Skip to content

Conversation

@jlsec-bot
Copy link
Contributor

This action searched recent NVD/EUVD changes/publications, checking 587 (+20) advisories from NVD and 373 (+263) from EUVD for advisories that pertain here. It identified 6 advisories as being related to the Julia package(s): Perl_jll, XML2_jll, libssh_jll, GnuPG_jll, and LibArchive_jll.

1 advisories failed to parse the source version range

These advisories seem to apply to a Julia package but had trouble identifying exactly how and at which versions.

  • CVE-2025-5318 for packages: libssh_jll
    • libssh_jll computed ["*"]. Its latest version (0.11.1+0) has components: {libssh = "0.11.1"}
      • libssh:libssh at `` failed to parse

1 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2025-30258 for packages: GnuPG_jll
    • GnuPG_jll computed ["*"]. Its latest version (2.4.7+0) has components: {gnupg = "2.4.7"}
      • gnupg:gnupg at < 2.4.8 includes all versions

1 advisories apply to the latest version of a package and do not have a patch

  • CVE-2024-56406 for packages: Perl_jll
    • Perl_jll computed [">= 5.34.0+0"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}
      • perl:perl at >= 5.33.1, < 5.38.4 mapped to [>= 5.34.0+0], includes the latest version`

3 advisories found concrete vulnerable ranges

  • CVE-2024-56171 for packages: XML2_jll
    • XML2_jll computed ["< 2.13.6+1"]. Its latest version (2.15.0+0) has components: {libxml2 = "2.15.0"}
  • CVE-2025-24928 for packages: XML2_jll
    • XML2_jll computed ["< 2.13.6+1"]. Its latest version (2.15.0+0) has components: {libxml2 = "2.15.0"}
  • CVE-2025-5914 for packages: LibArchive_jll
    • LibArchive_jll computed ["< 3.8.0+0"]. Its latest version (3.8.1+0) has components: {libarchive = "3.8.1"}

@mbauman mbauman closed this Oct 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants