CVE-2026-11481

Source
https://cve.org/CVERecord?id=CVE-2026-11481
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11481.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-11481
Aliases
Downstream
Related
Published
2026-06-08T02:45:11Z
Modified
2026-09-09T18:26:43Z
Severity
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
Details

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-327",
        "CWE-328"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11481.json"
}
References

Affected packages

Git / github.com/yoanbernabeu/grepai

Affected ranges

Type
GIT
Repo
https://github.com/yoanbernabeu/grepai
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.1"
        },
        {
            "last_affected": "0.1"
        },
        {
            "introduced": "0.2"
        },
        {
            "last_affected": "0.2"
        },
        {
            "introduced": "0.3"
        },
        {
            "last_affected": "0.3"
        },
        {
            "introduced": "0.4"
        },
        {
            "last_affected": "0.4"
        },
        {
            "introduced": "0.5"
        },
        {
            "last_affected": "0.5"
        },
        {
            "introduced": "0.6"
        },
        {
            "last_affected": "0.6"
        },
        {
            "introduced": "0.7"
        },
        {
            "last_affected": "0.7"
        },
        {
            "introduced": "0.8"
        },
        {
            "last_affected": "0.8"
        },
        {
            "introduced": "0.9"
        },
        {
            "last_affected": "0.9"
        },
        {
            "introduced": "0.10"
        },
        {
            "last_affected": "0.10"
        },
        {
            "introduced": "0.11"
        },
        {
            "last_affected": "0.11"
        },
        {
            "introduced": "0.12"
        },
        {
            "last_affected": "0.12"
        },
        {
            "introduced": "0.13"
        },
        {
            "last_affected": "0.13"
        },
        {
            "introduced": "0.14"
        },
        {
            "last_affected": "0.14"
        },
        {
            "introduced": "0.15"
        },
        {
            "last_affected": "0.15"
        },
        {
            "introduced": "0.16"
        },
        {
            "last_affected": "0.16"
        },
        {
            "introduced": "0.17"
        },
        {
            "last_affected": "0.17"
        },
        {
            "introduced": "0.18"
        },
        {
            "last_affected": "0.18"
        },
        {
            "introduced": "0.19"
        },
        {
            "last_affected": "0.19"
        },
        {
            "introduced": "0.20"
        },
        {
            "last_affected": "0.20"
        },
        {
            "introduced": "0.21"
        },
        {
            "last_affected": "0.21"
        },
        {
            "introduced": "0.22"
        },
        {
            "last_affected": "0.22"
        },
        {
            "introduced": "0.23"
        },
        {
            "last_affected": "0.23"
        },
        {
            "introduced": "0.24"
        },
        {
            "last_affected": "0.24"
        },
        {
            "introduced": "0.25"
        },
        {
            "last_affected": "0.25"
        },
        {
            "introduced": "0.26"
        },
        {
            "last_affected": "0.26"
        },
        {
            "introduced": "0.27"
        },
        {
            "last_affected": "0.27"
        },
        {
            "introduced": "0.28"
        },
        {
            "last_affected": "0.28"
        },
        {
            "introduced": "0.29"
        },
        {
            "last_affected": "0.29"
        },
        {
            "introduced": "0.30"
        },
        {
            "last_affected": "0.30"
        },
        {
            "introduced": "0.31"
        },
        {
            "last_affected": "0.31"
        },
        {
            "introduced": "0.32"
        },
        {
            "last_affected": "0.32"
        },
        {
            "introduced": "0.33"
        },
        {
            "last_affected": "0.33"
        },
        {
            "introduced": "0.34"
        },
        {
            "last_affected": "0.34"
        },
        {
            "introduced": "0.35.0"
        },
        {
            "last_affected": "0.35.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
0.21
0.22
0.23
0.24
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.34
0.35.0
0.4
0.5
0.6
0.7
0.8
0.9
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.15.1
v0.16.0
v0.16.1
v0.2.0
v0.20.0
v0.20.1
v0.21.0
v0.22.0
v0.23.0
v0.23.1
v0.24.0
v0.24.1
v0.25.0
v0.25.1
v0.25.2
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.3.0
v0.30.0
v0.31.0
v0.32.0
v0.32.1
v0.33.0
v0.34.0
v0.35.0
v0.4.0
v0.5.0
v0.7.0
v0.7.1
v0.7.2
v0.8.0
v0.8.1
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11481.json"