[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-21698":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":449,"aliases":450,"duplicate_of":9,"upstream":453,"downstream":454,"duplicates":525,"related":526,"reserved_at":9,"published_at":561,"modified_at":562,"state":563,"summary":564,"references_raw":573,"kevs":757,"epss":758,"epss_history":761,"metrics":1026,"affected":1040},"CVE-2022-21698","client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.",null,[11,86],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-400","Uncontrolled Resource Consumption","The product does not properly control the allocation and maintenance of a limited resource.","weakness","Draft","Class","High",[20,24,82],{"id":21,"name":22,"techniques":23},"CAPEC-147","XML Ping of the Death",[],{"id":25,"name":26,"techniques":27},"CAPEC-227","Sustained Client Engagement",[28],{"id":29,"name":30,"tactics":31,"countermeasures":35},"T1499","Endpoint Denial of Service",[32],{"id":33,"name":34},"TA0105","Impact",[36,41,45,49,53,57,61,65,69,73,78],{"id":37,"name":38,"tactic":39},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":40},"Detect",{"id":42,"name":43,"tactic":44},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":40},{"id":46,"name":47,"tactic":48},"D3-CSPP","Client-server Payload Profiling",{"name":40},{"id":50,"name":51,"tactic":52},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":40},{"id":54,"name":55,"tactic":56},"D3-NTSA","Network Traffic Signature Analysis",{"name":40},{"id":58,"name":59,"tactic":60},"D3-APCA","Application Protocol Command Analysis",{"name":40},{"id":62,"name":63,"tactic":64},"D3-NTCD","Network Traffic Community Deviation",{"name":40},{"id":66,"name":67,"tactic":68},"D3-RTSD","Remote Terminal Session Detection",{"name":40},{"id":70,"name":71,"tactic":72},"D3-ISVA","Inbound Session Volume Analysis",{"name":40},{"id":74,"name":75,"tactic":76},"D3-NTF","Network Traffic Filtering",{"name":77},"Isolate",{"id":79,"name":80,"tactic":81},"D3-ITF","Inbound Traffic Filtering",{"name":77},{"id":83,"name":84,"techniques":85},"CAPEC-492","Regular Expression Exponential Blowup",[],{"_key":87,"id":87,"name":88,"description":89,"type":15,"status":90,"abstraction":91,"likelihood_of_exploit":18,"capec":92},"CWE-770","Allocation of Resources Without Limits or Throttling","The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.","Incomplete","Base",[93,151,161,163,167,171,175,179,211,273,277,281,311,341,373,377,381,385,389,393],{"id":94,"name":95,"techniques":96},"CAPEC-125","Flooding",[97,125],{"id":98,"name":99,"tactics":100,"countermeasures":102},"T1498.001","Direct Network Flood",[101],{"id":33,"name":34},[103,105,107,109,111,113,115,117,119,121,123],{"id":37,"name":38,"tactic":104},{"name":40},{"id":42,"name":43,"tactic":106},{"name":40},{"id":46,"name":47,"tactic":108},{"name":40},{"id":50,"name":51,"tactic":110},{"name":40},{"id":54,"name":55,"tactic":112},{"name":40},{"id":58,"name":59,"tactic":114},{"name":40},{"id":62,"name":63,"tactic":116},{"name":40},{"id":66,"name":67,"tactic":118},{"name":40},{"id":70,"name":71,"tactic":120},{"name":40},{"id":74,"name":75,"tactic":122},{"name":77},{"id":79,"name":80,"tactic":124},{"name":77},{"id":29,"name":30,"tactics":126,"countermeasures":128},[127],{"id":33,"name":34},[129,131,133,135,137,139,141,143,145,147,149],{"id":37,"name":38,"tactic":130},{"name":40},{"id":42,"name":43,"tactic":132},{"name":40},{"id":46,"name":47,"tactic":134},{"name":40},{"id":50,"name":51,"tactic":136},{"name":40},{"id":54,"name":55,"tactic":138},{"name":40},{"id":58,"name":59,"tactic":140},{"name":40},{"id":62,"name":63,"tactic":142},{"name":40},{"id":66,"name":67,"tactic":144},{"name":40},{"id":70,"name":71,"tactic":146},{"name":40},{"id":74,"name":75,"tactic":148},{"name":77},{"id":79,"name":80,"tactic":150},{"name":77},{"id":152,"name":153,"techniques":154},"CAPEC-130","Excessive Allocation",[155],{"id":156,"name":157,"tactics":158,"countermeasures":160},"T1499.003","Application Exhaustion Flood",[159],{"id":33,"name":34},[],{"id":21,"name":22,"techniques":162},[],{"id":164,"name":165,"techniques":166},"CAPEC-197","Exponential Data Expansion",[],{"id":168,"name":169,"techniques":170},"CAPEC-229","Serialized Data Parameter Blowup",[],{"id":172,"name":173,"techniques":174},"CAPEC-230","Serialized Data with Nested Payloads",[],{"id":176,"name":177,"techniques":178},"CAPEC-231","Oversized Serialized Data Payloads",[],{"id":180,"name":181,"techniques":182},"CAPEC-469","HTTP DoS",[183],{"id":184,"name":185,"tactics":186,"countermeasures":188},"T1499.002","Service Exhaustion Flood",[187],{"id":33,"name":34},[189,191,193,195,197,199,201,203,205,207,209],{"id":37,"name":38,"tactic":190},{"name":40},{"id":42,"name":43,"tactic":192},{"name":40},{"id":46,"name":47,"tactic":194},{"name":40},{"id":50,"name":51,"tactic":196},{"name":40},{"id":54,"name":55,"tactic":198},{"name":40},{"id":58,"name":59,"tactic":200},{"name":40},{"id":62,"name":63,"tactic":202},{"name":40},{"id":66,"name":67,"tactic":204},{"name":40},{"id":70,"name":71,"tactic":206},{"name":40},{"id":74,"name":75,"tactic":208},{"name":77},{"id":79,"name":80,"tactic":210},{"name":77},{"id":212,"name":213,"techniques":214},"CAPEC-482","TCP Flood",[215,241,247],{"id":98,"name":99,"tactics":216,"countermeasures":218},[217],{"id":33,"name":34},[219,221,223,225,227,229,231,233,235,237,239],{"id":37,"name":38,"tactic":220},{"name":40},{"id":42,"name":43,"tactic":222},{"name":40},{"id":46,"name":47,"tactic":224},{"name":40},{"id":50,"name":51,"tactic":226},{"name":40},{"id":54,"name":55,"tactic":228},{"name":40},{"id":58,"name":59,"tactic":230},{"name":40},{"id":62,"name":63,"tactic":232},{"name":40},{"id":66,"name":67,"tactic":234},{"name":40},{"id":70,"name":71,"tactic":236},{"name":40},{"id":74,"name":75,"tactic":238},{"name":77},{"id":79,"name":80,"tactic":240},{"name":77},{"id":242,"name":243,"tactics":244,"countermeasures":246},"T1499.001","OS Exhaustion Flood",[245],{"id":33,"name":34},[],{"id":184,"name":185,"tactics":248,"countermeasures":250},[249],{"id":33,"name":34},[251,253,255,257,259,261,263,265,267,269,271],{"id":37,"name":38,"tactic":252},{"name":40},{"id":42,"name":43,"tactic":254},{"name":40},{"id":46,"name":47,"tactic":256},{"name":40},{"id":50,"name":51,"tactic":258},{"name":40},{"id":54,"name":55,"tactic":260},{"name":40},{"id":58,"name":59,"tactic":262},{"name":40},{"id":62,"name":63,"tactic":264},{"name":40},{"id":66,"name":67,"tactic":266},{"name":40},{"id":70,"name":71,"tactic":268},{"name":40},{"id":74,"name":75,"tactic":270},{"name":77},{"id":79,"name":80,"tactic":272},{"name":77},{"id":274,"name":275,"techniques":276},"CAPEC-486","UDP Flood",[],{"id":278,"name":279,"techniques":280},"CAPEC-487","ICMP Flood",[],{"id":282,"name":283,"techniques":284},"CAPEC-488","HTTP Flood",[285],{"id":184,"name":185,"tactics":286,"countermeasures":288},[287],{"id":33,"name":34},[289,291,293,295,297,299,301,303,305,307,309],{"id":37,"name":38,"tactic":290},{"name":40},{"id":42,"name":43,"tactic":292},{"name":40},{"id":46,"name":47,"tactic":294},{"name":40},{"id":50,"name":51,"tactic":296},{"name":40},{"id":54,"name":55,"tactic":298},{"name":40},{"id":58,"name":59,"tactic":300},{"name":40},{"id":62,"name":63,"tactic":302},{"name":40},{"id":66,"name":67,"tactic":304},{"name":40},{"id":70,"name":71,"tactic":306},{"name":40},{"id":74,"name":75,"tactic":308},{"name":77},{"id":79,"name":80,"tactic":310},{"name":77},{"id":312,"name":313,"techniques":314},"CAPEC-489","SSL Flood",[315],{"id":184,"name":185,"tactics":316,"countermeasures":318},[317],{"id":33,"name":34},[319,321,323,325,327,329,331,333,335,337,339],{"id":37,"name":38,"tactic":320},{"name":40},{"id":42,"name":43,"tactic":322},{"name":40},{"id":46,"name":47,"tactic":324},{"name":40},{"id":50,"name":51,"tactic":326},{"name":40},{"id":54,"name":55,"tactic":328},{"name":40},{"id":58,"name":59,"tactic":330},{"name":40},{"id":62,"name":63,"tactic":332},{"name":40},{"id":66,"name":67,"tactic":334},{"name":40},{"id":70,"name":71,"tactic":336},{"name":40},{"id":74,"name":75,"tactic":338},{"name":77},{"id":79,"name":80,"tactic":340},{"name":77},{"id":342,"name":343,"techniques":344},"CAPEC-490","Amplification",[345],{"id":346,"name":347,"tactics":348,"countermeasures":350},"T1498.002","Reflection Amplification",[349],{"id":33,"name":34},[351,353,355,357,359,361,363,365,367,369,371],{"id":37,"name":38,"tactic":352},{"name":40},{"id":42,"name":43,"tactic":354},{"name":40},{"id":46,"name":47,"tactic":356},{"name":40},{"id":50,"name":51,"tactic":358},{"name":40},{"id":54,"name":55,"tactic":360},{"name":40},{"id":58,"name":59,"tactic":362},{"name":40},{"id":62,"name":63,"tactic":364},{"name":40},{"id":66,"name":67,"tactic":366},{"name":40},{"id":70,"name":71,"tactic":368},{"name":40},{"id":74,"name":75,"tactic":370},{"name":77},{"id":79,"name":80,"tactic":372},{"name":77},{"id":374,"name":375,"techniques":376},"CAPEC-491","Quadratic Data Expansion",[],{"id":378,"name":379,"techniques":380},"CAPEC-493","SOAP Array Blowup",[],{"id":382,"name":383,"techniques":384},"CAPEC-494","TCP Fragmentation",[],{"id":386,"name":387,"techniques":388},"CAPEC-495","UDP Fragmentation",[],{"id":390,"name":391,"techniques":392},"CAPEC-496","ICMP Fragmentation",[],{"id":394,"name":395,"techniques":396},"CAPEC-528","XML Flood",[397,423],{"id":184,"name":185,"tactics":398,"countermeasures":400},[399],{"id":33,"name":34},[401,403,405,407,409,411,413,415,417,419,421],{"id":37,"name":38,"tactic":402},{"name":40},{"id":42,"name":43,"tactic":404},{"name":40},{"id":46,"name":47,"tactic":406},{"name":40},{"id":50,"name":51,"tactic":408},{"name":40},{"id":54,"name":55,"tactic":410},{"name":40},{"id":58,"name":59,"tactic":412},{"name":40},{"id":62,"name":63,"tactic":414},{"name":40},{"id":66,"name":67,"tactic":416},{"name":40},{"id":70,"name":71,"tactic":418},{"name":40},{"id":74,"name":75,"tactic":420},{"name":77},{"id":79,"name":80,"tactic":422},{"name":77},{"id":98,"name":99,"tactics":424,"countermeasures":426},[425],{"id":33,"name":34},[427,429,431,433,435,437,439,441,443,445,447],{"id":37,"name":38,"tactic":428},{"name":40},{"id":42,"name":43,"tactic":430},{"name":40},{"id":46,"name":47,"tactic":432},{"name":40},{"id":50,"name":51,"tactic":434},{"name":40},{"id":54,"name":55,"tactic":436},{"name":40},{"id":58,"name":59,"tactic":438},{"name":40},{"id":62,"name":63,"tactic":440},{"name":40},{"id":66,"name":67,"tactic":442},{"name":40},{"id":70,"name":71,"tactic":444},{"name":40},{"id":74,"name":75,"tactic":446},{"name":77},{"id":79,"name":80,"tactic":448},{"name":77},[],[451,452],"GHSA-cg3q-j54f-5p7p","GO-2022-0322",[],[455,457,459,461,463,465,467,469,471,473,475,477,479,481,483,485,487,489,491,493,495,497,499,501,503,505,507,509,511,513,515,517,519,521,523],{"_key":456},"OPENSUSE-SU-2024:12400-1",{"_key":458},"SUSE-RU-2022:2145-1",{"_key":460},"SUSE-SU-2022:1433-1",{"_key":462},"SUSE-SU-2022:1434-1",{"_key":464},"SUSE-SU-2022:2134-1",{"_key":466},"SUSE-SU-2022:2137-1",{"_key":468},"SUSE-SU-2022:2145-1",{"_key":470},"SUSE-SU-2022:3747-1",{"_key":472},"SUSE-SU-2024:0191-1",{"_key":474},"SUSE-SU-2022:1435-1",{"_key":476},"SUSE-SU-2022:2139-1",{"_key":478},"SUSE-SU-2022:2140-1",{"_key":480},"SUSE-SU-2022:2834-1",{"_key":482},"SUSE-SU-2022:2839-1",{"_key":484},"SUSE-SU-2022:2839-2",{"_key":486},"SUSE-SU-2022:3745-1",{"_key":488},"OPENSUSE-SU-2024:11965-1",{"_key":490},"OPENSUSE-SU-2024:12259-1",{"_key":492},"MGASA-2022-0180",{"_key":494},"MGASA-2023-0213",{"_key":496},"DEBIAN-CVE-2022-21698",{"_key":498},"OPENSUSE-SU-2026:10644-1",{"_key":500},"OPENSUSE-SU-2026:10634-1",{"_key":502},"UBUNTU-CVE-2022-21698",{"_key":504},"RHSA-2022:1762",{"_key":506},"RHSA-2022:2280",{"_key":508},"RHSA-2022:4667",{"_key":510},"RHSA-2022:5068",{"_key":512},"RHSA-2024:0564",{"_key":514},"RHSA-2022:6042",{"_key":516},"RHSA-2022:6061",{"_key":518},"RHSA-2022:6066",{"_key":520},"RHSA-2022:7519",{"_key":522},"RHSA-2022:7529",{"_key":524},"RHSA-2022:8057",[],[527,528,529,530,531,532,533,534,535,536,537,539,541,542,543,544,545,546,547,548,549,550,551,552,553,555,557,559],{"_key":456},{"_key":494},{"_key":458},{"_key":460},{"_key":462},{"_key":464},{"_key":466},{"_key":468},{"_key":470},{"_key":472},{"_key":538},"CVE-2023-25151",{"_key":540},"CVE-2023-45142",{"_key":474},{"_key":476},{"_key":478},{"_key":480},{"_key":482},{"_key":484},{"_key":486},{"_key":488},{"_key":490},{"_key":492},{"_key":498},{"_key":500},{"_key":554},"CGA-59W3-CFW7-VHVV",{"_key":556},"CGA-7WHR-JH3C-X8QW",{"_key":558},"CGA-RCHR-8Q9C-5W98",{"_key":560},"CGA-8XHP-794R-624P","2022-02-15T00:00:00.000Z","2025-04-23T19:05:16.614Z","Modified",{"cisa_kev":565,"cisa_ransomware":565,"cisa_vendor":9,"epss_severity":566,"epss_score":567,"severity":568,"severity_score":569,"severity_version":570,"severity_source":571,"severity_vector":572,"severity_status":563},false,"low",0.00376,"high",7.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[574,583,589,593,598,603,607,611,615,619,623,627,631,635,639,643,647,651,655,659,663,667,671,676,680,684,688,692,696,700,704,708,712,716,720,724,728,732,736,740,744,748,752],{"url":575,"sources":576,"tags":579},"https://github.com/prometheus/client_golang/security/advisories/GHSA-cg3q-j54f-5p7p",[571,577,578],"nvd","osv_go",[580,581,582],"Issue Tracking","Third Party Advisory","WEB",{"url":584,"sources":585,"tags":586},"https://github.com/prometheus/client_golang/pull/962",[571,577,578],[587,581,582,588],"Patch","FIX",{"url":590,"sources":591,"tags":592},"https://github.com/prometheus/client_golang/pull/987",[571,577,578],[587,581,582],{"url":594,"sources":595,"tags":596},"https://github.com/prometheus/client_golang/releases/tag/v1.11.1",[571,577,578],[597,581,582],"Release Notes",{"url":599,"sources":600,"tags":601},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FY3N7H6VSDZM37B4SKM2PFFCUWU7QYWN/",[571,577],[602],"Vendor Advisory",{"url":604,"sources":605,"tags":606},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKORFJTRRDJCWBTJPISKKCVMMMJBIRLG/",[571,577],[602],{"url":608,"sources":609,"tags":610},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AK7CJBCGERCRXYUR2EWDSSDVAQMTAZGX/",[571,577],[602],{"url":612,"sources":613,"tags":614},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SASRKYHT5ZFSVMJUQUG3UAEQRJYGJKAR/",[571,577],[602],{"url":616,"sources":617,"tags":618},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KBMVIQFKQDSSTHVVJWJ4QH6TW3JVB7XZ/",[571,577],[602],{"url":620,"sources":621,"tags":622},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7V7I72LSQ3IET3QJR6QPAVGJZ4CBDLN5/",[571,577],[602],{"url":624,"sources":625,"tags":626},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/",[571,577],[602],{"url":628,"sources":629,"tags":630},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/",[571,577],[602],{"url":632,"sources":633,"tags":634},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J5WPM42UR6XIBQNQPNQHM32X7S4LJTRX/",[571,577],[602],{"url":636,"sources":637,"tags":638},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KDETHL5XCT6RZN2BBNOCEXRZ2W3SFU3/",[571,577],[602],{"url":640,"sources":641,"tags":642},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/",[571,577],[602],{"url":644,"sources":645,"tags":646},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLUJZV3HBP56ADXU6QH2V7RNYUPMVBXQ/",[571,577],[602],{"url":648,"sources":649,"tags":650},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IK53GWZ475OQ6ENABKMJMTOBZG6LXUR/",[571,577],[602],{"url":652,"sources":653,"tags":654},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MH6ALXEQXIFQRQFNJ5Y2MJ5DFPIX76VN/",[571,577],[602],{"url":656,"sources":657,"tags":658},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/",[571,577],[602],{"url":660,"sources":661,"tags":662},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RN7JGC2LVHPEGSJYODFUV5FEKPBVG4D7/",[571,577],[602],{"url":664,"sources":665,"tags":666},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5OGNAFVXSMTTT2UPH6CS3IH6L3KM42Q7/",[571,577],[602],{"url":668,"sources":669,"tags":670},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3L6GDN5S5QZSCFKWD3GKL2RDZQ6B4UWA/",[571,577],[602],{"url":672,"sources":673,"tags":674},"https://nvd.nist.gov/vuln/detail/CVE-2022-21698",[578],[675],"Advisory",{"url":677,"sources":678,"tags":679},"https://pkg.go.dev/vuln/GO-2022-0322",[578],[582],{"url":681,"sources":682,"tags":683},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR",[578],[582],{"url":685,"sources":686,"tags":687},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKORFJTRRDJCWBTJPISKKCVMMMJBIRLG",[578],[582],{"url":689,"sources":690,"tags":691},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SASRKYHT5ZFSVMJUQUG3UAEQRJYGJKAR",[578],[582],{"url":693,"sources":694,"tags":695},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RN7JGC2LVHPEGSJYODFUV5FEKPBVG4D7",[578],[582],{"url":697,"sources":698,"tags":699},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MH6ALXEQXIFQRQFNJ5Y2MJ5DFPIX76VN",[578],[582],{"url":701,"sources":702,"tags":703},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KBMVIQFKQDSSTHVVJWJ4QH6TW3JVB7XZ",[578],[582],{"url":705,"sources":706,"tags":707},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J5WPM42UR6XIBQNQPNQHM32X7S4LJTRX",[578],[582],{"url":709,"sources":710,"tags":711},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ",[578],[582],{"url":713,"sources":714,"tags":715},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FY3N7H6VSDZM37B4SKM2PFFCUWU7QYWN",[578],[582],{"url":717,"sources":718,"tags":719},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLUJZV3HBP56ADXU6QH2V7RNYUPMVBXQ",[578],[582],{"url":721,"sources":722,"tags":723},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AK7CJBCGERCRXYUR2EWDSSDVAQMTAZGX",[578],[582],{"url":725,"sources":726,"tags":727},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7V7I72LSQ3IET3QJR6QPAVGJZ4CBDLN5",[578],[582],{"url":729,"sources":730,"tags":731},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5OGNAFVXSMTTT2UPH6CS3IH6L3KM42Q7",[578],[582],{"url":733,"sources":734,"tags":735},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4KDETHL5XCT6RZN2BBNOCEXRZ2W3SFU3",[578],[582],{"url":737,"sources":738,"tags":739},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3L6GDN5S5QZSCFKWD3GKL2RDZQ6B4UWA",[578],[582],{"url":741,"sources":742,"tags":743},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH",[578],[582],{"url":745,"sources":746,"tags":747},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D",[578],[582],{"url":749,"sources":750,"tags":751},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2IK53GWZ475OQ6ENABKMJMTOBZG6LXUR",[578],[582],{"url":753,"sources":754,"tags":755},"https://github.com/prometheus/client_golang",[578],[756],"PACKAGE",[],{"date":759,"score":567,"percentile":760},"2026-06-04",0.59467,[762,766,769,772,775,778,781,784,786,789,792,795,797,800,802,806,809,812,815,818,821,824,826,829,832,835,838,841,844,847,850,853,856,859,862,865,868,871,874,877,880,883,886,889,892,896,899,902,906,909,912,915,919,922,925,928,931,934,937,940,943,946,949,952,955,958,961,963,966,968,971,974,977,980,982,984,986,989,992,995,998,1001,1004,1007,1010,1012,1015,1018,1021,1023],{"date":763,"score":764,"percentile":765},"2025-11-04",0.00279,0.50953,{"date":767,"score":764,"percentile":768},"2025-11-05",0.50934,{"date":770,"score":764,"percentile":771},"2025-11-06",0.50951,{"date":773,"score":764,"percentile":774},"2025-11-07",0.50974,{"date":776,"score":764,"percentile":777},"2025-11-08",0.50979,{"date":779,"score":764,"percentile":780},"2025-11-09",0.50967,{"date":782,"score":764,"percentile":783},"2025-11-10",0.50936,{"date":785,"score":764,"percentile":765},"2025-11-11",{"date":787,"score":764,"percentile":788},"2025-11-12",0.50977,{"date":790,"score":764,"percentile":791},"2025-11-13",0.5098,{"date":793,"score":764,"percentile":794},"2025-11-14",0.50985,{"date":796,"score":764,"percentile":777},"2025-11-15",{"date":798,"score":764,"percentile":799},"2025-11-16",0.50958,{"date":801,"score":764,"percentile":783},"2025-11-17",{"date":803,"score":804,"percentile":805},"2025-11-18",0.04255,0.87683,{"date":807,"score":804,"percentile":808},"2025-11-19",0.87688,{"date":810,"score":804,"percentile":811},"2025-11-20",0.87693,{"date":813,"score":764,"percentile":814},"2025-11-21",0.50949,{"date":816,"score":764,"percentile":817},"2025-11-22",0.50944,{"date":819,"score":764,"percentile":820},"2025-11-23",0.50905,{"date":822,"score":764,"percentile":823},"2025-11-24",0.50898,{"date":825,"score":764,"percentile":820},"2025-11-25",{"date":827,"score":764,"percentile":828},"2025-11-26",0.50906,{"date":830,"score":764,"percentile":831},"2025-11-27",0.50912,{"date":833,"score":764,"percentile":834},"2025-11-28",0.50878,{"date":836,"score":764,"percentile":837},"2025-11-29",0.50858,{"date":839,"score":764,"percentile":840},"2025-11-30",0.50847,{"date":842,"score":764,"percentile":843},"2025-12-01",0.50999,{"date":845,"score":764,"percentile":846},"2025-12-02",0.51021,{"date":848,"score":764,"percentile":849},"2025-12-03",0.51017,{"date":851,"score":764,"percentile":852},"2025-12-04",0.50861,{"date":854,"score":764,"percentile":855},"2025-12-05",0.50886,{"date":857,"score":764,"percentile":858},"2025-12-06",0.50884,{"date":860,"score":764,"percentile":861},"2025-12-07",0.50876,{"date":863,"score":764,"percentile":864},"2025-12-08",0.50879,{"date":866,"score":764,"percentile":867},"2025-12-09",0.50901,{"date":869,"score":764,"percentile":870},"2025-12-10",0.50965,{"date":872,"score":764,"percentile":873},"2025-12-11",0.50983,{"date":875,"score":764,"percentile":876},"2025-12-12",0.51015,{"date":878,"score":764,"percentile":879},"2025-12-13",0.51001,{"date":881,"score":764,"percentile":882},"2025-12-14",0.50986,{"date":884,"score":764,"percentile":885},"2025-12-15",0.5097,{"date":887,"score":764,"percentile":888},"2025-12-16",0.50981,{"date":890,"score":764,"percentile":891},"2025-12-17",0.51003,{"date":893,"score":894,"percentile":895},"2025-12-18",0.00287,0.51875,{"date":897,"score":894,"percentile":898},"2025-12-19",0.51877,{"date":900,"score":894,"percentile":901},"2025-12-20",0.5184,{"date":903,"score":904,"percentile":905},"2025-12-21",0.00244,0.47573,{"date":907,"score":904,"percentile":908},"2025-12-22",0.4755,{"date":910,"score":904,"percentile":911},"2025-12-23",0.47548,{"date":913,"score":904,"percentile":914},"2025-12-24",0.47563,{"date":916,"score":917,"percentile":918},"2025-12-25",0.00237,0.46757,{"date":920,"score":894,"percentile":921},"2025-12-26",0.51854,{"date":923,"score":894,"percentile":924},"2025-12-27",0.51881,{"date":926,"score":894,"percentile":927},"2025-12-28",0.51804,{"date":929,"score":894,"percentile":930},"2025-12-29",0.51782,{"date":932,"score":894,"percentile":933},"2025-12-30",0.51777,{"date":935,"score":894,"percentile":936},"2025-12-31",0.51815,{"date":938,"score":894,"percentile":939},"2026-01-01",0.51982,{"date":941,"score":894,"percentile":942},"2026-01-02",0.51959,{"date":944,"score":894,"percentile":945},"2026-01-03",0.51954,{"date":947,"score":894,"percentile":948},"2026-01-04",0.51784,{"date":950,"score":894,"percentile":951},"2026-01-05",0.51768,{"date":953,"score":894,"percentile":954},"2026-01-06",0.51775,{"date":956,"score":894,"percentile":957},"2026-01-07",0.51796,{"date":959,"score":764,"percentile":960},"2026-01-08",0.50968,{"date":962,"score":764,"percentile":765},"2026-01-09",{"date":964,"score":764,"percentile":965},"2026-01-10",0.50952,{"date":967,"score":764,"percentile":768},"2026-01-11",{"date":969,"score":764,"percentile":970},"2026-01-12",0.5089,{"date":972,"score":764,"percentile":973},"2026-01-13",0.50864,{"date":975,"score":764,"percentile":976},"2026-01-14",0.50914,{"date":978,"score":764,"percentile":979},"2026-01-15",0.50917,{"date":981,"score":764,"percentile":768},"2026-01-16",{"date":983,"score":764,"percentile":831},"2026-01-17",{"date":985,"score":764,"percentile":970},"2026-01-18",{"date":987,"score":764,"percentile":988},"2026-01-19",0.50866,{"date":990,"score":764,"percentile":991},"2026-01-20",0.50865,{"date":993,"score":764,"percentile":994},"2026-01-21",0.50867,{"date":996,"score":764,"percentile":997},"2026-01-22",0.50874,{"date":999,"score":764,"percentile":1000},"2026-01-23",0.50923,{"date":1002,"score":764,"percentile":1003},"2026-01-24",0.5093,{"date":1005,"score":764,"percentile":1006},"2026-01-25",0.50883,{"date":1008,"score":764,"percentile":1009},"2026-01-26",0.50859,{"date":1011,"score":764,"percentile":973},"2026-01-27",{"date":1013,"score":764,"percentile":1014},"2026-01-28",0.50875,{"date":1016,"score":764,"percentile":1017},"2026-01-29",0.50873,{"date":1019,"score":764,"percentile":1020},"2026-01-30",0.50877,{"date":1022,"score":764,"percentile":858},"2026-01-31",{"date":1024,"score":764,"percentile":1025},"2026-02-01",0.51019,[1027,1032,1038],{"source":571,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":1028,"cvss_v4_0":9},{"baseScore":569,"baseSeverity":1029,"vectorString":572,"impactScore":1030,"exploitabilityScore":1031},"HIGH",6,10,{"source":577,"cvss_v2_0":1033,"cvss_v3_0":9,"cvss_v3_1":1037,"cvss_v4_0":9},{"baseScore":1034,"baseSeverity":9,"vectorString":1035,"impactScore":1036,"exploitabilityScore":1031},5,"AV:N/AC:L/Au:N/C:N/I:N/A:P",2.9,{"baseScore":569,"baseSeverity":1029,"vectorString":572,"impactScore":1030,"exploitabilityScore":1031},{"source":578,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":1039,"cvss_v4_0":9},{"baseScore":569,"baseSeverity":9,"vectorString":572,"impactScore":1030,"exploitabilityScore":1031},[1041,1052,1064,1077,1083],{"ecosystem":9,"name":1042,"vendor":1043,"product":1044,"cpe_part":1045,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1046},"extra packages for enterprise linux","fedoraproject","extra_packages_for_enterprise_linux","a",[1047,1050],{"version":1048,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0","cpe",{"version":1051,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0",{"ecosystem":9,"name":1053,"vendor":1043,"product":1053,"cpe_part":1054,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1055},"fedora","o",[1056,1058,1060,1062],{"version":1057,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"34",{"version":1059,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"35",{"version":1061,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"36",{"version":1063,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"37",{"ecosystem":1065,"name":1066,"vendor":1067,"product":1068,"cpe_part":9,"purl_type":1069,"purl_namespace":1067,"purl_name":1068,"source":9,"versions":1070},"Go","github.com/prometheus/client_golang","github.com/prometheus","client_golang","golang",[1071],{"version":1072,"is_range":1073,"range_type":1074,"version_start":9,"version_start_type":9,"version_end":1075,"version_end_type":1076,"fixed_in":9},"lt1_11_1",true,"semver","1.11.1","excluding",{"ecosystem":9,"name":1078,"vendor":1079,"product":1068,"cpe_part":1045,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1080},"client golang","prometheus",[1081],{"version":1082,"is_range":1073,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":1075,"version_end_type":1076,"fixed_in":9},"lt1.11.1",{"ecosystem":9,"name":1084,"vendor":1085,"product":1084,"cpe_part":1045,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":1086},"rdo","rdo_project",[1087],{"version":1088,"is_range":565,"range_type":1049,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"na"]