{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://openvex.dev/docs/public/vex-726b897eb387a650299537852ef21d0fbb5286f9b0289749091a583a93ce489e",
  "author": "minimus",
  "timestamp": "2026-06-25T06:22:54.395424038Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-2pch-g7qr-4hgj",
        "aliases": [
          "CVE-2020-8912"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-2q54-wf2r-8xr5",
        "aliases": [
          "CVE-2026-41889"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-34x9-ffvp-r3fc",
        "aliases": [
          "CVE-2026-33816"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "affected",
      "action_statement": "For more context and potential remediation information, review the References tab: https://images.minimus.io/advisories/CVE-2026-33816/references"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4gcx-4vqw-xwpx",
        "aliases": [
          "CVE-2026-41602"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "affected",
      "action_statement": "For more context and potential remediation information, review the References tab: https://images.minimus.io/advisories/CVE-2026-41602/references"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4mwp-32g3-4x3m",
        "aliases": [
          "CVE-2026-5358"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "This CVE was rejected by sourceware, for more details refer to - https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0008;h=43b38ce38a78b6458608fa4c044994b8d8516751;hb=HEAD"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-5c65-23cv-57c5",
        "aliases": [
          "CVE-2026-2303"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-6433-7r4f-rvg4",
        "aliases": [
          "CVE-2020-8911"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-gx66-w6jh-f4x5",
        "aliases": [
          "CVE-2026-33815"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "affected",
      "action_statement": "For more context and potential remediation information, review the References tab: https://images.minimus.io/advisories/CVE-2026-33815/references"
    },
    {
      "vulnerability": {
        "name": "MINI-j8c5-x5rp-jfvv",
        "aliases": [
          "CVE-2025-69725"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-jr7f-pw98-vm92",
        "aliases": [
          "GHSA-xmrv-pmrh-hhx2"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.16@1.16.16-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.16@1.16.16-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:db6d4a23e6e27475a236b86be5ba946dbcc0c5534eb34156c3034b59918d6edb"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    }
  ]
}