StackRadar

CVE-2026-42533

Critical

Advisory

Published 15 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.045
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,781 indexed, latest versions
Container images
119
deployed by those charts
Fix available
6 of 6
affected packages

NGINX Map directive and Regex matching vulnerability

Carried by container images the latest versions of 119 of 17,781 indexed charts deploy, on 119 images.

Affected packageAffected versionsFixed inImages
nginxdeb1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+35 more1.18.0-6ubuntu14.20, 1.24.0-2ubuntu7.17, 1.26.3-3+deb13u888
nginxapk1.26.2-r4, 1.26.3-r0, 1.28.0-r3, 1.28.1-r1+4 more1.26.3-r2, 1.28.3-r614
nginxbitnami1.25.5-0, 1.27.1-2, 1.28.0-0, 1.31.3-01.30.44
nginx-mainlineapk1.27.4-r0, 1.27.4-r2, 1.29.8-r11.31.3-r03
NGINX Open Sourcebitnami1.25.5-01.30.41
nginxrpm1:1.20.1-13.el9, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0, 1:1.22.1-8.module+el9.5.0+22953+b175c265.1, 1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3+3 more1.21.5-150600.10.27.1, 2:1.20.1-28.el9_8.610
OSV records
ALPINE-CVE-2026-42533BIT-nginx-2026-42533CGA-3cc9-j23w-933vDEBIAN-CVE-2026-42533RHSA-2026:66542UBUNTU-CVE-2026-42533SUSE-SU-2026:3469-1
Also known as
BIT-nginx-gateway-2026-42533, CGA-x99p-pq5w-pxj6, USN-8563-1, USN-8563-2, USN-8563-3, USN-8563-4

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
zabbixzabbix-communityVerified publisher7.1.01 of 5See more

zabbix zabbix-community 7.1.0

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nginx@1.24.0-2ubuntu7.5
1.24.0-2ubuntu7.17

Open the chart page →

13,664
zammadzammadOfficialVerified publisher18.0.51 of 5See more

zammad zammad 18.0.5

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8

Open the chart page →

6,887
k10kastenVerified publisher9.0.51 of 23See more

k10 kasten 9.0.5

1 of the 23 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
gcr.io/kasten-images/frontend:9.0.54b36f413cabb
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
2:1.20.1-28.el9_8.6

Open the chart page →

1,880
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
nginx@1.22.1-9
no fix listed

Open the chart page →

10,622
weblateweblateOfficialVerified publisher0.5.361 of 3See more

weblate weblate 0.5.36

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
weblate/weblate:2026.9.1.0990720d1737a
nginx@1.28.3-2ubuntu1.10
no fix listed

Open the chart page →

6,699
zabbixcetic3.1.31 of 5See more

zabbix cetic 3.1.3

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
nginx@1.22.0-1~jammy
no fix listed

Open the chart page →

33,725
stackstorm-hastackstormVerified publisher1.1.01 of 17See more

stackstorm-ha stackstorm 1.1.0

1 of the 17 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
stackstorm/st2web:3.809989a26c8b7
nginx@1.24.0-1~focal
no fix listed

Open the chart page →

96,419
zabbix-serveraekondratievVerified publisher1.0.61 of 4See more

zabbix-server aekondratiev 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
nginx@1.20.1-1~focal
no fix listed

Open the chart page →

30,668
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
nginx@1.26.2-r4
1.26.3-r2

Open the chart page →

2,811
passboltpassbolt2.1.11 of 6See more

passbolt passbolt 2.1.1

1 of the 6 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8

Open the chart page →

13,350
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
nginx@1.28.0-1~jammy
no fix listed

Open the chart page →

27,267
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
nginx@1.28.3-2ubuntu1.10
no fix listed

Open the chart page →

1,201
bookstackbookstack-mgVerified publisher0.3.11 of 2See more

bookstack bookstack-mg 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
linuxserver/bookstack:26.05.202605282ebf97852661
nginx@1.28.3-r2
1.28.3-r6

Open the chart page →

1,896
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
nginx@1:1.26.1-2.el9.ngx
2:1.20.1-28.el9_8.6

Open the chart page →

7,450
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
nginx@1.27.4-1~bookworm
no fix listed

Open the chart page →

5,435
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
nginx@1.27.3-1~bookworm
no fix listed

Open the chart page →

7,052
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8

Open the chart page →

9,770
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nginx@1.25.1-1~bookworm
no fix listed

Open the chart page →

9,724
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
nginx@1.28.0-0
1.30.4

Open the chart page →

52,635
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
nginx@1.26.1-2~jammy
no fix listed

Open the chart page →

10,858
zabbix-server-mysqlfermosit3.0.21 of 4See more

zabbix-server-mysql fermosit 3.0.2

1 of the 4 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
nginx@1.24.0-2ubuntu7.1
1.24.0-2ubuntu7.17

Open the chart page →

12,840
rss-bridgegabe565Verified publisher0.5.21 of 1See more

rss-bridge gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/rss-bridge/rss-bridge:latest606896116558
nginx@1.22.1-9+deb12u9
no fix listed

Open the chart page →

2,186
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nginx@1.18.0-0ubuntu1.2
no fix listed

Open the chart page →

12,422
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
nginx@1.29.1-1~bookworm
no fix listed

Open the chart page →

3,544
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
nginx@1.28.0-1~bookworm
no fix listed

Open the chart page →

3,980
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.10.0e60f36161511
nginx@1.21.5-150600.10.9.1
1.21.5-150600.10.27.1

Open the chart page →

13,479
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
nginx@1.27.2-1~bookworm
no fix listed

Open the chart page →

5,039
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nginx@1.25.1-1~bookworm
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

14,838
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
nginx@1.22.1-9+deb12u4
no fix listed

Open the chart page →

5,482
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
nginx@1.29.0-1~bookworm
no fix listed

Open the chart page →

5,315
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,676
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
nginx@1.24.0-2ubuntu7.7
1.24.0-2ubuntu7.17

Open the chart page →

2,826
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
nginx@1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3
2:1.20.1-28.el9_8.6

Open the chart page →

2,902
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
nginx@1.25.3-1~bookworm
no fix listed

Open the chart page →

6,297
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
nginx@1.27.5-1~bookworm
no fix listed
kuzwolka/aws9:news3e8880fbbb96
nginx@1.27.5-1~bookworm
no fix listed
kuzwolka/aws9:blog4a7707410bf1
nginx@1.27.5-1~bookworm
no fix listed
kuzwolka/aws9:shop84a9d9766345
nginx@1.27.5-1~bookworm
no fix listed

Open the chart page →

18,344
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nginx@1.25.3-1~bookworm
no fix listed

Open the chart page →

6,297
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
nginx@1.27.2-1~bookworm
no fix listed

Open the chart page →

5,039
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
nginx@1.4.6-1ubuntu3.8ppa1
no fix listed

Open the chart page →

70,895
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.4.0b4e849fcf94a
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8

Open the chart page →

58,897
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8

Open the chart page →

6,632
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.28-alpinea8b39bd9cf0f
nginx@1.28.3-r1
1.28.3-r6

Open the chart page →

12,274
custom-rhcl-consolecustom-rhcl-consoleVerified publisher0.1.21 of 3See more

custom-rhcl-console custom-rhcl-console 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/custom-rhcl-console:v0.1.270bb0cabd653
nginx@1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3
2:1.20.1-28.el9_8.6

Open the chart page →

1,885
cypikcypik-app0.1.01 of 2See more

cypik cypik-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
nginx@1.25.5-1~bookworm
no fix listed

Open the chart page →

7,503
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
nginx@1.27.2-1~bookworm
no fix listed

Open the chart page →

10,090
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
nginx@1.24.0-1~focal
no fix listed

Open the chart page →

14,856
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8

Open the chart page →

7,459
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nginx@1.22.1-9
no fix listed

Open the chart page →

14,627
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nginx@1.29.1-1~bookworm
no fix listed

Open the chart page →

10,270
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nginx@1:1.20.1-13.el9
2:1.20.1-28.el9_8.6

Open the chart page →

55,666
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
nginx@1.22.1-9+deb12u3
no fix listed

Open the chart page →

4,460

Container images carrying it

119 by charts deploying them

A fixed version is listed for 6 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
nginx@1.27.0-2~bookworm
no fix listed
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
nginx@1.18.0-6ubuntu14.7
1.18.0-6ubuntu14.20
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
nginx@1.22.1-9+deb12u9
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
nginx@1.28.0-r3
1.28.3-r6
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
nginx@1.28.0-r3
1.28.3-r6
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
nginx@1.24.0-2ubuntu7.7
1.24.0-2ubuntu7.17
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
nginx@1.25.4-1~bookworm
no fix listed
1
ghcr.io/tarkyaio/tarka-ui:0.4.1b2dfabe13cfe
nginx-mainline@1.29.8-r1
1.31.3-r0
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nginx@1.22.1-9
no fix listed
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
nginx@1.25.5-0
NGINX Open Source@1.25.5-0
1.30.4
1.30.4
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nginx@1.27.2-1~bookworm
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nginx@1.25.3-1~bookworm
no fix listed
1
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
nginx@1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3
2:1.20.1-28.el9_8.6
1
quay.io/maximilianopizarro/custom-rhcl-console:v0.1.270bb0cabd653
nginx@1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3
2:1.20.1-28.el9_8.6
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
2:1.20.1-28.el9_8.6
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
2:1.20.1-28.el9_8.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.