CLEANSTART-2026-AH85401

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-AH85401.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-AH85401
Upstream
Published
2026-10-06T00:39:11Z
Modified
2026-10-08T16:47:26Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, with...
Details

Security vulnerability affects the sonarqube package. The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage.

References

Affected packages

CleanStart / sonarqube

Package

Name
sonarqube
Purl
pkg:apk/cleanstart/sonarqube

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.6.0.123539-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-AH85401.json"