{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-31837",
        "tracking": {
            "current_release_date": "2026-03-27T21:40:31.699914Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-31837",
            "initial_release_date": "2026-03-10T22:26:21.829461Z",
            "revision_history": [
                {
                    "date": "2026-03-10T22:26:21.829461Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T22:26:26.267033Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-10T22:38:41.171963Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-10T22:38:42.626962Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T14:54:31.175468Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-11T14:54:45.545749Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-11T16:39:54.754657Z",
                    "number": "7",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-12T12:16:24.264263Z",
                    "number": "8",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (5).| References created (4)."
                },
                {
                    "date": "2026-03-12T12:16:26.027766Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T00:27:47.075962Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (46).| Product Identifiers created (8).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-13T00:27:53.561929Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T19:25:20.109427Z",
                    "number": "12",
                    "summary": "CVSS created.| Products connected (1).| Product Identifiers created (3).| Products created (2)."
                },
                {
                    "date": "2026-03-18T19:25:22.693992Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:32:42.879379Z",
                    "number": "14",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:32:46.700269Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T00:27:57.162095Z",
                    "number": "16",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (8).| Product Remediations created (3).| Product Identifiers created (24).| Product Identifiers removed (24).| References created (20).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T00:28:08.809406Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T00:28:16.057541Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (8).| Product Remediations created (3).| Product Identifiers created (24).| Product Identifiers removed (24).| References created (20).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T00:28:38.592857Z",
                    "number": "19",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (8).| Product Remediations created (3).| Product Identifiers created (24).| Product Identifiers removed (24).| References created (20).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T09:06:34.705061Z",
                    "number": "20",
                    "summary": "Products connected (1).| References created (3)."
                }
            ],
            "status": "interim",
            "version": "20"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441053",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:cert_manager:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Cert-manager Operator For Red Hat Openshift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-5446213",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ext_dns_optr:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "ExternalDNS Operator"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441076",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:serverless:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Serverless"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1488100",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_mesh:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Service Mesh 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-2942231",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_mesh:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Service Mesh 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1508257",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-2914823",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:connectivity_link:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Connectivity Link 1"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:5::server"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/3.0",
                                        "product": {
                                            "name": "vers:rpm/3.0",
                                            "product_id": "CSAFPID-5681240",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:service_mesh:3.0::el9"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat OpenShift Service Mesh 3"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/3.1",
                                        "product": {
                                            "name": "vers:rpm/3.1",
                                            "product_id": "CSAFPID-5248262",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:service_mesh:3.1::el9"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat OpenShift Service Mesh 3.1"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/3.2",
                                        "product": {
                                            "name": "vers:rpm/3.2",
                                            "product_id": "CSAFPID-5248270",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:service_mesh:3.2::el9"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat OpenShift Service Mesh 3.2"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774037349",
                                        "product": {
                                            "name": "vers:oci/1774037349",
                                            "product_id": "CSAFPID-5920306",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-cni-rhel9@sha256%3Ae997516338202cdbd61076accd9284b07d41a4e5f110acb646dce4d1ecef232d?arch=s390x&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774037349"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774206585",
                                        "product": {
                                            "name": "vers:oci/1774206585",
                                            "product_id": "CSAFPID-5920299",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-cni-rhel9@sha256%3A90e9ef5b9db44a7f18bcdfaba6851c89138577636cb765de938bdf0e68d296be?arch=arm64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774206585"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774214116",
                                        "product": {
                                            "name": "vers:oci/1774214116",
                                            "product_id": "CSAFPID-5920357",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-cni-rhel9@sha256%3Adcd2685d0f51bd9654e77891351273f5f9f93161efd413925c3d0b96b3bdbf0f?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774214116"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-cni-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774018912",
                                        "product": {
                                            "name": "vers:oci/1774018912",
                                            "product_id": "CSAFPID-5920362",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-must-gather-rhel9@sha256%3Aef560e57543bec7d17f46e7baede5f906a5feb1d59feabca310feada79180b85?arch=arm64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774018912"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774024187",
                                        "product": {
                                            "name": "vers:oci/1774024187",
                                            "product_id": "CSAFPID-5920303",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-must-gather-rhel9@sha256%3A226cdb05c3583a75732796acb0fa9afe0771267e9575c0585b0c222141736e0a?arch=arm64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774024187"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774037182",
                                        "product": {
                                            "name": "vers:oci/1774037182",
                                            "product_id": "CSAFPID-5920311",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-must-gather-rhel9@sha256%3Aced8fd70a941190d72af02804cd1e3aa55131dd831eb353a46dfe02497474660?arch=s390x&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774037182"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-must-gather-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774006090",
                                        "product": {
                                            "name": "vers:oci/1774006090",
                                            "product_id": "CSAFPID-5920358",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-pilot-rhel9@sha256%3A9dda1ca14a4d44819498e5e00470bedf540ba7cd5a6be015e47bbf1fe5aa8ca3?arch=s390x&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774006090"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774037369",
                                        "product": {
                                            "name": "vers:oci/1774037369",
                                            "product_id": "CSAFPID-5920307",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-pilot-rhel9@sha256%3Af19d8eea123addd242941d65c7b9d7f4cf0c8a2009c681ad07a87fb365193a7e?arch=arm64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774037369"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774206464",
                                        "product": {
                                            "name": "vers:oci/1774206464",
                                            "product_id": "CSAFPID-5920300",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-pilot-rhel9@sha256%3Aeba1f0afeb06ac3eba3c1e35a2045e25e60a37b1a542ef393f7d8d6382030af8?arch=s390x&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774206464"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-pilot-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774068855",
                                        "product": {
                                            "name": "vers:oci/1774068855",
                                            "product_id": "CSAFPID-5920359",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-proxyv2-rhel9@sha256%3Aefc87388d29385d36a26a19da1adb52bd9ef8dea42503b409d1f3d25769c3e76?arch=arm64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774068855"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774114903",
                                        "product": {
                                            "name": "vers:oci/1774114903",
                                            "product_id": "CSAFPID-5920301",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-proxyv2-rhel9@sha256%3Aa65212d6c07f11e855e60c2027076351947fa2d9a4a725dab519afa796615d3a?arch=ppc64le&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774114903"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774244136",
                                        "product": {
                                            "name": "vers:oci/1774244136",
                                            "product_id": "CSAFPID-5920308",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-proxyv2-rhel9@sha256%3Ad839d9bbb4faa2b0e7d91a66d85d5d43f8af6cb8681c8bab58fd8e2af1a6ebf7?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774244136"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-proxyv2-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774293851",
                                        "product": {
                                            "name": "vers:oci/1774293851",
                                            "product_id": "CSAFPID-5920309",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-rhel9-operator@sha256%3Aa75a0ac8954c9654263226507088a7969b7f554ba5852bcfcf8a5d64a0d29c92?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774293851"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774294372",
                                        "product": {
                                            "name": "vers:oci/1774294372",
                                            "product_id": "CSAFPID-5920360",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-rhel9-operator@sha256%3Afe35fc6ea8320c1d0e8ee0712788879daee23d4cea6b970237375e264344ddd0?arch=ppc64le&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774294372"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774294809",
                                        "product": {
                                            "name": "vers:oci/1774294809",
                                            "product_id": "CSAFPID-5920302",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-rhel9-operator@sha256%3Ae1de1bc5f4472757cd9dd1e87de88fc54cdde8bbb9a4fd2245388dc3076efada?arch=ppc64le&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774294809"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774299519",
                                        "product": {
                                            "name": "vers:oci/1774299519",
                                            "product_id": "CSAFPID-5920312",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-sail-operator-bundle@sha256%3A94bd9b7d5013e610f49e7c5376e5c63579a525f2e45e3498908a88b9773c4fcb?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774299519"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774299791",
                                        "product": {
                                            "name": "vers:oci/1774299791",
                                            "product_id": "CSAFPID-5920304",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-sail-operator-bundle@sha256%3A915c426f6d9e02f951d13df06a3e2398a9cc0cdaae6f4deb71aaaf280ad55421?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774299791"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774302863",
                                        "product": {
                                            "name": "vers:oci/1774302863",
                                            "product_id": "CSAFPID-5920363",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-sail-operator-bundle@sha256%3A6067e8bd752fec6a4c9791b5416feebd3755e812677393c1c2ad4746f5aced5e?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774302863"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-sail-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774019474",
                                        "product": {
                                            "name": "vers:oci/1774019474",
                                            "product_id": "CSAFPID-5920361",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-ztunnel-rhel9@sha256%3Aefdcf5819964e4edf19ec04f7b496d84bb705b4b0d2a9c7f8220ea2937d09d36?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh-dev-preview-beta&tag=1774019474"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774207172",
                                        "product": {
                                            "name": "vers:oci/1774207172",
                                            "product_id": "CSAFPID-5920305",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-ztunnel-rhel9@sha256%3Ac99eadf319dd88c8a7e6e2201dd749f1f631a60d1bc0cc683cf83fb14f01317b?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh&tag=1774207172"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774215103",
                                        "product": {
                                            "name": "vers:oci/1774215103",
                                            "product_id": "CSAFPID-5920310",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/istio-ztunnel-rhel9@sha256%3Af24f6e672693c3ee080caa418bc1dc1924921898e07e1aeb06923dd0c195cf30?arch=amd64&repository_url=registry.redhat.io/openshift-service-mesh-tech-preview&tag=1774215103"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-ztunnel-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Service Mesh"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1919980"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway-proxy"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2652728"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway-proxy-openssl30"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2652729"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway-proxy-openssl32"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2551999"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cert-manager-istio-csr-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2552000"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cert-manager-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2109922"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cert-manager-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441054"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetstack-cert-manager-acmesolver-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441055"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jetstack-cert-manager-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "cert-manager Operator for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446214"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-dns-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446215"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-dns-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "ExternalDNS Operator"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1488101"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-cni-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1496223"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1488102"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pilot-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1488104"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "proxyv2-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Service Mesh 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942233"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-cni-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942235"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-pilot-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942236"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-proxyv2-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2942237"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "istio-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985384"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985386"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985387"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kiali-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Service Mesh 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446216"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kn-eventing-istio-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446217"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "net-istio-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446218"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "net-istio-webhook-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446219"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "serverless-kn-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5446220"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "serverless-openshift-kn-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Serverless"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1906087"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kf-notebook-controller-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119808"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kserve-agent-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119810"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kserve-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119811"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-kserve-router-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1906088"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-controller-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3036145"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914848"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-operator-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2960949"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2960950"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1906089"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-notebook-controller-rhel8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914831"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhcl-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914832"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhcl-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Connectivity Link 1"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/envoy proxy",
                                "product": {
                                    "name": "vers:unknown/envoy proxy",
                                    "product_id": "CSAFPID-5810304",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:google:cloud_platform:envoy_proxy"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/istio",
                                "product": {
                                    "name": "vers:unknown/istio",
                                    "product_id": "CSAFPID-5810308",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:google:cloud_platform:istio"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/service mesh <1.26.8-asm.3",
                                "product": {
                                    "name": "vers:unknown/service mesh <1.26.8-asm.3",
                                    "product_id": "CSAFPID-5810305"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/service mesh <1.27.8-asm.7",
                                "product": {
                                    "name": "vers:unknown/service mesh <1.27.8-asm.7",
                                    "product_id": "CSAFPID-5810307"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/service mesh <1.28.5-asm.9",
                                "product": {
                                    "name": "vers:unknown/service mesh <1.28.5-asm.9",
                                    "product_id": "CSAFPID-5810306"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Cloud Platform"
                    }
                ],
                "category": "vendor",
                "name": "Google"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.27.8",
                                "product": {
                                    "name": "vers:unknown/<1.27.8",
                                    "product_id": "CSAFPID-5779787",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.28.0-alpha.0|<1.28.5",
                                "product": {
                                    "name": "vers:unknown/>=1.28.0-alpha.0|<1.28.5",
                                    "product_id": "CSAFPID-5779786"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.28.0|<1.28.5",
                                "product": {
                                    "name": "vers:unknown/>=1.28.0|<1.28.5",
                                    "product_id": "CSAFPID-5845003",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.29.0-alpha.0|<1.29.1",
                                "product": {
                                    "name": "vers:unknown/>=1.29.0-alpha.0|<1.29.1",
                                    "product_id": "CSAFPID-5779785"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.29.0|<1.29.1",
                                "product": {
                                    "name": "vers:unknown/>=1.29.0|<1.29.1",
                                    "product_id": "CSAFPID-5845004",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:istio:istio:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Istio"
                    }
                ],
                "category": "vendor",
                "name": "Istio"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-31837",
            "cwe": {
                "id": "CWE-1392",
                "name": "Use of Default Credentials"
            },
            "flags": [
                {
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "CSAFPID-5920299",
                        "CSAFPID-5920302",
                        "CSAFPID-5920303",
                        "CSAFPID-5920304",
                        "CSAFPID-5920305",
                        "CSAFPID-5920306",
                        "CSAFPID-5920309",
                        "CSAFPID-5920310",
                        "CSAFPID-5920311",
                        "CSAFPID-5920312",
                        "CSAFPID-5920357",
                        "CSAFPID-5920360",
                        "CSAFPID-5920361",
                        "CSAFPID-5920362",
                        "CSAFPID-5920363"
                    ]
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-31837"
                },
                {
                    "category": "description",
                    "text": "Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-31837"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver becomes unavailable or fails to fetch keys. This vulnerability can lead to the exposure of hardcoded default settings, potentially bypassing authentication mechanisms and allowing unauthorized access.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-31837"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver becomes unavailable or fails to fetch keys. This vulnerability can lead to the exposure of hardcoded default settings, potentially bypassing authentication mechanisms and allowing unauthorized access.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5952.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver becomes unavailable or fails to fetch keys. This vulnerability can lead to the exposure of hardcoded default settings, potentially bypassing authentication mechanisms and allowing unauthorized access.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5950.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Istio. A user of Istio could be impacted if the JSON Web Key Set (JWKS) resolver becomes unavailable or fails to fetch keys. This vulnerability can lead to the exposure of hardcoded default settings, potentially bypassing authentication mechanisms and allowing unauthorized access.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5948.json"
                },
                {
                    "category": "other",
                    "text": "0.00048",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "5.1",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "VENDOR FIX as product remediation category, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Red Hat, There is cvss data available from source Redhat, There is product_remediation data available from source Redhat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5920300",
                    "CSAFPID-5920301",
                    "CSAFPID-5920307",
                    "CSAFPID-5920308",
                    "CSAFPID-5920358",
                    "CSAFPID-5920359"
                ],
                "known_affected": [
                    "CSAFPID-5779785",
                    "CSAFPID-5779786",
                    "CSAFPID-5779787",
                    "CSAFPID-5810304",
                    "CSAFPID-5810305",
                    "CSAFPID-5810306",
                    "CSAFPID-5810307",
                    "CSAFPID-5810308",
                    "CSAFPID-1439279",
                    "CSAFPID-1441053",
                    "CSAFPID-1441054",
                    "CSAFPID-1441055",
                    "CSAFPID-1441076",
                    "CSAFPID-1488100",
                    "CSAFPID-1488101",
                    "CSAFPID-1488102",
                    "CSAFPID-1488104",
                    "CSAFPID-1906087",
                    "CSAFPID-1906088",
                    "CSAFPID-1906089",
                    "CSAFPID-2109922",
                    "CSAFPID-2551999",
                    "CSAFPID-2552000",
                    "CSAFPID-2914848",
                    "CSAFPID-2942231",
                    "CSAFPID-2942233",
                    "CSAFPID-2942235",
                    "CSAFPID-2942236",
                    "CSAFPID-2942237",
                    "CSAFPID-2960949",
                    "CSAFPID-3036145",
                    "CSAFPID-5119808",
                    "CSAFPID-5119810",
                    "CSAFPID-5119811",
                    "CSAFPID-5446216",
                    "CSAFPID-5446217",
                    "CSAFPID-5446218",
                    "CSAFPID-5446219",
                    "CSAFPID-5446220",
                    "CSAFPID-5845003",
                    "CSAFPID-5845004",
                    "CSAFPID-1317175"
                ],
                "known_not_affected": [
                    "CSAFPID-1496223",
                    "CSAFPID-1508257",
                    "CSAFPID-1919980",
                    "CSAFPID-2652728",
                    "CSAFPID-2652729",
                    "CSAFPID-2914823",
                    "CSAFPID-2914831",
                    "CSAFPID-2914832",
                    "CSAFPID-2960950",
                    "CSAFPID-2985384",
                    "CSAFPID-2985386",
                    "CSAFPID-2985387",
                    "CSAFPID-5446213",
                    "CSAFPID-5446214",
                    "CSAFPID-5446215",
                    "CSAFPID-5920299",
                    "CSAFPID-5920302",
                    "CSAFPID-5920303",
                    "CSAFPID-5920304",
                    "CSAFPID-5920305",
                    "CSAFPID-5920306",
                    "CSAFPID-5920309",
                    "CSAFPID-5920310",
                    "CSAFPID-5920311",
                    "CSAFPID-5920312",
                    "CSAFPID-5920357",
                    "CSAFPID-5920360",
                    "CSAFPID-5920361",
                    "CSAFPID-5920362",
                    "CSAFPID-5920363"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/31xxx/CVE-2026-31837.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0704.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-31837.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5952.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5950.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:5948.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; redhat",
                    "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0704.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0704"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-013"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-013"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2446344"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5952"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-61726"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-61728"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-61731"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-61732"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-68121"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/cve-2025-61726"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/cve-2025-61728"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/cve-2025-61731"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/cve-2025-61732"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/cve-2025-68121"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/cve-2026-31837"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5952.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5950"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5950.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:5948"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5948.json"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "See Red Hat OpenShift Service Mesh 3.2.3 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2",
                    "product_ids": [
                        "CSAFPID-5248270",
                        "CSAFPID-5920300",
                        "CSAFPID-5920301"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:5952"
                },
                {
                    "category": "vendor_fix",
                    "details": "See Red Hat OpenShift Service Mesh 3.1.6 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1",
                    "product_ids": [
                        "CSAFPID-5248262",
                        "CSAFPID-5920307",
                        "CSAFPID-5920308"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:5950"
                },
                {
                    "category": "vendor_fix",
                    "details": "See Red Hat OpenShift Service Mesh 3.0.9 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0",
                    "product_ids": [
                        "CSAFPID-5681240",
                        "CSAFPID-5920358",
                        "CSAFPID-5920359"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:5948"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1317175",
                        "CSAFPID-1439279",
                        "CSAFPID-1441053",
                        "CSAFPID-1441054",
                        "CSAFPID-1441055",
                        "CSAFPID-1441076",
                        "CSAFPID-1488100",
                        "CSAFPID-1488101",
                        "CSAFPID-1488102",
                        "CSAFPID-1488104",
                        "CSAFPID-1906087",
                        "CSAFPID-1906088",
                        "CSAFPID-1906089",
                        "CSAFPID-2109922",
                        "CSAFPID-2551999",
                        "CSAFPID-2552000",
                        "CSAFPID-2914848",
                        "CSAFPID-2942231",
                        "CSAFPID-2942233",
                        "CSAFPID-2942235",
                        "CSAFPID-2942236",
                        "CSAFPID-2942237",
                        "CSAFPID-2960949",
                        "CSAFPID-3036145",
                        "CSAFPID-5119808",
                        "CSAFPID-5119810",
                        "CSAFPID-5119811",
                        "CSAFPID-5446216",
                        "CSAFPID-5446217",
                        "CSAFPID-5446218",
                        "CSAFPID-5446219",
                        "CSAFPID-5446220",
                        "CSAFPID-5779785",
                        "CSAFPID-5779786",
                        "CSAFPID-5779787",
                        "CSAFPID-5810304",
                        "CSAFPID-5810305",
                        "CSAFPID-5810306",
                        "CSAFPID-5810307",
                        "CSAFPID-5810308",
                        "CSAFPID-5845003",
                        "CSAFPID-5845004"
                    ]
                }
            ],
            "title": "CVE-2026-31837"
        }
    ]
}