{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-31958",
        "tracking": {
            "current_release_date": "2026-04-01T15:54:55.859070Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-31958",
            "initial_release_date": "2026-03-11T19:38:48.646503Z",
            "revision_history": [
                {
                    "date": "2026-03-11T19:38:48.646503Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T19:39:01.049911Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-11T20:26:43.225819Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-03-11T20:26:50.415190Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T00:44:34.398559Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (2)."
                },
                {
                    "date": "2026-03-12T00:44:43.486043Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T06:43:58.679623Z",
                    "number": "7",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-03-12T14:50:34.875117Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-12T14:50:44.825049Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T14:57:26.803511Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-12T14:57:29.378450Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-12T20:38:52.633617Z",
                    "number": "12",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-13T00:29:02.126986Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (35).| Product Identifiers created (6).| Product Remediations created (35).| References created (3).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-13T00:29:12.376161Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-16T20:25:05.307677Z",
                    "number": "15",
                    "summary": "CVSS created.| Products connected (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-16T20:25:12.998888Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T15:30:22.280187Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:30:24.767369Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:32:08.417997Z",
                    "number": "19",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:32:13.565459Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T11:12:32.394683Z",
                    "number": "21",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (69).| Products created (2).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-27T11:12:46.004761Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-01T09:50:53.781265Z",
                    "number": "23",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products created (1)."
                },
                {
                    "date": "2026-04-01T09:50:56.940697Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-01T12:44:34.285806Z",
                    "number": "25",
                    "summary": "Products created (1).| Product Identifiers created (1).| Products removed (1)."
                },
                {
                    "date": "2026-04-01T12:44:40.847667Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-01T15:36:09.594537Z",
                    "number": "27",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-04-01T15:36:12.109435Z",
                    "number": "28",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-01T15:54:53.768409Z",
                    "number": "29",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (2).| CWES updated (1).| Unknown change."
                }
            ],
            "status": "interim",
            "version": "29"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-5207390",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:external_secrets_operator:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "External Secrets Operator for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-5198605",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux_ai:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux AI (RHEL AI) 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439328",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5264795"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "bitwarden-sdk-server-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5264796"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-secrets-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5264797"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-secrets-operator-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5207391"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "external-secrets-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "External Secrets Operator for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5205180"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "bootc-cuda-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5205182"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "disk-image-cuda-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux AI (RHEL AI) 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3112099"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-llama-stack-core-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068100"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-datascience-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068103"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-minimal-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068105"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-pytorch-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222767"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068108"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-pytorch-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068110"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-tensorflow-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5155537"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-pipeline-runtime-tensorflow-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5207375"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-trustyai-ragas-lls-provider-dsp-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068114"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-codeserver-datascience-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068116"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-datascience-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068119"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-minimal-cpu-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068121"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-minimal-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068123"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-minimal-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068126"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-pytorch-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222780"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068128"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-pytorch-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068131"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-tensorflow-cuda-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5155538"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-tensorflow-rocm-py312-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5068134"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-workbench-jupyter-trustyai-cpu-py312-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2109952"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pcs"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2109953"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pcs"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847198"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pep517"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Container Platform 4"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<6.5.5",
                                "product": {
                                    "name": "vers:unknown/<6.5.5",
                                    "product_id": "CSAFPID-5798753",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0",
                                "product": {
                                    "name": "vers:unknown/v1.0.0",
                                    "product_id": "CSAFPID-3461238"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0",
                                "product": {
                                    "name": "vers:unknown/v1.1.0",
                                    "product_id": "CSAFPID-3461239"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.1",
                                "product": {
                                    "name": "vers:unknown/v1.1.1",
                                    "product_id": "CSAFPID-3461240"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0",
                                "product": {
                                    "name": "vers:unknown/v1.2.0",
                                    "product_id": "CSAFPID-3461241"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.1",
                                "product": {
                                    "name": "vers:unknown/v1.2.1",
                                    "product_id": "CSAFPID-3461242"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0",
                                "product": {
                                    "name": "vers:unknown/v2.0.0",
                                    "product_id": "CSAFPID-3461243"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.0",
                                "product": {
                                    "name": "vers:unknown/v2.1.0",
                                    "product_id": "CSAFPID-3461244"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.1.1",
                                "product": {
                                    "name": "vers:unknown/v2.1.1",
                                    "product_id": "CSAFPID-3461245"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.2.0",
                                "product": {
                                    "name": "vers:unknown/v2.2.0",
                                    "product_id": "CSAFPID-3461246"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.2.1",
                                "product": {
                                    "name": "vers:unknown/v2.2.1",
                                    "product_id": "CSAFPID-3461247"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.3.0",
                                "product": {
                                    "name": "vers:unknown/v2.3.0",
                                    "product_id": "CSAFPID-3461248"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.0",
                                "product": {
                                    "name": "vers:unknown/v2.4.0",
                                    "product_id": "CSAFPID-3461249"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.4.1",
                                "product": {
                                    "name": "vers:unknown/v2.4.1",
                                    "product_id": "CSAFPID-3461250"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.0.0",
                                "product": {
                                    "name": "vers:unknown/v3.0.0",
                                    "product_id": "CSAFPID-3461251"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.0.1",
                                "product": {
                                    "name": "vers:unknown/v3.0.1",
                                    "product_id": "CSAFPID-3461252"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.0.2",
                                "product": {
                                    "name": "vers:unknown/v3.0.2",
                                    "product_id": "CSAFPID-3461253"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.1.0",
                                "product": {
                                    "name": "vers:unknown/v3.1.0",
                                    "product_id": "CSAFPID-3461254"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.1.1",
                                "product": {
                                    "name": "vers:unknown/v3.1.1",
                                    "product_id": "CSAFPID-3461255"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0",
                                "product": {
                                    "name": "vers:unknown/v3.2.0",
                                    "product_id": "CSAFPID-3461256"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0b1",
                                "product": {
                                    "name": "vers:unknown/v3.2.0b1",
                                    "product_id": "CSAFPID-3461257"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.0b2",
                                "product": {
                                    "name": "vers:unknown/v3.2.0b2",
                                    "product_id": "CSAFPID-3461258"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.1",
                                "product": {
                                    "name": "vers:unknown/v3.2.1",
                                    "product_id": "CSAFPID-3461259"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.2.2",
                                "product": {
                                    "name": "vers:unknown/v3.2.2",
                                    "product_id": "CSAFPID-3461260"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.0",
                                "product": {
                                    "name": "vers:unknown/v4.0.0",
                                    "product_id": "CSAFPID-3461261"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.0b1",
                                "product": {
                                    "name": "vers:unknown/v4.0.0b1",
                                    "product_id": "CSAFPID-3461262"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.0b2",
                                "product": {
                                    "name": "vers:unknown/v4.0.0b2",
                                    "product_id": "CSAFPID-3461263"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.0b3",
                                "product": {
                                    "name": "vers:unknown/v4.0.0b3",
                                    "product_id": "CSAFPID-3461264"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.1",
                                "product": {
                                    "name": "vers:unknown/v4.0.1",
                                    "product_id": "CSAFPID-3461265"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.2",
                                "product": {
                                    "name": "vers:unknown/v4.0.2",
                                    "product_id": "CSAFPID-3461266"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.1.0",
                                "product": {
                                    "name": "vers:unknown/v4.1.0",
                                    "product_id": "CSAFPID-3461267"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.1.0b1",
                                "product": {
                                    "name": "vers:unknown/v4.1.0b1",
                                    "product_id": "CSAFPID-3461268"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.1.0b2",
                                "product": {
                                    "name": "vers:unknown/v4.1.0b2",
                                    "product_id": "CSAFPID-3461269"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.2.0",
                                "product": {
                                    "name": "vers:unknown/v4.2.0",
                                    "product_id": "CSAFPID-3461270"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.2.0b1",
                                "product": {
                                    "name": "vers:unknown/v4.2.0b1",
                                    "product_id": "CSAFPID-3461271"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.2.1",
                                "product": {
                                    "name": "vers:unknown/v4.2.1",
                                    "product_id": "CSAFPID-3461272"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.3.0",
                                "product": {
                                    "name": "vers:unknown/v4.3.0",
                                    "product_id": "CSAFPID-3461273"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.3.0b1",
                                "product": {
                                    "name": "vers:unknown/v4.3.0b1",
                                    "product_id": "CSAFPID-3461274"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.3.0b2",
                                "product": {
                                    "name": "vers:unknown/v4.3.0b2",
                                    "product_id": "CSAFPID-3461275"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.4.0",
                                "product": {
                                    "name": "vers:unknown/v4.4.0",
                                    "product_id": "CSAFPID-3461276"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.4.0b1",
                                "product": {
                                    "name": "vers:unknown/v4.4.0b1",
                                    "product_id": "CSAFPID-3461277"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.4.1",
                                "product": {
                                    "name": "vers:unknown/v4.4.1",
                                    "product_id": "CSAFPID-3461278"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.4.2",
                                "product": {
                                    "name": "vers:unknown/v4.4.2",
                                    "product_id": "CSAFPID-3461279"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.4.3",
                                "product": {
                                    "name": "vers:unknown/v4.4.3",
                                    "product_id": "CSAFPID-3461280"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.5.0",
                                "product": {
                                    "name": "vers:unknown/v4.5.0",
                                    "product_id": "CSAFPID-3461281"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.5.1",
                                "product": {
                                    "name": "vers:unknown/v4.5.1",
                                    "product_id": "CSAFPID-3461282"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.5.2",
                                "product": {
                                    "name": "vers:unknown/v4.5.2",
                                    "product_id": "CSAFPID-3461283"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.5.3",
                                "product": {
                                    "name": "vers:unknown/v4.5.3",
                                    "product_id": "CSAFPID-3461284"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.0",
                                "product": {
                                    "name": "vers:unknown/v5.0.0",
                                    "product_id": "CSAFPID-3461285"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.1",
                                "product": {
                                    "name": "vers:unknown/v5.0.1",
                                    "product_id": "CSAFPID-3461286"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.1.0",
                                "product": {
                                    "name": "vers:unknown/v5.1.0",
                                    "product_id": "CSAFPID-3461287"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.1.0b1",
                                "product": {
                                    "name": "vers:unknown/v5.1.0b1",
                                    "product_id": "CSAFPID-3461288"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.0.0",
                                "product": {
                                    "name": "vers:unknown/v6.0.0",
                                    "product_id": "CSAFPID-3461289"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.0.0b1",
                                "product": {
                                    "name": "vers:unknown/v6.0.0b1",
                                    "product_id": "CSAFPID-3461290"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.1.0",
                                "product": {
                                    "name": "vers:unknown/v6.1.0",
                                    "product_id": "CSAFPID-3461291"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.1.0b1",
                                "product": {
                                    "name": "vers:unknown/v6.1.0b1",
                                    "product_id": "CSAFPID-3461292"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.1.0b2",
                                "product": {
                                    "name": "vers:unknown/v6.1.0b2",
                                    "product_id": "CSAFPID-3461293"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.2.0",
                                "product": {
                                    "name": "vers:unknown/v6.2.0",
                                    "product_id": "CSAFPID-3461294"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.2.0b1",
                                "product": {
                                    "name": "vers:unknown/v6.2.0b1",
                                    "product_id": "CSAFPID-3461295"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.2.0b2",
                                "product": {
                                    "name": "vers:unknown/v6.2.0b2",
                                    "product_id": "CSAFPID-3461296"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.3.0",
                                "product": {
                                    "name": "vers:unknown/v6.3.0",
                                    "product_id": "CSAFPID-3461297"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.3.0b1",
                                "product": {
                                    "name": "vers:unknown/v6.3.0b1",
                                    "product_id": "CSAFPID-3461298"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.3.1",
                                "product": {
                                    "name": "vers:unknown/v6.3.1",
                                    "product_id": "CSAFPID-3461299"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.4.0",
                                "product": {
                                    "name": "vers:unknown/v6.4.0",
                                    "product_id": "CSAFPID-3650482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.4.0b1",
                                "product": {
                                    "name": "vers:unknown/v6.4.0b1",
                                    "product_id": "CSAFPID-3650483"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.4.1",
                                "product": {
                                    "name": "vers:unknown/v6.4.1",
                                    "product_id": "CSAFPID-3650484"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.5.0",
                                "product": {
                                    "name": "vers:unknown/v6.5.0",
                                    "product_id": "CSAFPID-5264723"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.5.0b1",
                                "product": {
                                    "name": "vers:unknown/v6.5.0b1",
                                    "product_id": "CSAFPID-3677769"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.5.1",
                                "product": {
                                    "name": "vers:unknown/v6.5.1",
                                    "product_id": "CSAFPID-5264724"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.5.2",
                                "product": {
                                    "name": "vers:unknown/v6.5.2",
                                    "product_id": "CSAFPID-5264725"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.5.3",
                                "product": {
                                    "name": "vers:unknown/v6.5.3",
                                    "product_id": "CSAFPID-5937996"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v6.5.4",
                                "product": {
                                    "name": "vers:unknown/v6.5.4",
                                    "product_id": "CSAFPID-5937997"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Tornado"
                    }
                ],
                "category": "vendor",
                "name": "Tornado Web"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1404748"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-tornado"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/6.1.0-1+deb11u4",
                                        "product": {
                                            "name": "vers:deb/6.1.0-1+deb11u4",
                                            "product_id": "CSAFPID-5973128",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/python-tornado@6.1.0-1+deb11u4?distro=bullseye"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-tornado"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<6.5.5",
                                "product": {
                                    "name": "vers:unknown/<6.5.5",
                                    "product_id": "CSAFPID-5971816"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "tornado"
                    }
                ],
                "category": "vendor",
                "name": "unknown"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-31958",
            "cwe": {
                "id": "CWE-770",
                "name": "Allocation of Resources Without Limits or Throttling"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-31958"
                },
                {
                    "category": "description",
                    "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-31958"
                },
                {
                    "category": "description",
                    "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-31958"
                },
                {
                    "category": "description",
                    "text": "In versions of Tornado prior to 6.5.5, the only limit on the number of parts in `multipart/form-data` is the `max_body_size` setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. \n\nTornado 6.5.5 introduces new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request. These limits are configurable if needed; see `tornado.httputil.ParseMultipartConfig`. It is also now possible to disable `multipart/form-data` parsing entirely if it is not required for the application.",
                    "title": "github - https://github.com/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in tornado-python. A remote attacker can exploit this vulnerability by sending a specially crafted, very large multipart body with numerous parts. Because the parsing of these large bodies occurs synchronously on the main thread, it can consume excessive resources, leading to a denial of service (DoS) for the application.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-31958"
                },
                {
                    "category": "description",
                    "text": "In versions of Tornado prior to 6.5.5, the only limit on the number of parts in `multipart/form-data` is the `max_body_size` setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. \n\nTornado 6.5.5 introduces new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request. These limits are configurable if needed; see `tornado.httputil.ParseMultipartConfig`. It is also now possible to disable `multipart/form-data` parsing entirely if it is not required for the application.",
                    "title": "github - https://api.github.com/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "description",
                    "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-31958.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Affected versions of the Tornado package are vulnerable to Denial of Service (DoS) due to uncontrolled multipart parsing complexity. The vulnerable multipart/form-data parser processes request bodies synchronously on the main thread, and before version 6.5.5 the only effective constraint on the number of multipart sections was max_body_size, which allows an attacker to submit a very large body containing an excessive number of parts and force expensive parsing work.",
                    "title": "pyupio - https://raw.githubusercontent.com/pyupio/safety-db/refs/heads/master/data/insecure_full.json"
                },
                {
                    "category": "description",
                    "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-31958"
                },
                {
                    "category": "description",
                    "text": "Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/31xxx/CVE-2026-31958.json"
                },
                {
                    "category": "other",
                    "text": "0.00071",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "3.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, The value of the most recent CVSS (V3) score, Is related to a product by vendor Unknown",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "first_fixed": [
                    "CSAFPID-5973128"
                ],
                "known_affected": [
                    "CSAFPID-5798753",
                    "CSAFPID-1404748",
                    "CSAFPID-1439279",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1439328",
                    "CSAFPID-2109952",
                    "CSAFPID-2109953",
                    "CSAFPID-2847198",
                    "CSAFPID-3112099",
                    "CSAFPID-5068100",
                    "CSAFPID-5068103",
                    "CSAFPID-5068105",
                    "CSAFPID-5068108",
                    "CSAFPID-5068110",
                    "CSAFPID-5068114",
                    "CSAFPID-5068116",
                    "CSAFPID-5068119",
                    "CSAFPID-5068121",
                    "CSAFPID-5068123",
                    "CSAFPID-5068126",
                    "CSAFPID-5068128",
                    "CSAFPID-5068131",
                    "CSAFPID-5068134",
                    "CSAFPID-5155537",
                    "CSAFPID-5155538",
                    "CSAFPID-5198605",
                    "CSAFPID-5205180",
                    "CSAFPID-5205182",
                    "CSAFPID-5207375",
                    "CSAFPID-5207390",
                    "CSAFPID-5207391",
                    "CSAFPID-5222767",
                    "CSAFPID-5222780",
                    "CSAFPID-5264795",
                    "CSAFPID-5264796",
                    "CSAFPID-5264797",
                    "CSAFPID-3461238",
                    "CSAFPID-3461239",
                    "CSAFPID-3461240",
                    "CSAFPID-3461241",
                    "CSAFPID-3461242",
                    "CSAFPID-3461243",
                    "CSAFPID-3461244",
                    "CSAFPID-3461245",
                    "CSAFPID-3461246",
                    "CSAFPID-3461247",
                    "CSAFPID-3461248",
                    "CSAFPID-3461249",
                    "CSAFPID-3461250",
                    "CSAFPID-3461251",
                    "CSAFPID-3461252",
                    "CSAFPID-3461253",
                    "CSAFPID-3461254",
                    "CSAFPID-3461255",
                    "CSAFPID-3461256",
                    "CSAFPID-3461257",
                    "CSAFPID-3461258",
                    "CSAFPID-3461259",
                    "CSAFPID-3461260",
                    "CSAFPID-3461261",
                    "CSAFPID-3461262",
                    "CSAFPID-3461263",
                    "CSAFPID-3461264",
                    "CSAFPID-3461265",
                    "CSAFPID-3461266",
                    "CSAFPID-3461267",
                    "CSAFPID-3461268",
                    "CSAFPID-3461269",
                    "CSAFPID-3461270",
                    "CSAFPID-3461271",
                    "CSAFPID-3461272",
                    "CSAFPID-3461273",
                    "CSAFPID-3461274",
                    "CSAFPID-3461275",
                    "CSAFPID-3461276",
                    "CSAFPID-3461277",
                    "CSAFPID-3461278",
                    "CSAFPID-3461279",
                    "CSAFPID-3461280",
                    "CSAFPID-3461281",
                    "CSAFPID-3461282",
                    "CSAFPID-3461283",
                    "CSAFPID-3461284",
                    "CSAFPID-3461285",
                    "CSAFPID-3461286",
                    "CSAFPID-3461287",
                    "CSAFPID-3461288",
                    "CSAFPID-3461289",
                    "CSAFPID-3461290",
                    "CSAFPID-3461291",
                    "CSAFPID-3461292",
                    "CSAFPID-3461293",
                    "CSAFPID-3461294",
                    "CSAFPID-3461295",
                    "CSAFPID-3461296",
                    "CSAFPID-3461297",
                    "CSAFPID-3461298",
                    "CSAFPID-3461299",
                    "CSAFPID-3650482",
                    "CSAFPID-3650483",
                    "CSAFPID-3650484",
                    "CSAFPID-3677769",
                    "CSAFPID-5264723",
                    "CSAFPID-5264724",
                    "CSAFPID-5264725",
                    "CSAFPID-5937996",
                    "CSAFPID-5937997",
                    "CSAFPID-5971816"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/31xxx/CVE-2026-31958.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-31958.json"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-31958.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - pyupio",
                    "url": "https://raw.githubusercontent.com/pyupio/safety-db/refs/heads/master/data/insecure_full.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/31xxx/CVE-2026-31958.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/tornadoweb/tornado/releases/tag/v6.5.5"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-qjxf-f2mg-c6mc"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-31958"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31958.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://lists.debian.org/debian-lts-announce/2026/04/msg00000.html"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
                    "product_ids": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1439328",
                        "CSAFPID-2109952",
                        "CSAFPID-2109953",
                        "CSAFPID-2847198",
                        "CSAFPID-3112099",
                        "CSAFPID-5068100",
                        "CSAFPID-5068103",
                        "CSAFPID-5068105",
                        "CSAFPID-5068108",
                        "CSAFPID-5068110",
                        "CSAFPID-5068114",
                        "CSAFPID-5068116",
                        "CSAFPID-5068119",
                        "CSAFPID-5068121",
                        "CSAFPID-5068123",
                        "CSAFPID-5068126",
                        "CSAFPID-5068128",
                        "CSAFPID-5068131",
                        "CSAFPID-5068134",
                        "CSAFPID-5155537",
                        "CSAFPID-5155538",
                        "CSAFPID-5198605",
                        "CSAFPID-5205180",
                        "CSAFPID-5205182",
                        "CSAFPID-5207375",
                        "CSAFPID-5207390",
                        "CSAFPID-5207391",
                        "CSAFPID-5222767",
                        "CSAFPID-5222780",
                        "CSAFPID-5264795",
                        "CSAFPID-5264796",
                        "CSAFPID-5264797"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1404748",
                        "CSAFPID-1439279",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1439328",
                        "CSAFPID-2109952",
                        "CSAFPID-2109953",
                        "CSAFPID-2847198",
                        "CSAFPID-3112099",
                        "CSAFPID-3461238",
                        "CSAFPID-3461239",
                        "CSAFPID-3461240",
                        "CSAFPID-3461241",
                        "CSAFPID-3461242",
                        "CSAFPID-3461243",
                        "CSAFPID-3461244",
                        "CSAFPID-3461245",
                        "CSAFPID-3461246",
                        "CSAFPID-3461247",
                        "CSAFPID-3461248",
                        "CSAFPID-3461249",
                        "CSAFPID-3461250",
                        "CSAFPID-3461251",
                        "CSAFPID-3461252",
                        "CSAFPID-3461253",
                        "CSAFPID-3461254",
                        "CSAFPID-3461255",
                        "CSAFPID-3461256",
                        "CSAFPID-3461257",
                        "CSAFPID-3461258",
                        "CSAFPID-3461259",
                        "CSAFPID-3461260",
                        "CSAFPID-3461261",
                        "CSAFPID-3461262",
                        "CSAFPID-3461263",
                        "CSAFPID-3461264",
                        "CSAFPID-3461265",
                        "CSAFPID-3461266",
                        "CSAFPID-3461267",
                        "CSAFPID-3461268",
                        "CSAFPID-3461269",
                        "CSAFPID-3461270",
                        "CSAFPID-3461271",
                        "CSAFPID-3461272",
                        "CSAFPID-3461273",
                        "CSAFPID-3461274",
                        "CSAFPID-3461275",
                        "CSAFPID-3461276",
                        "CSAFPID-3461277",
                        "CSAFPID-3461278",
                        "CSAFPID-3461279",
                        "CSAFPID-3461280",
                        "CSAFPID-3461281",
                        "CSAFPID-3461282",
                        "CSAFPID-3461283",
                        "CSAFPID-3461284",
                        "CSAFPID-3461285",
                        "CSAFPID-3461286",
                        "CSAFPID-3461287",
                        "CSAFPID-3461288",
                        "CSAFPID-3461289",
                        "CSAFPID-3461290",
                        "CSAFPID-3461291",
                        "CSAFPID-3461292",
                        "CSAFPID-3461293",
                        "CSAFPID-3461294",
                        "CSAFPID-3461295",
                        "CSAFPID-3461296",
                        "CSAFPID-3461297",
                        "CSAFPID-3461298",
                        "CSAFPID-3461299",
                        "CSAFPID-3650482",
                        "CSAFPID-3650483",
                        "CSAFPID-3650484",
                        "CSAFPID-3677769",
                        "CSAFPID-5068100",
                        "CSAFPID-5068103",
                        "CSAFPID-5068105",
                        "CSAFPID-5068108",
                        "CSAFPID-5068110",
                        "CSAFPID-5068114",
                        "CSAFPID-5068116",
                        "CSAFPID-5068119",
                        "CSAFPID-5068121",
                        "CSAFPID-5068123",
                        "CSAFPID-5068126",
                        "CSAFPID-5068128",
                        "CSAFPID-5068131",
                        "CSAFPID-5068134",
                        "CSAFPID-5155537",
                        "CSAFPID-5155538",
                        "CSAFPID-5198605",
                        "CSAFPID-5205180",
                        "CSAFPID-5205182",
                        "CSAFPID-5207375",
                        "CSAFPID-5207390",
                        "CSAFPID-5207391",
                        "CSAFPID-5222767",
                        "CSAFPID-5222780",
                        "CSAFPID-5264723",
                        "CSAFPID-5264724",
                        "CSAFPID-5264725",
                        "CSAFPID-5264795",
                        "CSAFPID-5264796",
                        "CSAFPID-5264797",
                        "CSAFPID-5798753",
                        "CSAFPID-5937996",
                        "CSAFPID-5937997",
                        "CSAFPID-5971816"
                    ]
                }
            ],
            "title": "CVE-2026-31958"
        }
    ]
}