Skip to content

[GHSA-pghw-ch4m-h3f9] Add finder credit and fix reference (CVE-2026-78367) - #9647

Open
ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9647from
ByteHackr:cve-2026-78367-credit-GHSA-pghw-ch4m-h3f9
Open

ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9647from
ByteHackr:cve-2026-78367-credit-GHSA-pghw-ch4m-h3f9

Conversation

@ByteHackr

Copy link
Copy Markdown

Adds a credits entry crediting Sandipan Roy (@ByteHackr) as FINDER for this advisory, and adds the CVE record JSON as a supporting WEB reference.

Public evidence supporting this credit:

The credits structure follows the OSV schema and the convention already used in this repository (e.g. merged PR #7190 and open PR #9446).

Per CONTRIBUTING.md this PR touches exactly one advisory.

@github-actions
github-actions Bot changed the base branch from main to ByteHackr/advisory-improvement-9647 September 20, 2026 19:05
@ByteHackr

Copy link
Copy Markdown
Author

Thanks! Aside from the credit, would the curation team be able to consider this advisory for review (i.e., upgrade it from the NVD mirror entry to a reviewed advisory)? It affects a system/distro package (rpm), so I understand ecosystem version-range mapping may be limited, but happy to help with any additional information (affected versions, fixed versions, references) that makes the review possible.

@ByteHackr
ByteHackr force-pushed the cve-2026-78367-credit-GHSA-pghw-ch4m-h3f9 branch from 91ef879 to f9fc797 Compare September 20, 2026 20:13
@ByteHackr ByteHackr changed the title Add finder credit for GHSA-pghw-ch4m-h3f9 [GHSA-pghw-ch4m-h3f9] Add finder credit and fix reference (CVE-2026-78367) Sep 20, 2026
@ByteHackr

Copy link
Copy Markdown
Author

Note on affected: intentionally left empty — rpm is a C-level OS package outside the supported ecosystems. The fix (commit 2a11eb3e4e51094082e0123aebd797ec051dc094, "Prevent command injection via rpmbuild -t", 2026-09-03) landed on main after the 6.1.0 release (2026-08-20), so no fixed release exists yet; the range can be added once one ships. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant