{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-3304",
        "tracking": {
            "current_release_date": "2026-03-31T18:48:20.408983Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-3304",
            "initial_release_date": "2026-02-27T16:26:20.666293Z",
            "revision_history": [
                {
                    "date": "2026-02-27T16:26:20.666293Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T16:26:26.273516Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-27T16:38:56.850479Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T16:38:58.150885Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T17:38:46.228474Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-28T14:13:24.118004Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-01T01:39:34.404686Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-03-01T01:39:41.127498Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T00:27:46.344636Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (27).| Product Identifiers created (9).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-03T00:27:51.878981Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T11:45:28.587650Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (23).| References created (4)."
                },
                {
                    "date": "2026-03-03T11:45:41.116765Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T18:20:55.714026Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T18:21:04.075762Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:29:16.476244Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T18:17:09.474235Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T18:17:12.346170Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-30T12:07:54.977531Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (2).| References created (3)."
                },
                {
                    "date": "2026-03-30T12:07:58.985907Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T00:37:52.084931Z",
                    "number": "20",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| Product Remediations created (2).| References created (36).| CWES updated (1)."
                },
                {
                    "date": "2026-03-31T00:37:54.729507Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T18:47:59.327938Z",
                    "number": "22",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (2).| References created (7).| CWES updated (1)."
                }
            ],
            "status": "interim",
            "version": "22"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<12.0.12.24",
                                "product": {
                                    "name": "vers:unknown/<12.0.12.24",
                                    "product_id": "CSAFPID-5844093"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<13.0.7.0",
                                "product": {
                                    "name": "vers:unknown/<13.0.7.0",
                                    "product_id": "CSAFPID-5963615"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "App Connect Enterprise"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/5",
                                "product": {
                                    "name": "vers:rpm/5",
                                    "product_id": "CSAFPID-1459353",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:logging:5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1455864",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:logging:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Logging Subsystem for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1508265",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:rhdh:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Developer Hub"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/1.8",
                                        "product": {
                                            "name": "vers:rpm/1.8",
                                            "product_id": "CSAFPID-5177667",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:rhdh:1.8::el9"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Developer Hub 1.8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774545605",
                                        "product": {
                                            "name": "vers:oci/1774545605",
                                            "product_id": "CSAFPID-5966218",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/rhdh-hub-rhel9@sha256%3A2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046?arch=amd64&repository_url=registry.redhat.io/rhdh&tag=1774545605"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508266"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhdh-hub-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774549552",
                                        "product": {
                                            "name": "vers:oci/1774549552",
                                            "product_id": "CSAFPID-5966219",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/rhdh-operator-bundle@sha256%3A400d642f10348a0728a624b135228714b3302f1cabc096150a340407133c54e7?arch=amd64&repository_url=registry.redhat.io/rhdh&tag=1774549552"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhdh-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1774544220",
                                        "product": {
                                            "name": "vers:oci/1774544220",
                                            "product_id": "CSAFPID-5966220",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/rhdh-rhel9-operator@sha256%3A72d72d0e8b67012bfaaeae0e1fbbcf8e35c74d4d6252051eabef3e9dd979d48e?arch=amd64&repository_url=registry.redhat.io/rhdh&tag=1774544220"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhdh-rhel9-operator"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Developer Hub"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439315",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2878788",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:trusted_profile_analyzer:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Trusted Profile Analyzer"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-5486263",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_portal:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Self-service automation portal 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5486265"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-portal"
                            }
                        ],
                        "category": "product_family",
                        "name": "Self-service automation portal 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3010673"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cluster-logging-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1496167"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cluster-logging-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2485093"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "eventrouter-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2821638"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "fluentd-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914700"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "log-file-metric-exporter-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2914698"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "logging-view-plugin-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3010674"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "vector-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Logging Subsystem for Red Hat OpenShift"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2878760"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "fido-device-onboard"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2873478"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2876286"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1459356"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1459357"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1459358"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1459360"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "firefox"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1459361"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "thunderbird"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1832822"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhtpa-trustification-service-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Trusted Profile Analyzer"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/0.0.0|<2.1.0",
                                "product": {
                                    "name": "vers:semver/0.0.0|<2.1.0",
                                    "product_id": "CSAFPID-5735671"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2.1.0",
                                "product": {
                                    "name": "vers:unknown/<2.1.0",
                                    "product_id": "CSAFPID-5873918",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:expressjs:multer:*:*:*:*:*:node.js:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<2.1.0",
                                "product": {
                                    "name": "vers:unknown/>=0|<2.1.0",
                                    "product_id": "CSAFPID-5758983"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0",
                                "product": {
                                    "name": "vers:unknown/v1.0.0",
                                    "product_id": "CSAFPID-3678919"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.1",
                                "product": {
                                    "name": "vers:unknown/v1.0.1",
                                    "product_id": "CSAFPID-3678920"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.2",
                                "product": {
                                    "name": "vers:unknown/v1.0.2",
                                    "product_id": "CSAFPID-3678921"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.3",
                                "product": {
                                    "name": "vers:unknown/v1.0.3",
                                    "product_id": "CSAFPID-3678922"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.4",
                                "product": {
                                    "name": "vers:unknown/v1.0.4",
                                    "product_id": "CSAFPID-3678923"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.5",
                                "product": {
                                    "name": "vers:unknown/v1.0.5",
                                    "product_id": "CSAFPID-3678924"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.6",
                                "product": {
                                    "name": "vers:unknown/v1.0.6",
                                    "product_id": "CSAFPID-3678925"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0",
                                "product": {
                                    "name": "vers:unknown/v1.1.0",
                                    "product_id": "CSAFPID-3678926"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0",
                                "product": {
                                    "name": "vers:unknown/v1.2.0",
                                    "product_id": "CSAFPID-3678927"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.1",
                                "product": {
                                    "name": "vers:unknown/v1.2.1",
                                    "product_id": "CSAFPID-3678928"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.0",
                                "product": {
                                    "name": "vers:unknown/v1.3.0",
                                    "product_id": "CSAFPID-3678929"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.1",
                                "product": {
                                    "name": "vers:unknown/v1.3.1",
                                    "product_id": "CSAFPID-3678930"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.0",
                                "product": {
                                    "name": "vers:unknown/v1.4.0",
                                    "product_id": "CSAFPID-3678931"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.1",
                                "product": {
                                    "name": "vers:unknown/v1.4.1",
                                    "product_id": "CSAFPID-3678932"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.2",
                                "product": {
                                    "name": "vers:unknown/v1.4.2",
                                    "product_id": "CSAFPID-3678933"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.3",
                                "product": {
                                    "name": "vers:unknown/v1.4.3",
                                    "product_id": "CSAFPID-3678934"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.4",
                                "product": {
                                    "name": "vers:unknown/v1.4.4",
                                    "product_id": "CSAFPID-3678935"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.4-lts.1",
                                "product": {
                                    "name": "vers:unknown/v1.4.4-lts.1",
                                    "product_id": "CSAFPID-3678936"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.5-lts.1",
                                "product": {
                                    "name": "vers:unknown/v1.4.5-lts.1",
                                    "product_id": "CSAFPID-3678937"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.4.5-lts.2",
                                "product": {
                                    "name": "vers:unknown/v1.4.5-lts.2",
                                    "product_id": "CSAFPID-3678938"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0",
                                "product": {
                                    "name": "vers:unknown/v2.0.0",
                                    "product_id": "CSAFPID-3694484"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.1",
                                "product": {
                                    "name": "vers:unknown/v2.0.1",
                                    "product_id": "CSAFPID-3694485"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.2",
                                "product": {
                                    "name": "vers:unknown/v2.0.2",
                                    "product_id": "CSAFPID-5755735"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "multer"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-5969421"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<2.1.0",
                                "product": {
                                    "name": "vers:unknown/<2.1.0",
                                    "product_id": "CSAFPID-5969422"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "npm/multer"
                    }
                ],
                "category": "vendor",
                "name": "expressjs"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-3304",
            "cwe": {
                "id": "CWE-459",
                "name": "Incomplete Cleanup"
            },
            "flags": [
                {
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "CSAFPID-5966219",
                        "CSAFPID-5966220"
                    ]
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-3304"
                },
                {
                    "category": "description",
                    "text": "Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-3304"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\nA vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.\n\n### Patches\n\nUsers should upgrade to `2.1.0`\n\n### Workarounds\n\nNone",
                    "title": "github - https://github.com/advisories/GHSA-xf7r-hgr6-v32p"
                },
                {
                    "category": "description",
                    "text": "Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.\nA flaw was found in Multer, a Node.js middleware. A remote attacker could exploit this vulnerability by sending specially crafted malformed requests. This could lead to resource exhaustion, resulting in a Denial of Service (DoS) for the application using Multer.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-3304"
                },
                {
                    "category": "description",
                    "text": "Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-3304.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\nA vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.\n\n### Patches\n\nUsers should upgrade to `2.1.0`\n\n### Workarounds\n\nNone",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-xf7r-hgr6-v32p.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-3304"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Multer, a Node.js middleware. A remote attacker could exploit this vulnerability by sending specially crafted malformed requests. This could lead to resource exhaustion, resulting in a Denial of Service (DoS) for the application using Multer.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:6174.json"
                },
                {
                    "category": "description",
                    "text": "A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.",
                    "title": "gitlab - https://gitlab.com/api/v4/projects/25847700/repository/files/npm%2Fmulter%2FCVE-2026-3304.yml/raw"
                },
                {
                    "category": "other",
                    "text": "0.00055",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "VENDOR FIX as product remediation category, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is product_remediation data available from source Redhat, Is related to a product by vendor Ibm",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5966218",
                    "CSAFPID-5969421"
                ],
                "known_affected": [
                    "CSAFPID-5735671",
                    "CSAFPID-1508265",
                    "CSAFPID-1508266",
                    "CSAFPID-5486263",
                    "CSAFPID-5486265",
                    "CSAFPID-3678919",
                    "CSAFPID-3678920",
                    "CSAFPID-3678921",
                    "CSAFPID-3678922",
                    "CSAFPID-3678923",
                    "CSAFPID-3678924",
                    "CSAFPID-3678925",
                    "CSAFPID-3678926",
                    "CSAFPID-3678927",
                    "CSAFPID-3678928",
                    "CSAFPID-3678929",
                    "CSAFPID-3678930",
                    "CSAFPID-3678931",
                    "CSAFPID-3678932",
                    "CSAFPID-3678933",
                    "CSAFPID-3678934",
                    "CSAFPID-3678935",
                    "CSAFPID-3678936",
                    "CSAFPID-3678937",
                    "CSAFPID-3678938",
                    "CSAFPID-3694484",
                    "CSAFPID-3694485",
                    "CSAFPID-5755735",
                    "CSAFPID-5758983",
                    "CSAFPID-5873918",
                    "CSAFPID-5844093",
                    "CSAFPID-5963615",
                    "CSAFPID-5969422"
                ],
                "known_not_affected": [
                    "CSAFPID-1439315",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1455864",
                    "CSAFPID-1459353",
                    "CSAFPID-1459356",
                    "CSAFPID-1459357",
                    "CSAFPID-1459358",
                    "CSAFPID-1459360",
                    "CSAFPID-1459361",
                    "CSAFPID-1496167",
                    "CSAFPID-1832822",
                    "CSAFPID-2485093",
                    "CSAFPID-2821638",
                    "CSAFPID-2858634",
                    "CSAFPID-2873478",
                    "CSAFPID-2876286",
                    "CSAFPID-2878760",
                    "CSAFPID-2878788",
                    "CSAFPID-2914698",
                    "CSAFPID-2914700",
                    "CSAFPID-3010673",
                    "CSAFPID-3010674",
                    "CSAFPID-5966219",
                    "CSAFPID-5966220"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/3xxx/CVE-2026-3304.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-xf7r-hgr6-v32p"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-xf7r-hgr6-v32p"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-3304.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-3304.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-xf7r-hgr6-v32p.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0903.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:6174.json"
                },
                {
                    "category": "external",
                    "summary": "Source - gitlab",
                    "url": "https://gitlab.com/api/v4/projects/25847700/repository/files/npm%2Fmulter%2FCVE-2026-3304.yml/raw"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv; redhat",
                    "url": "https://cna.openjsf.org/security-advisories.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv; redhat",
                    "url": "https://github.com/expressjs/multer/commit/739919097dde3921ec31b930e4b9025036fa74ee"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv; redhat",
                    "url": "https://github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv; redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab",
                    "url": "https://github.com/advisories/GHSA-xf7r-hgr6-v32p"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0903.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0903"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ibm.com/support/pages/node/7267862"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-3304"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2443353"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:6174"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-61140"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-1615"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-2359"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-24046"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-25153"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-25639"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-25896"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-26278"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-27606"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-27942"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-3520"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://catalog.redhat.com/search?gs&searchType=containers&q=rhdh"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://developers.redhat.com/rhdh/overview"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://docs.redhat.com/en/documentation/red_hat_developer_hub"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-11518"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-11639"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-11731"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12108"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12139"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12323"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12335"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12392"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12417"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12444"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12447"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHIDP-12480"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6174.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - gitlab",
                    "url": "https://github.com/expressjs/multer"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "For more about Red Hat Developer Hub, see References links",
                    "product_ids": [
                        "CSAFPID-5177667",
                        "CSAFPID-5966218"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:6174"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1508265",
                        "CSAFPID-1508266",
                        "CSAFPID-3678919",
                        "CSAFPID-3678920",
                        "CSAFPID-3678921",
                        "CSAFPID-3678922",
                        "CSAFPID-3678923",
                        "CSAFPID-3678924",
                        "CSAFPID-3678925",
                        "CSAFPID-3678926",
                        "CSAFPID-3678927",
                        "CSAFPID-3678928",
                        "CSAFPID-3678929",
                        "CSAFPID-3678930",
                        "CSAFPID-3678931",
                        "CSAFPID-3678932",
                        "CSAFPID-3678933",
                        "CSAFPID-3678934",
                        "CSAFPID-3678935",
                        "CSAFPID-3678936",
                        "CSAFPID-3678937",
                        "CSAFPID-3678938",
                        "CSAFPID-3694484",
                        "CSAFPID-3694485",
                        "CSAFPID-5486263",
                        "CSAFPID-5486265",
                        "CSAFPID-5735671",
                        "CSAFPID-5755735",
                        "CSAFPID-5758983",
                        "CSAFPID-5844093",
                        "CSAFPID-5873918",
                        "CSAFPID-5963615",
                        "CSAFPID-5969422"
                    ]
                }
            ],
            "title": "CVE-2026-3304"
        }
    ]
}