Duplicate: GHSA-5g3q-578q-gf3m duplicates GHSA-79wq-w74x-74ch (CVE-2026-75839)
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
Research direction
Review the two linked GitHub advisory records, GHSA-79wq-w74x-74ch and GHSA-5g3q-578q-gf3m, along with their shared CVE-2026-75839 references. Determine the repository's reconciliation process, then mark or merge the unreviewed record so one record represents the CVE while preserving the applicable reporter credit.
Written by the indexing model from the issue text.
Description
Summary
GHSA-5g3q-578q-gf3m (unreviewed) and GHSA-79wq-w74x-74ch (reviewed repository advisory) describe the same vulnerability and now carry the same CVE, CVE-2026-75839. Requesting the two be reconciled so a single record represents this CVE.
The two records
| Reviewed repo advisory | Unreviewed global advisory | |
|---|---|---|
| ID | GHSA-79wq-w74x-74ch | GHSA-5g3q-578q-gf3m |
| CVE | CVE-2026-75839 | CVE-2026-75839 |
| Type | reviewed (published) | unreviewed |
| Credits | manus-use (reporter, accepted) |
(empty) |
| Repo link | ArcadeData/arcadedb | repository_advisory_url: null |
- Reviewed advisory: https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-79wq-w74x-74ch
- Unreviewed advisory: https://github.com/advisories/GHSA-5g3q-578q-gf3m
Both describe the same issue: the ArcadeDB Raft cluster-info endpoints (GetClusterHandler, PostBootstrapStateHandler) in com.arcadedb:arcadedb-server <= 26.7.3 authenticate but do not authorize, disclosing the full server database registry and per-database metadata to any authenticated user. Fixed in 26.8.1. Same affected package, same version range, same fixed version, same CWE-200.
Sequence of events
The vulnerability was reported privately to ArcadeDB and published as GHSA-79wq-w74x-74ch on 2026-08-04, crediting me as reporter. On 2026-08-18 a third-party CNA assigned CVE-2026-75839 based on that published advisory, and the resulting CVE record was ingested as the separate unreviewed advisory GHSA-5g3q-578q-gf3m (published 2026-08-18T12:31:22Z) with no credits.
GHSA-5g3q-578q-gf3m already lists GHSA-79wq-w74x-74ch in its own references, so the relationship is recorded one-directionally. I have since set cve_id on the repository advisory, so GHSA-79wq-w74x-74ch now also carries CVE-2026-75839 and the two records share a join key.
Requests
-
Reconcile the duplicate. Please mark
GHSA-5g3q-578q-gf3mas a duplicate ofGHSA-79wq-w74x-74ch, or otherwise merge them so a single record represents CVE-2026-75839. The main goal is to avoid a third record being created for the same issue when this CVE is curated. -
Reporter credit, if your conventions allow it. The reviewed repository advisory credits
manus-useas reporter; the unreviewed record has no credits. If credits can be carried over to whichever record ends up representing this CVE, I would appreciate it. I understand credits normally live on the reviewed advisory, so please treat this as a request rather than an expectation.
Happy to provide any further detail if useful. Thanks for maintaining the database.
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 18h
- Merged PRs (30d)
- 48
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
splunk/token-meter#56 ·
-
Doc: Oppdater README Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
bug status: needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 84/100