Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_enterprise_linux_9:aspnetcore-runtime-7.0 aspnetcore-runtime-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: aspnetcore-runtime-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:aspnetcore-targeting-pack-7.0 aspnetcore-targeting-pack-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: aspnetcore-targeting-pack-7.0 | not applicable | csaf_redhat | |
| streams_for_apache_kafka_2:com.github.streamshub-console com.github.streamshub-console as a component of streams for Apache Kafka 2 | not affected vulnerable code not present | no version stated vendor label: com.github.streamshub-console | not applicable | csaf_redhat | |
| streams_for_apache_kafka_3:com.github.streamshub-console com.github.streamshub-console as a component of streams for Apache Kafka 3 | not affected vulnerable code not present | no version stated vendor label: com.github.streamshub-console | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-apphost-pack-7.0 dotnet-apphost-pack-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-apphost-pack-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-host dotnet-host as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-host | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-hostfxr-7.0 dotnet-hostfxr-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-hostfxr-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-runtime-7.0 dotnet-runtime-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-runtime-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-sdk-7.0 dotnet-sdk-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-sdk-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-sdk-7.0-source-built-artifacts dotnet-sdk-7.0-source-built-artifacts as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-sdk-7.0-source-built-artifacts | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-targeting-pack-7.0 dotnet-targeting-pack-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-targeting-pack-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet-templates-7.0 dotnet-templates-7.0 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet-templates-7.0 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:dotnet7.0.src dotnet7.0.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: dotnet7.0.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:firefox firefox as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:firefox firefox as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:firefox firefox as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:firefox firefox as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:firefox-x11 firefox-x11 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: firefox-x11 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:firefox.src firefox.src as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:firefox.src firefox.src as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:firefox.src firefox.src as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:firefox.src firefox.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:netstandard-targeting-pack-2.1 netstandard-targeting-pack-2.1 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: netstandard-targeting-pack-2.1 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-cuda-rhel9 rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3 | not affected vulnerable code not present | rhelai3/bootc-cuda-rhel9 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/disk-image-cuda-rhel9 rhelai3/disk-image-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3 | not affected vulnerable code not present | rhelai3/disk-image-cuda-rhel9 | not applicable | csaf_redhat | |
| red_hat_openshift_ai_(rhoai):rhoai/odh-dashboard-rhel9 rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI) | not affected vulnerable code not in execute path | rhoai/odh-dashboard-rhel9 | not applicable | csaf_redhat | |
| red_hat_trusted_artifact_signer:rhtas/rekor-search-ui-rhel9 rhtas/rekor-search-ui-rhel9 as a component of Red Hat Trusted Artifact Signer | not affected vulnerable code not present | rhtas/rekor-search-ui-rhel9 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:thunderbird thunderbird as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: thunderbird | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:thunderbird thunderbird as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: thunderbird | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:thunderbird thunderbird as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: thunderbird | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: thunderbird.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: thunderbird.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: thunderbird.src | not applicable | csaf_redhat | |
| https://github.com/react/react | affected | >= 7aa5dda3b3e4c2baa905a59b922ae7ec14734b24, <= ae74234eae6ebd62f19190731278e20bc1c37d51 | none available | osv | |
| https://github.com/vercel/next.js | affected | >= 51bfe3c1863b191f4b039bc230e8ed5c57b0baf3, < 3d663f2141a05adb975de4e9dae4c49780791881 | vendor fix → 3d663f2141a05adb975de4e9dae4c49780791881 | osv | |
| https://github.com/vercel/next.js | affected | >= dafcd43fac3ef9d0ffd94f9c94fd61db4449df25, < aeb69d97f8aad106f4760ff04f6d3aaa33597635 | vendor fix → aeb69d97f8aad106f4760ff04f6d3aaa33597635 | osv | |
| https://github.com/vercel/next.js | affected | >= b0416fbb44d1d148b6322ed79b6448d588260e49, < 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 | vendor fix → 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 | osv | |
| https://github.com/vercel/next.js | affected | >= b2ff04995be722a5c93225e16e1c7fcc8bb53f91, < 2f026aae46027d9575494fb3aecbd0d75fd674f0 | vendor fix → 2f026aae46027d9575494fb3aecbd0d75fd674f0 | osv | |
| https://github.com/vercel/next.js | affected | >= 7ad467409b67691ae4f5dc4dc47f1a247c4ba988, < 49668475daba15ef8cea1d8e469dc0f9a765b635 | vendor fix → 49668475daba15ef8cea1d8e469dc0f9a765b635 | osv | |
| https://github.com/vercel/next.js | affected | >= 7e08c8223d64bc2add7a0e5a323cbce0a84bb292, < 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 | vendor fix → 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 | osv | |
| https://github.com/vercel/next.js | affected | >= 950609f96f694c5475d18cd2d72a0052ca04d4b9, < 7492122a3bbc6655b64ccba04076c73ab418cdcc | vendor fix → 7492122a3bbc6655b64ccba04076c73ab418cdcc | osv | |
| https://github.com/vercel/next.js | affected | <= 950609f96f694c5475d18cd2d72a0052ca04d4b9 | none available | osv | |
| https://github.com/vercel/next.js | affected | >= 74be1f68c2ed99671d66e3e7f1337b997e74f464, <= 33759e0be7d31f8a5d59544267f7ec9b914f37e5 | none available | osv | |
| react-server-dom-parcel | affected | >= 19.0.0, < 19.0.1 | vendor fix → 19.0.1 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-parcel | affected | >= 19.1.0, < 19.1.2 | vendor fix → 19.1.2 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-parcel | affected | >= 19.2.0, < 19.2.1 | vendor fix → 19.2.1 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-turbopack | affected | >= 19.0.0, < 19.0.1 | vendor fix → 19.0.1 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-turbopack | affected | >= 19.1.0, < 19.1.2 | vendor fix → 19.1.2 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-turbopack | affected | >= 19.2.0, < 19.2.1 | vendor fix → 19.2.1 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-webpack | affected | >= 19.0.0, < 19.0.1 | vendor fix → 19.0.1 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-webpack | affected | >= 19.1.0, < 19.1.2 | vendor fix → 19.1.2 | osv GHSA-fv66-9v8q-g76r | |
| react-server-dom-webpack | affected | >= 19.2.0, < 19.2.1 | vendor fix → 19.2.1 | osv GHSA-fv66-9v8q-g76r | |
| https://github.com/vercel/next.js | fixed | 3d663f2141a05adb975de4e9dae4c49780791881 | vendor fix → 3d663f2141a05adb975de4e9dae4c49780791881 | osv | |
| https://github.com/vercel/next.js | fixed | aeb69d97f8aad106f4760ff04f6d3aaa33597635 | vendor fix → aeb69d97f8aad106f4760ff04f6d3aaa33597635 | osv | |
| https://github.com/vercel/next.js | fixed | 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 | vendor fix → 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 | osv | |
| https://github.com/vercel/next.js | fixed | 2f026aae46027d9575494fb3aecbd0d75fd674f0 | vendor fix → 2f026aae46027d9575494fb3aecbd0d75fd674f0 | osv | |
| https://github.com/vercel/next.js | fixed | 49668475daba15ef8cea1d8e469dc0f9a765b635 | vendor fix → 49668475daba15ef8cea1d8e469dc0f9a765b635 | osv | |
| https://github.com/vercel/next.js | fixed | 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 | vendor fix → 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 | osv | |
| https://github.com/vercel/next.js | fixed | 7492122a3bbc6655b64ccba04076c73ab418cdcc | vendor fix → 7492122a3bbc6655b64ccba04076c73ab418cdcc | osv | |
| react-server-dom-parcel | fixed | 19.0.1 | vendor fix → 19.0.1 | osv GHSA-fv66-9v8q-g76r |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.