[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2021-41190":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":72,"related":73,"reserved_at":9,"published_at":99,"modified_at":100,"state":101,"summary":102,"references_raw":111,"kevs":209,"epss":210,"epss_history":213,"metrics":475,"affected":494},"CVE-2021-41190","The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both “manifests” and “layers” fields or “manifests” and “config” fields if they are unable to update to version 1.0.1 of the spec.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-843","Access of Resource Using Incompatible Type ('Type Confusion')","The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.","weakness","Incomplete","Base",[],[],[21],"GHSA-mc8v-mgrf-8f4m",[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70],{"_key":25},"UBUNTU-CVE-2021-41190",{"_key":27},"SUSE-SU-2025:02282-1",{"_key":29},"OPENSUSE-SU-2024:11647-1",{"_key":31},"SUSE-SU-2022:0213-1",{"_key":33},"SUSE-SU-2022:0334-1",{"_key":35},"SUSE-SU-2022:1507-1",{"_key":37},"SUSE-SU-2022:23018-1",{"_key":39},"SUSE-SU-2025:03540-1",{"_key":41},"SUSE-SU-2023:0187-1",{"_key":43},"SUSE-SU-2023:0326-1",{"_key":45},"OPENSUSE-SU-2021:1525-1",{"_key":47},"OPENSUSE-SU-2022:0334-1",{"_key":49},"OPENSUSE-SU-2022:23018-1",{"_key":51},"OPENSUSE-SU-2024:11646-1",{"_key":53},"OPENSUSE-SU-2024:11659-1",{"_key":55},"OPENSUSE-SU-2024:11674-1",{"_key":57},"SUSE-SU-2025:03545-1",{"_key":59},"OPENSUSE-SU-2025:15166-1",{"_key":61},"OPENSUSE-SU-2025:15589-1",{"_key":63},"MGASA-2021-0531",{"_key":65},"MGASA-2022-0006",{"_key":67},"MGASA-2023-0213",{"_key":69},"RHSA-2022:0055",{"_key":71},"RHSA-2022:7457",[],[74,76,77,78,79,80,81,82,83,84,86,87,88,89,90,91,92,93,94,95,96,97,98],{"_key":75},"GO-2024-2914",{"_key":27},{"_key":29},{"_key":67},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":85},"GHSA-XMMX-7JPF-FX42",{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},"2021-11-17T19:20:11.000Z","2024-08-04T03:08:31.262Z","Modified",{"cisa_kev":103,"cisa_ransomware":103,"cisa_vendor":9,"epss_severity":104,"epss_score":105,"severity":106,"severity_score":107,"severity_version":108,"severity_source":109,"severity_vector":110,"severity_status":101},false,"low",0.00383,"medium",5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",[112,121,127,133,139,143,147,151,155,159,163,167,172,177,181,185,189,193,197,201,205],{"url":113,"sources":114,"tags":117},"https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m",[115,109,116],"cve.org","osv_go",[118,119,120],"X Refsource CONFIRM","Third Party Advisory","WEB",{"url":122,"sources":123,"tags":124},"https://github.com/opencontainers/distribution-spec/commit/ac28cac0557bcd3084714ab09f9f2356fe504923",[115,109,116],[125,126,119,120],"X Refsource MISC","Patch",{"url":128,"sources":129,"tags":130},"http://www.openwall.com/lists/oss-security/2021/11/19/10",[115,109,116],[131,132,119,120],"Mailing List","X Refsource MLIST",{"url":134,"sources":135,"tags":136},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A2RRFNTMFYKOTRKD37F5ANMCIO3GGJML/",[115,109],[137,138],"Vendor Advisory","X Refsource FEDORA",{"url":140,"sources":141,"tags":142},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DX63GRWFEI5RVMYV6XLMCG4OHPWZML27/",[115,109],[137,138],{"url":144,"sources":145,"tags":146},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQBCYJUIM5GVCMFUPRWKRZNXMMI5EFA4/",[115,109],[137,138],{"url":148,"sources":149,"tags":150},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4OJ764CKKCWCVONHD4YXTGR7HZ7LRUV/",[115,109],[137,138],{"url":152,"sources":153,"tags":154},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3TUZNDAH2B26VPBK342UC3BHZNLBUXGX/",[115,109],[137,138],{"url":156,"sources":157,"tags":158},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RZTO6N55WHKHIZI4IMLY2QFBPMVTAERM/",[115,109],[137,138],{"url":160,"sources":161,"tags":162},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4334HT7AZPLWNYHW4ARU6JBUF3VZJPZN/",[115,109],[137,138],{"url":164,"sources":165,"tags":166},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YIGVQWOA5XXCQXEOOKZX4CDAGLBDRPRX/",[115,109],[137,138],{"url":168,"sources":169,"tags":170},"https://nvd.nist.gov/vuln/detail/CVE-2021-41190",[116],[171],"Advisory",{"url":173,"sources":174,"tags":175},"https://github.com/opencontainers/distribution-spec",[116],[176],"PACKAGE",{"url":178,"sources":179,"tags":180},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TUZNDAH2B26VPBK342UC3BHZNLBUXGX",[116],[120],{"url":182,"sources":183,"tags":184},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4334HT7AZPLWNYHW4ARU6JBUF3VZJPZN",[116],[120],{"url":186,"sources":187,"tags":188},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A2RRFNTMFYKOTRKD37F5ANMCIO3GGJML",[116],[120],{"url":190,"sources":191,"tags":192},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DX63GRWFEI5RVMYV6XLMCG4OHPWZML27",[116],[120],{"url":194,"sources":195,"tags":196},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RZTO6N55WHKHIZI4IMLY2QFBPMVTAERM",[116],[120],{"url":198,"sources":199,"tags":200},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SQBCYJUIM5GVCMFUPRWKRZNXMMI5EFA4",[116],[120],{"url":202,"sources":203,"tags":204},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4OJ764CKKCWCVONHD4YXTGR7HZ7LRUV",[116],[120],{"url":206,"sources":207,"tags":208},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YIGVQWOA5XXCQXEOOKZX4CDAGLBDRPRX",[116],[120],[],{"date":211,"score":105,"percentile":212},"2026-06-04",0.59954,[214,218,221,224,227,230,233,236,239,242,245,248,251,254,257,261,264,267,270,272,275,278,281,284,287,290,293,296,299,302,305,307,309,312,316,319,322,325,328,331,334,337,340,342,345,348,351,354,357,360,363,366,369,372,375,378,381,384,387,390,393,396,399,402,405,407,409,411,414,417,420,423,426,428,430,433,436,439,442,444,447,450,453,455,458,461,464,467,470,472],{"date":215,"score":216,"percentile":217},"2025-11-04",0.00287,0.51799,{"date":219,"score":216,"percentile":220},"2025-11-05",0.51778,{"date":222,"score":216,"percentile":223},"2025-11-06",0.51795,{"date":225,"score":216,"percentile":226},"2025-11-07",0.51819,{"date":228,"score":216,"percentile":229},"2025-11-08",0.51823,{"date":231,"score":216,"percentile":232},"2025-11-09",0.51817,{"date":234,"score":216,"percentile":235},"2025-11-10",0.5179,{"date":237,"score":216,"percentile":238},"2025-11-11",0.51804,{"date":240,"score":216,"percentile":241},"2025-11-12",0.5183,{"date":243,"score":216,"percentile":244},"2025-11-13",0.51833,{"date":246,"score":216,"percentile":247},"2025-11-14",0.51837,{"date":249,"score":216,"percentile":250},"2025-11-15",0.51831,{"date":252,"score":216,"percentile":253},"2025-11-16",0.51809,{"date":255,"score":216,"percentile":256},"2025-11-17",0.51792,{"date":258,"score":259,"percentile":260},"2025-11-18",0.00398,0.57845,{"date":262,"score":259,"percentile":263},"2025-11-19",0.57861,{"date":265,"score":259,"percentile":266},"2025-11-20",0.57852,{"date":268,"score":216,"percentile":269},"2025-11-21",0.518,{"date":271,"score":216,"percentile":223},"2025-11-22",{"date":273,"score":216,"percentile":274},"2025-11-23",0.51755,{"date":276,"score":216,"percentile":277},"2025-11-24",0.51747,{"date":279,"score":216,"percentile":280},"2025-11-25",0.51752,{"date":282,"score":216,"percentile":283},"2025-11-26",0.51753,{"date":285,"score":216,"percentile":286},"2025-11-27",0.5176,{"date":288,"score":216,"percentile":289},"2025-11-28",0.51721,{"date":291,"score":216,"percentile":292},"2025-11-29",0.51697,{"date":294,"score":216,"percentile":295},"2025-11-30",0.51684,{"date":297,"score":216,"percentile":298},"2025-12-01",0.51832,{"date":300,"score":216,"percentile":301},"2025-12-02",0.51854,{"date":303,"score":216,"percentile":304},"2025-12-03",0.51852,{"date":306,"score":216,"percentile":292},"2025-12-04",{"date":308,"score":216,"percentile":289},"2025-12-05",{"date":310,"score":216,"percentile":311},"2025-12-06",0.51719,{"date":313,"score":314,"percentile":315},"2025-12-07",0.00303,0.53055,{"date":317,"score":314,"percentile":318},"2025-12-08",0.53054,{"date":320,"score":314,"percentile":321},"2025-12-09",0.5307,{"date":323,"score":314,"percentile":324},"2025-12-10",0.53129,{"date":326,"score":314,"percentile":327},"2025-12-11",0.5315,{"date":329,"score":314,"percentile":330},"2025-12-12",0.53176,{"date":332,"score":314,"percentile":333},"2025-12-13",0.53171,{"date":335,"score":314,"percentile":336},"2025-12-14",0.5316,{"date":338,"score":314,"percentile":339},"2025-12-15",0.53149,{"date":341,"score":314,"percentile":336},"2025-12-16",{"date":343,"score":314,"percentile":344},"2025-12-17",0.53182,{"date":346,"score":314,"percentile":347},"2025-12-18",0.53219,{"date":349,"score":314,"percentile":350},"2025-12-19",0.53221,{"date":352,"score":314,"percentile":353},"2025-12-20",0.53208,{"date":355,"score":314,"percentile":356},"2025-12-21",0.53187,{"date":358,"score":314,"percentile":359},"2025-12-22",0.53165,{"date":361,"score":314,"percentile":362},"2025-12-23",0.53168,{"date":364,"score":314,"percentile":365},"2025-12-24",0.53179,{"date":367,"score":314,"percentile":368},"2025-12-25",0.53225,{"date":370,"score":314,"percentile":371},"2025-12-26",0.5322,{"date":373,"score":314,"percentile":374},"2025-12-27",0.53269,{"date":376,"score":314,"percentile":377},"2025-12-28",0.53196,{"date":379,"score":314,"percentile":380},"2025-12-29",0.5318,{"date":382,"score":314,"percentile":383},"2025-12-30",0.53172,{"date":385,"score":314,"percentile":386},"2025-12-31",0.53189,{"date":388,"score":314,"percentile":389},"2026-01-01",0.53357,{"date":391,"score":314,"percentile":392},"2026-01-02",0.53334,{"date":394,"score":314,"percentile":395},"2026-01-03",0.53327,{"date":397,"score":314,"percentile":398},"2026-01-04",0.53161,{"date":400,"score":314,"percentile":401},"2026-01-05",0.53147,{"date":403,"score":314,"percentile":404},"2026-01-06",0.53152,{"date":406,"score":314,"percentile":330},"2026-01-07",{"date":408,"score":314,"percentile":377},"2026-01-08",{"date":410,"score":314,"percentile":386},"2026-01-09",{"date":412,"score":314,"percentile":413},"2026-01-10",0.53188,{"date":415,"score":314,"percentile":416},"2026-01-11",0.53169,{"date":418,"score":314,"percentile":419},"2026-01-12",0.53123,{"date":421,"score":314,"percentile":422},"2026-01-13",0.53099,{"date":424,"score":314,"percentile":425},"2026-01-14",0.53143,{"date":427,"score":314,"percentile":401},"2026-01-15",{"date":429,"score":314,"percentile":362},"2026-01-16",{"date":431,"score":314,"percentile":432},"2026-01-17",0.53154,{"date":434,"score":314,"percentile":435},"2026-01-18",0.53142,{"date":437,"score":314,"percentile":438},"2026-01-19",0.53135,{"date":440,"score":314,"percentile":441},"2026-01-20",0.53134,{"date":443,"score":314,"percentile":435},"2026-01-21",{"date":445,"score":314,"percentile":446},"2026-01-22",0.53148,{"date":448,"score":314,"percentile":449},"2026-01-23",0.5319,{"date":451,"score":314,"percentile":452},"2026-01-24",0.53192,{"date":454,"score":314,"percentile":446},"2026-01-25",{"date":456,"score":314,"percentile":457},"2026-01-26",0.5313,{"date":459,"score":314,"percentile":460},"2026-01-27",0.5314,{"date":462,"score":314,"percentile":463},"2026-01-28",0.53157,{"date":465,"score":314,"percentile":466},"2026-01-29",0.53151,{"date":468,"score":314,"percentile":469},"2026-01-30",0.53153,{"date":471,"score":314,"percentile":336},"2026-01-31",{"date":473,"score":314,"percentile":474},"2026-02-01",0.53299,[476,483,492],{"source":115,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":477,"cvss_v4_0":9},{"baseScore":478,"baseSeverity":479,"vectorString":480,"impactScore":481,"exploitabilityScore":482},3,"LOW","CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N",2.3,3.3,{"source":109,"cvss_v2_0":484,"cvss_v3_0":9,"cvss_v3_1":489,"cvss_v4_0":9},{"baseScore":485,"baseSeverity":9,"vectorString":486,"impactScore":487,"exploitabilityScore":488},4,"AV:N/AC:L/Au:S/C:N/I:P/A:N",2.9,8,{"baseScore":107,"baseSeverity":490,"vectorString":110,"impactScore":481,"exploitabilityScore":491},"MEDIUM",7.9,{"source":116,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":493,"cvss_v4_0":9},{"baseScore":478,"baseSeverity":9,"vectorString":480,"impactScore":481,"exploitabilityScore":482},[495,505,518,528,534],{"ecosystem":9,"name":496,"vendor":497,"product":496,"cpe_part":498,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":499},"fedora","fedoraproject","o",[500,503],{"version":501,"is_range":103,"range_type":502,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"34","cpe",{"version":504,"is_range":103,"range_type":502,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"35",{"ecosystem":506,"name":507,"vendor":508,"product":509,"cpe_part":9,"purl_type":510,"purl_namespace":508,"purl_name":509,"source":9,"versions":511},"Go","github.com/opencontainers/distribution-spec","github.com/opencontainers","distribution-spec","golang",[512],{"version":513,"is_range":514,"range_type":515,"version_start":9,"version_start_type":9,"version_end":516,"version_end_type":517,"fixed_in":9},"lt1_0_1",true,"semver","1.0.1","excluding",{"ecosystem":9,"name":519,"vendor":520,"product":521,"cpe_part":522,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":523},"open container initiative distribution specification","linuxfoundation","open_container_initiative_distribution_specification","a",[524],{"version":525,"is_range":514,"range_type":502,"version_start":9,"version_start_type":9,"version_end":526,"version_end_type":527,"fixed_in":9},"lte1.0.0","1.0.0","including",{"ecosystem":9,"name":529,"vendor":520,"product":530,"cpe_part":522,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":531},"open container initiative image format specification","open_container_initiative_image_format_specification",[532],{"version":533,"is_range":514,"range_type":502,"version_start":9,"version_start_type":9,"version_end":516,"version_end_type":527,"fixed_in":9},"lte1.0.1",{"ecosystem":9,"name":509,"vendor":535,"product":509,"cpe_part":522,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":536},"opencontainers",[537],{"version":538,"is_range":514,"range_type":115,"version_start":9,"version_start_type":9,"version_end":516,"version_end_type":517,"fixed_in":9},"\u003C 1.0.1"]