-
Notifications
You must be signed in to change notification settings - Fork 494
Add alias CVE-2025-55182 to GHSA-9qr9-h5gf-34mp #6496
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add alias CVE-2025-55182 to GHSA-9qr9-h5gf-34mp #6496
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR updates the security advisory GHSA-9qr9-h5gf-34mp to replace a rejected CVE ID with the active one. CVE-2025-66478 was rejected by NVD as a duplicate of CVE-2025-55182, so both IDs are now listed as aliases to ensure proper vulnerability tracking.
Key changes:
- Added CVE-2025-55182 to the aliases array
- Retained CVE-2025-66478 for reference
- Updated the modification timestamp
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Per the OSV schema, https://ossf.github.io/osv-schema/#aliases-field
|
|
@mswilson Thanks for the comment! |
|
As long as |
|
Hi @tockn and @mswilson, I'm removing CVE-2025-66478 as a CVE ID and changing the reference link https://nvd.nist.gov/vuln/detail/CVE-2025-66478 to https://nvd.nist.gov/vuln/detail/CVE-2025-55182 to clarify that GHSA-9qr9-h5gf-34mp refers to CVE-2025-55182. However, I can't add CVE-2025-55182 as an alias to GHSA-9qr9-h5gf-34mp because CVE-2025-55182 is already attached to GHSA-fv66-9v8q-g76r in the database backend. |
0b6dad6
into
github:tockn/advisory-improvement-6496
|
Hi @tockn! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Summary
This PR adds
CVE-2025-55182as an alias to this advisory.Details
According to NVD,
CVE-2025-66478has been REJECTED as a duplicate ofCVE-2025-55182.This change adds the active CVE ID to the aliases to correctly map this vulnerability.
References