Skip to content

Conversation

jlsec-bot
Copy link

This action searched recent NVD/EUVD changes/publications, checking 658 (+0) advisories from NVD and 5000 (+654) from EUVD for advisories that pertain here. It identified 2 advisories as being related to the Julia package(s): Poppler_jll, and GnuTLS_jll.

2 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2025-32988 for packages: GnuTLS_jll
    • GnuTLS_jll computed ["*"]. Its latest version (3.8.4+0) has components: {gnutls = "3.8.4"}
      • gnu:gnutls at < 3.8.10 includes all versions
  • CVE-2025-43903 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.04.0 includes all versions

@mbauman mbauman added the DONOTUSEJLSEC Testing data prior to publishing real JLSEC identifiers label Oct 7, 2025
@mbauman mbauman closed this Oct 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
DONOTUSEJLSEC Testing data prior to publishing real JLSEC identifiers
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants