{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://openvex.dev/docs/public/vex-860edb5c7d2c5b14cd896ede924584d309a0b814239dad659dda778916d7cbba",
  "author": "minimus",
  "timestamp": "2026-06-25T06:19:26.896081917Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-2vq6-p4cq-6h9q",
        "aliases": [
          "CVE-2026-2303"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.18@1.18.1-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.18@1.18.1-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4mwp-32g3-4x3m",
        "aliases": [
          "CVE-2026-5358"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "This CVE was rejected by sourceware, for more details refer to - https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0008;h=43b38ce38a78b6458608fa4c044994b8d8516751;hb=HEAD"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-fhcp-53pw-rw73",
        "aliases": [
          "CVE-2025-69725"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.18@1.18.1-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.18@1.18.1-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-mr33-p69r-g3gq",
        "aliases": [
          "CVE-2026-26958"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.18@1.18.1-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.18@1.18.1-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-qq9v-x46q-h6mw",
        "aliases": [
          "GHSA-xmrv-pmrh-hhx2"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/dapr-daprd-1.18@1.18.1-r0"
            },
            {
              "@id": "pkg:apk/minimos/dapr-daprd-compat-1.18@1.18.1-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/dapr-daprd",
          "hashes": {
            "sha-256": "sha256:3a1d324d436934026adca1ca16b1e99109f1afae501970f2f0e8bbabd1664f91"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    }
  ]
}