CyberzSOC

Applicability
← Back to CVE-2025-55182

CVE-2025-55182

In CISA KEV Meta

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2026-08-04
33 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-08-27
19 affected 16 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2026-08-04
9 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (77)

Product Status Versions Remediation Source
red_hat_enterprise_linux_9:aspnetcore-runtime-7.0 aspnetcore-runtime-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: aspnetcore-runtime-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:aspnetcore-targeting-pack-7.0 aspnetcore-targeting-pack-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: aspnetcore-targeting-pack-7.0 not applicable csaf_redhat
streams_for_apache_kafka_2:com.github.streamshub-console com.github.streamshub-console as a component of streams for Apache Kafka 2 not affected vulnerable code not present no version stated vendor label: com.github.streamshub-console not applicable csaf_redhat
streams_for_apache_kafka_3:com.github.streamshub-console com.github.streamshub-console as a component of streams for Apache Kafka 3 not affected vulnerable code not present no version stated vendor label: com.github.streamshub-console not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-apphost-pack-7.0 dotnet-apphost-pack-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-apphost-pack-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-host dotnet-host as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-host not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-hostfxr-7.0 dotnet-hostfxr-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-hostfxr-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-runtime-7.0 dotnet-runtime-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-runtime-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-sdk-7.0 dotnet-sdk-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-sdk-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-sdk-7.0-source-built-artifacts dotnet-sdk-7.0-source-built-artifacts as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-sdk-7.0-source-built-artifacts not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-targeting-pack-7.0 dotnet-targeting-pack-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-targeting-pack-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet-templates-7.0 dotnet-templates-7.0 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet-templates-7.0 not applicable csaf_redhat
red_hat_enterprise_linux_9:dotnet7.0.src dotnet7.0.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: dotnet7.0.src not applicable csaf_redhat
red_hat_enterprise_linux_10:firefox firefox as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_7:firefox firefox as a component of Red Hat Enterprise Linux 7 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_8:firefox firefox as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_9:firefox firefox as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_9:firefox-x11 firefox-x11 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: firefox-x11 not applicable csaf_redhat
red_hat_enterprise_linux_10:firefox.src firefox.src as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_7:firefox.src firefox.src as a component of Red Hat Enterprise Linux 7 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_8:firefox.src firefox.src as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_9:firefox.src firefox.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_9:netstandard-targeting-pack-2.1 netstandard-targeting-pack-2.1 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: netstandard-targeting-pack-2.1 not applicable csaf_redhat
red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/bootc-cuda-rhel9 rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3 not affected vulnerable code not present rhelai3/bootc-cuda-rhel9 not applicable csaf_redhat
red_hat_enterprise_linux_ai_(rhel_ai)_3:rhelai3/disk-image-cuda-rhel9 rhelai3/disk-image-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3 not affected vulnerable code not present rhelai3/disk-image-cuda-rhel9 not applicable csaf_redhat
red_hat_openshift_ai_(rhoai):rhoai/odh-dashboard-rhel9 rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI) not affected vulnerable code not in execute path rhoai/odh-dashboard-rhel9 not applicable csaf_redhat
red_hat_trusted_artifact_signer:rhtas/rekor-search-ui-rhel9 rhtas/rekor-search-ui-rhel9 as a component of Red Hat Trusted Artifact Signer not affected vulnerable code not present rhtas/rekor-search-ui-rhel9 not applicable csaf_redhat
red_hat_enterprise_linux_10:thunderbird thunderbird as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: thunderbird not applicable csaf_redhat
red_hat_enterprise_linux_8:thunderbird thunderbird as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: thunderbird not applicable csaf_redhat
red_hat_enterprise_linux_9:thunderbird thunderbird as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: thunderbird not applicable csaf_redhat
red_hat_enterprise_linux_10:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: thunderbird.src not applicable csaf_redhat
red_hat_enterprise_linux_8:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: thunderbird.src not applicable csaf_redhat
red_hat_enterprise_linux_9:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: thunderbird.src not applicable csaf_redhat
https://github.com/react/react affected >= 7aa5dda3b3e4c2baa905a59b922ae7ec14734b24, <= ae74234eae6ebd62f19190731278e20bc1c37d51 none available osv
https://github.com/vercel/next.js affected >= 51bfe3c1863b191f4b039bc230e8ed5c57b0baf3, < 3d663f2141a05adb975de4e9dae4c49780791881 vendor fix → 3d663f2141a05adb975de4e9dae4c49780791881 osv
https://github.com/vercel/next.js affected >= dafcd43fac3ef9d0ffd94f9c94fd61db4449df25, < aeb69d97f8aad106f4760ff04f6d3aaa33597635 vendor fix → aeb69d97f8aad106f4760ff04f6d3aaa33597635 osv
https://github.com/vercel/next.js affected >= b0416fbb44d1d148b6322ed79b6448d588260e49, < 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 vendor fix → 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 osv
https://github.com/vercel/next.js affected >= b2ff04995be722a5c93225e16e1c7fcc8bb53f91, < 2f026aae46027d9575494fb3aecbd0d75fd674f0 vendor fix → 2f026aae46027d9575494fb3aecbd0d75fd674f0 osv
https://github.com/vercel/next.js affected >= 7ad467409b67691ae4f5dc4dc47f1a247c4ba988, < 49668475daba15ef8cea1d8e469dc0f9a765b635 vendor fix → 49668475daba15ef8cea1d8e469dc0f9a765b635 osv
https://github.com/vercel/next.js affected >= 7e08c8223d64bc2add7a0e5a323cbce0a84bb292, < 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 vendor fix → 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 osv
https://github.com/vercel/next.js affected >= 950609f96f694c5475d18cd2d72a0052ca04d4b9, < 7492122a3bbc6655b64ccba04076c73ab418cdcc vendor fix → 7492122a3bbc6655b64ccba04076c73ab418cdcc osv
https://github.com/vercel/next.js affected <= 950609f96f694c5475d18cd2d72a0052ca04d4b9 none available osv
https://github.com/vercel/next.js affected >= 74be1f68c2ed99671d66e3e7f1337b997e74f464, <= 33759e0be7d31f8a5d59544267f7ec9b914f37e5 none available osv
react-server-dom-parcel affected >= 19.0.0, < 19.0.1 vendor fix → 19.0.1 osv GHSA-fv66-9v8q-g76r
react-server-dom-parcel affected >= 19.1.0, < 19.1.2 vendor fix → 19.1.2 osv GHSA-fv66-9v8q-g76r
react-server-dom-parcel affected >= 19.2.0, < 19.2.1 vendor fix → 19.2.1 osv GHSA-fv66-9v8q-g76r
react-server-dom-turbopack affected >= 19.0.0, < 19.0.1 vendor fix → 19.0.1 osv GHSA-fv66-9v8q-g76r
react-server-dom-turbopack affected >= 19.1.0, < 19.1.2 vendor fix → 19.1.2 osv GHSA-fv66-9v8q-g76r
react-server-dom-turbopack affected >= 19.2.0, < 19.2.1 vendor fix → 19.2.1 osv GHSA-fv66-9v8q-g76r
react-server-dom-webpack affected >= 19.0.0, < 19.0.1 vendor fix → 19.0.1 osv GHSA-fv66-9v8q-g76r
react-server-dom-webpack affected >= 19.1.0, < 19.1.2 vendor fix → 19.1.2 osv GHSA-fv66-9v8q-g76r
react-server-dom-webpack affected >= 19.2.0, < 19.2.1 vendor fix → 19.2.1 osv GHSA-fv66-9v8q-g76r
https://github.com/vercel/next.js fixed 3d663f2141a05adb975de4e9dae4c49780791881 vendor fix → 3d663f2141a05adb975de4e9dae4c49780791881 osv
https://github.com/vercel/next.js fixed aeb69d97f8aad106f4760ff04f6d3aaa33597635 vendor fix → aeb69d97f8aad106f4760ff04f6d3aaa33597635 osv
https://github.com/vercel/next.js fixed 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 vendor fix → 25ba2c26f42dc33a72c7ff39710fcad9b19d9658 osv
https://github.com/vercel/next.js fixed 2f026aae46027d9575494fb3aecbd0d75fd674f0 vendor fix → 2f026aae46027d9575494fb3aecbd0d75fd674f0 osv
https://github.com/vercel/next.js fixed 49668475daba15ef8cea1d8e469dc0f9a765b635 vendor fix → 49668475daba15ef8cea1d8e469dc0f9a765b635 osv
https://github.com/vercel/next.js fixed 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 vendor fix → 3eaf68b09b2b6b8c0c8e080a9713e131a78dc529 osv
https://github.com/vercel/next.js fixed 7492122a3bbc6655b64ccba04076c73ab418cdcc vendor fix → 7492122a3bbc6655b64ccba04076c73ab418cdcc osv
react-server-dom-parcel fixed 19.0.1 vendor fix → 19.0.1 osv GHSA-fv66-9v8q-g76r
page 1 of 2 next →

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.