Skip to content

Conversation

@jlsec-bot
Copy link
Contributor

This action searched recent NVD/EUVD changes/publications, checking 408 (+0) advisories from NVD and 527 (+264) from EUVD for advisories that pertain here. It identified 5 advisories as being related to the Julia package(s): Poppler_jll, XML2_jll, GnuPG_jll, and HTTP.

3 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2024-56378 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at <= 24.12.0 includes all versions
  • CVE-2025-30258 for packages: GnuPG_jll
    • GnuPG_jll computed ["*"]. Its latest version (2.4.7+0) has components: {gnupg = "2.4.7"}
      • gnupg:gnupg at < 2.5.5 includes all versions
  • CVE-2025-52886 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.06.0 includes all versions

2 advisories found concrete vulnerable ranges

  • CVE-2024-34459 for packages: XML2_jll
    • XML2_jll computed ["< 2.12.7+0"]. Its latest version (2.14.4+0) has components: {libxml2 = "2.14.4"}
  • CVE-2025-61689 for packages: HTTP
    • HTTP computed ["< 1.10.19"].

@mbauman
Copy link
Member

mbauman commented Oct 17, 2025

@mbauman mbauman closed this Oct 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants