CVE-2026-22028 Significant scoring difference between GHSA<>NVD
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- github
- Domain
- security
Research direction
Start by comparing the CVSS vectors and descriptions in the NVD CVE-2026-22028 reference and the GHSA-36hm-qxxp-pg3m advisory. Review the stated UI interaction and impact assumptions; done means providing a documented explanation of the scoring difference or identifying the advisory data that requires correction.
Written by the indexing model from the issue text.
Description
Hello,
I am a vulnerability data analyst, and I have observed a significant difference in the CVSS scores of GHSA-36hm-qxxp-pg3m/CVE-2026-22028.
Score by NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Score by GHSA: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
According to the description, component is vulnerable based on the following conditions:
1. Pass unmodified, unsanitized values from user-modifiable data sources (APIs, databases, local storage, etc.) directly into the render tree >> indicates a user action (implies UI:R)
The additional notes in the description imply that the affected scope is quite limited, which could reduce the general impact of the vulnerability - (makes more sense in the IMPACT metrics)
Since scoring could rely on different assessment approaches, this raises various questions and confusion among development teams - could you please provide a reasonable explanation on your end for this score assignment?
References
https://nvd.nist.gov/vuln/detail/CVE-2026-22028
https://github.com/advisories/GHSA-36hm-qxxp-pg3m
Thanks in advance!
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 15h
- Merged PRs (30d)
- 46
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Nmap
Difficulty 1/5 Under an hour Newbie friendliness 85/100
-
Mend: dependency security vulnerability untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
blocklist removal
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
MetaMask/eth-phishing-detect#296544 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Azure/azure-functions-docker#1257 ·