Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Duplicate: GHSA-5g3q-578q-gf3m duplicates GHSA-79wq-w74x-74ch (CVE-2026-75839)

Abierto
#9,174 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
25/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
github

Línea de trabajo

Revisa los dos registros de avisos de GitHub vinculados, GHSA-79wq-w74x-74ch y GHSA-5g3q-578q-gf3m, junto con sus referencias compartidas a CVE-2026-75839. Determina el proceso de conciliación del repositorio y, a continuación, marca o fusiona el registro no revisado para que un registro represente la CVE, conservando el reconocimiento correspondiente al informante.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Summary

GHSA-5g3q-578q-gf3m (unreviewed) and GHSA-79wq-w74x-74ch (reviewed repository advisory) describe the same vulnerability and now carry the same CVE, CVE-2026-75839. Requesting the two be reconciled so a single record represents this CVE.

The two records
Reviewed repo advisory Unreviewed global advisory
ID GHSA-79wq-w74x-74ch GHSA-5g3q-578q-gf3m
CVE CVE-2026-75839 CVE-2026-75839
Type reviewed (published) unreviewed
Credits manus-use (reporter, accepted) (empty)
Repo link ArcadeData/arcadedb repository_advisory_url: null

Both describe the same issue: the ArcadeDB Raft cluster-info endpoints (GetClusterHandler, PostBootstrapStateHandler) in com.arcadedb:arcadedb-server <= 26.7.3 authenticate but do not authorize, disclosing the full server database registry and per-database metadata to any authenticated user. Fixed in 26.8.1. Same affected package, same version range, same fixed version, same CWE-200.

Sequence of events

The vulnerability was reported privately to ArcadeDB and published as GHSA-79wq-w74x-74ch on 2026-08-04, crediting me as reporter. On 2026-08-18 a third-party CNA assigned CVE-2026-75839 based on that published advisory, and the resulting CVE record was ingested as the separate unreviewed advisory GHSA-5g3q-578q-gf3m (published 2026-08-18T12:31:22Z) with no credits.

GHSA-5g3q-578q-gf3m already lists GHSA-79wq-w74x-74ch in its own references, so the relationship is recorded one-directionally. I have since set cve_id on the repository advisory, so GHSA-79wq-w74x-74ch now also carries CVE-2026-75839 and the two records share a join key.

Requests
  1. Reconcile the duplicate. Please mark GHSA-5g3q-578q-gf3m as a duplicate of GHSA-79wq-w74x-74ch, or otherwise merge them so a single record represents CVE-2026-75839. The main goal is to avoid a third record being created for the same issue when this CVE is curated.

  2. Reporter credit, if your conventions allow it. The reviewed repository advisory credits manus-use as reporter; the unreviewed record has no credits. If credits can be carried over to whichever record ends up representing this CVE, I would appreciate it. I understand credits normally live on the reviewed advisory, so please treat this as a request rather than an expectation.

Happy to provide any further detail if useful. Thanks for maintaining the database.

Lenguaje dominante
Sin datos de lenguaje
Estrellas
2.5k
Forks
772
Merge medio
3 d 15 h
PR fusionados (30 d)
46

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/advisory-database

Todos los issues de github/advisory-database

Issues similares

Más issues de Databases

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.