CLEANSTART-2026-JU43269

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-JU43269.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-JU43269
Upstream
  • CVE-2026-45409
  • ghsa-2h4p-vjrc-8xpq
  • ghsa-5239-wwwm-4pmq
  • ghsa-537c-gmf6-5ccf
  • ghsa-65pc-fj4g-8rjx
  • ghsa-68rp-wp8r-4726
  • ghsa-6v7p-g79w-8964
  • ghsa-mf9v-mfxr-j63j
  • ghsa-mf9w-mj56-hr94
  • ghsa-qccp-gfcp-xxvc
  • ghsa-v92g-xgxw-vvmm
Published
2026-07-21T08:22:17.111164Z
Modified
2026-07-22T01:00:09.811278692Z
Summary
Security fixes for CVE-2026-27205, CVE-2026-28684, CVE-2026-34180, CVE-2026-41205, CVE-2026-44307, CVE-2026-44405, CVE-2026-44431, CVE-2026-44432, CVE-2026-4539, CVE-2026-45409, CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-48526, CVE-2026-57585, CVE-2026-7246, ghsa-2h4p-vjrc-8xpq, ghsa-5239-wwwm-4pmq, ghsa-537c-gmf6-5ccf, ghsa-65pc-fj4g-8rjx, ghsa-68rp-wp8r-4726, ghsa-6v7p-g79w-8964, ghsa-mf9v-mfxr-j63j, ghsa-mf9w-mj56-hr94, ghsa-qccp-gfcp-xxvc, ghsa-v92g-xgxw-vvmm applied in versions: 5.0.0-r7, 5.0.0-r8
Details

Multiple security vulnerabilities affect the apache-superset package. These issues are resolved in later releases. See references for individual vulnerability details.

References

Affected packages

CleanStart / apache-superset

Package

Name
apache-superset

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-r8

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-JU43269.json"