Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Duplicate: GHSA-5g3q-578q-gf3m duplicates GHSA-79wq-w74x-74ch (CVE-2026-75839)

オープン
#9,174 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
25/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
github
領域
database, security

調査の方向性

リンクされている2つの GitHub アドバイザリーレコード、GHSA-79wq-w74x-74ch と GHSA-5g3q-578q-gf3m、およびそれらに共通する CVE-2026-75839 への参照を確認します。リポジトリの照合プロセスを特定し、未レビューのレコードをマークするかマージして、1つのレコードが CVE を表すようにしつつ、該当する報告者クレジットを保持します。

索引モデルが issue の本文から書いたものです。

説明

Summary

GHSA-5g3q-578q-gf3m (unreviewed) and GHSA-79wq-w74x-74ch (reviewed repository advisory) describe the same vulnerability and now carry the same CVE, CVE-2026-75839. Requesting the two be reconciled so a single record represents this CVE.

The two records
Reviewed repo advisory Unreviewed global advisory
ID GHSA-79wq-w74x-74ch GHSA-5g3q-578q-gf3m
CVE CVE-2026-75839 CVE-2026-75839
Type reviewed (published) unreviewed
Credits manus-use (reporter, accepted) (empty)
Repo link ArcadeData/arcadedb repository_advisory_url: null

Both describe the same issue: the ArcadeDB Raft cluster-info endpoints (GetClusterHandler, PostBootstrapStateHandler) in com.arcadedb:arcadedb-server <= 26.7.3 authenticate but do not authorize, disclosing the full server database registry and per-database metadata to any authenticated user. Fixed in 26.8.1. Same affected package, same version range, same fixed version, same CWE-200.

Sequence of events

The vulnerability was reported privately to ArcadeDB and published as GHSA-79wq-w74x-74ch on 2026-08-04, crediting me as reporter. On 2026-08-18 a third-party CNA assigned CVE-2026-75839 based on that published advisory, and the resulting CVE record was ingested as the separate unreviewed advisory GHSA-5g3q-578q-gf3m (published 2026-08-18T12:31:22Z) with no credits.

GHSA-5g3q-578q-gf3m already lists GHSA-79wq-w74x-74ch in its own references, so the relationship is recorded one-directionally. I have since set cve_id on the repository advisory, so GHSA-79wq-w74x-74ch now also carries CVE-2026-75839 and the two records share a join key.

Requests
  1. Reconcile the duplicate. Please mark GHSA-5g3q-578q-gf3m as a duplicate of GHSA-79wq-w74x-74ch, or otherwise merge them so a single record represents CVE-2026-75839. The main goal is to avoid a third record being created for the same issue when this CVE is curated.

  2. Reporter credit, if your conventions allow it. The reviewed repository advisory credits manus-use as reporter; the unreviewed record has no credits. If credits can be carried over to whichever record ends up representing this CVE, I would appreciate it. I understand credits normally live on the reviewed advisory, so please treat this as a request rather than an expectation.

Happy to provide any further detail if useful. Thanks for maintaining the database.

主要言語
言語のデータがありません
スター
2.5k
フォーク
772
平均マージ
3日 15時間
マージ済み PR(30日)
46

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/advisory-database のほかの issue

github/advisory-database の issue をすべて見る

似ている issue

Databases の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。