CVE-2026-32767 assigned to libexpat, should be CVE-2026-32776 #10412
mmusenbr
started this conversation in
False Detection
Replies: 2 comments 4 replies
-
Beta Was this translation helpful? Give feedback.
0 replies
-
|
I could still see the behaviour even after the change. Am i missing something here.? |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment

Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2026-32767, CVE-2026-32776
Description
CVE-2026-32767 is linked to libexpat, which is wrong (SiYuan). It seems there was a number switch from CVE-2026-32776.
Reproduction Steps
docker pull eclipse-temurin:21.0.10_7-jdk-alpine-3.23 trivy image eclipse-temurin:21.0.10_7-jdk-alpine-3.23 > libexpat │ CVE-2026-32767 │ CRITICAL │ SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API │ https://avd.aquasec.com/nvd/cve-2026-32767Target
Container Image
Scanner
Vulnerability
Target OS
No response
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions