{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://openvex.dev/docs/public/vex-e813432fc4f939fd56fb3d6cd0326c1f853236a4c0ab6f8fabfea00415da4d54",
  "author": "minimus",
  "timestamp": "2026-06-25T20:34:38.153471861Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3729-6w87-2929",
        "aliases": [
          "CVE-2025-60876"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.37.0-r7"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4mwp-32g3-4x3m",
        "aliases": [
          "CVE-2026-5358"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "This CVE was rejected by sourceware, for more details refer to - https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0008;h=43b38ce38a78b6458608fa4c044994b8d8516751;hb=HEAD"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-7xq4-37v3-672q",
        "aliases": [
          "CVE-2025-46394"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.37.0-r7"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-93w6-42qq-c9mm",
        "aliases": [
          "CVE-2024-10041"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/linux-pam@1.7.2-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE was fixed in version 1.6.0."
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9w5m-f95v-57hf",
        "aliases": [
          "CVE-2024-58251"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.37.0-r7"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/envoy",
          "hashes": {
            "sha-256": "sha256:3b617cb29ee5c18bde7ad5af5c6859fd606e73072ecab2e8de9aa43ce333b19a"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.43-r4"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.43-r4"
            }
          ]
        }
      ],
      "status": "fixed"
    }
  ]
}