5493193",
                    "CSAFPID-5493194",
                    "CSAFPID-5493195",
                    "CSAFPID-5493196",
                    "CSAFPID-5493197",
                    "CSAFPID-5493198",
                    "CSAFPID-5493199",
                    "CSAFPID-5493200",
                    "CSAFPID-5493201",
                    "CSAFPID-5493202",
                    "CSAFPID-5493203",
                    "CSAFPID-5493204",
                    "CSAFPID-5493205",
                    "CSAFPID-5493206",
                    "CSAFPID-5493207",
                    "CSAFPID-5493208",
                    "CSAFPID-5493209",
                    "CSAFPID-5493210",
                    "CSAFPID-5493211",
                    "CSAFPID-5493212",
                    "CSAFPID-5493213",
                    "CSAFPID-5493214",
                    "CSAFPID-5493215",
                    "CSAFPID-5493216",
                    "CSAFPID-5493217",
                    "CSAFPID-5493218",
                    "CSAFPID-5493219",
                    "CSAFPID-5493220",
                    "CSAFPID-5493221",
                    "CSAFPID-5493222",
                    "CSAFPID-5493223",
                    "CSAFPID-5493224",
                    "CSAFPID-5493225",
                    "CSAFPID-5493226",
                    "CSAFPID-5493227",
                    "CSAFPID-5493228",
                    "CSAFPID-5493229",
                    "CSAFPID-5493230",
                    "CSAFPID-5493231",
                    "CSAFPID-5643341",
                    "CSAFPID-5643342",
                    "CSAFPID-5643343",
                    "CSAFPID-5643344",
                    "CSAFPID-5643345",
                    "CSAFPID-5643346",
                    "CSAFPID-5643347",
                    "CSAFPID-5643348",
                    "CSAFPID-5643349",
                    "CSAFPID-5643350",
                    "CSAFPID-5750050",
                    "CSAFPID-5750051",
                    "CSAFPID-5750052",
                    "CSAFPID-5757048",
                    "CSAFPID-5965569"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28407"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28407.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28407"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28407"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-945p-3jhm-6rcp"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-945p-3jhm-6rcp"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-945p-3jhm-6rcp.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-28407"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28407.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4577.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - gitlab",
                    "url": "https://gitlab.com/api/v4/projects/25847700/repository/files/go%2Fgithub.com%2Fchainguard-dev%2Fmalcontent%2FCVE-2026-28407.yml/raw"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/chainguard-dev/malcontent/security/advisories/GHSA-945p-3jhm-6rcp"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/chainguard-dev/malcontent/pull/1383"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://github.com/chainguard-dev/malcontent/commit/356c56659ccfcad0b249a97de8cf71f151ed3ee9"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28407"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab",
                    "url": "https://github.com/advisories/GHSA-945p-3jhm-6rcp"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28407.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - gitlab",
                    "url": "https://github.com/chainguard-dev/malcontent"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-5493149",
                        "CSAFPID-5493150",
                        "CSAFPID-5493151",
                        "CSAFPID-5493152",
                        "CSAFPID-5493153",
                        "CSAFPID-5493154",
                        "CSAFPID-5493155",
                        "CSAFPID-5493156",
                        "CSAFPID-5493157",
                        "CSAFPID-5493158",
                        "CSAFPID-5493159",
                        "CSAFPID-5493160",
                        "CSAFPID-5493161",
                        "CSAFPID-5493162",
                        "CSAFPID-5493163",
                        "CSAFPID-5493164",
                        "CSAFPID-5493165",
                        "CSAFPID-5493166",
                        "CSAFPID-5493167",
                        "CSAFPID-5493168",
                        "CSAFPID-5493169",
                        "CSAFPID-5493170",
                        "CSAFPID-5493171",
                        "CSAFPID-5493172",
                        "CSAFPID-5493173",
                        "CSAFPID-5493174",
                        "CSAFPID-5493175",
                        "CSAFPID-5493176",
                        "CSAFPID-5493177",
                        "CSAFPID-5493178",
                        "CSAFPID-5493179",
                        "CSAFPID-5493180",
                        "CSAFPID-5493181",
                        "CSAFPID-5493182",
                        "CSAFPID-5493183",
                        "CSAFPID-5493184",
                        "CSAFPID-5493185",
                        "CSAFPID-5493186",
                        "CSAFPID-5493187",
                        "CSAFPID-5493188",
                        "CSAFPID-5493189",
                        "CSAFPID-5493190",
                        "CSAFPID-5493191",
                        "CSAFPID-5493192",
                        "CSAFPID-5493193",
                        "CSAFPID-5493194",
                        "CSAFPID-5493195",
                        "CSAFPID-5493196",
                        "CSAFPID-5493197",
                        "CSAFPID-5493198",
                        "CSAFPID-5493199",
                        "CSAFPID-5493200",
                        "CSAFPID-5493201",
                        "CSAFPID-5493202",
                        "CSAFPID-5493203",
                        "CSAFPID-5493204",
                        "CSAFPID-5493205",
                        "CSAFPID-5493206",
                        "CSAFPID-5493207",
                        "CSAFPID-5493208",
                        "CSAFPID-5493209",
                        "CSAFPID-5493210",
                        "CSAFPID-5493211",
                        "CSAFPID-5493212",
                        "CSAFPID-5493213",
                        "CSAFPID-5493214",
                        "CSAFPID-5493215",
                        "CSAFPID-5493216",
                        "CSAFPID-5493217",
                        "CSAFPID-5493218",
                        "CSAFPID-5493219",
                        "CSAFPID-5493220",
                        "CSAFPID-5493221",
                        "CSAFPID-5493222",
                        "CSAFPID-5493223",
                        "CSAFPID-5493224",
                        "CSAFPID-5493225",
                        "CSAFPID-5493226",
                        "CSAFPID-5493227",
                        "CSAFPID-5493228",
                        "CSAFPID-5493229",
                        "CSAFPID-5493230",
                        "CSAFPID-5493231",
                        "CSAFPID-5643341",
                        "CSAFPID-5643342",
                        "CSAFPID-5643343",
                        "CSAFPID-5643344",
                        "CSAFPID-5643345",
                        "CSAFPID-5643346",
                        "CSAFPID-5643347",
                        "CSAFPID-5643348",
                        "CSAFPID-5643349",
                        "CSAFPID-5643350",
                        "CSAFPID-5736455",
                        "CSAFPID-5748749",
                        "CSAFPID-5750050",
                        "CSAFPID-5750051",
                        "CSAFPID-5750052",
                        "CSAFPID-5757048",
                        "CSAFPID-5965569"
                    ]
                }
            ],
            "title": "CVE-2026-28407"
        }
    ]
}