{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://openvex.dev/docs/public/vex-117fd2dbe56c3567204c3b3671c8a1915ae9f7762d11395ab7a05105588604e1",
  "author": "minimus",
  "timestamp": "2026-06-25T12:23:07.179647977Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3729-6w87-2929",
        "aliases": [
          "CVE-2025-60876"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.37.0-r7"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4mwp-32g3-4x3m",
        "aliases": [
          "CVE-2026-5358"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "This CVE was rejected by sourceware, for more details refer to - https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0008;h=43b38ce38a78b6458608fa4c044994b8d8516751;hb=HEAD"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-7xq4-37v3-672q",
        "aliases": [
          "CVE-2025-46394"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.37.0-r7"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9w5m-f95v-57hf",
        "aliases": [
          "CVE-2024-58251"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.37.0-r7"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "affected",
      "action_statement": "For more context and potential remediation information, review the References tab: https://images.minimus.io/advisories/CVE-2026-5450/references"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/bun",
          "hashes": {
            "sha-256": "sha256:4a1f5edaeb07410f1acb6d7d894bab4406c56f8b754ad514dee2b092a9e18ab3"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r3"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r3"
            }
          ]
        }
      ],
      "status": "fixed"
    }
  ]
}