Skip to content

Duplicate: GHSA-5g3q-578q-gf3m duplicates GHSA-79wq-w74x-74ch (CVE-2026-75839) #9174

Description

@manus-use

Summary

GHSA-5g3q-578q-gf3m (unreviewed) and GHSA-79wq-w74x-74ch (reviewed repository advisory) describe the same vulnerability and now carry the same CVE, CVE-2026-75839. Requesting the two be reconciled so a single record represents this CVE.

The two records

Reviewed repo advisory Unreviewed global advisory
ID GHSA-79wq-w74x-74ch GHSA-5g3q-578q-gf3m
CVE CVE-2026-75839 CVE-2026-75839
Type reviewed (published) unreviewed
Credits manus-use (reporter, accepted) (empty)
Repo link ArcadeData/arcadedb repository_advisory_url: null

Both describe the same issue: the ArcadeDB Raft cluster-info endpoints (GetClusterHandler, PostBootstrapStateHandler) in com.arcadedb:arcadedb-server <= 26.7.3 authenticate but do not authorize, disclosing the full server database registry and per-database metadata to any authenticated user. Fixed in 26.8.1. Same affected package, same version range, same fixed version, same CWE-200.

Sequence of events

The vulnerability was reported privately to ArcadeDB and published as GHSA-79wq-w74x-74ch on 2026-08-04, crediting me as reporter. On 2026-08-18 a third-party CNA assigned CVE-2026-75839 based on that published advisory, and the resulting CVE record was ingested as the separate unreviewed advisory GHSA-5g3q-578q-gf3m (published 2026-08-18T12:31:22Z) with no credits.

GHSA-5g3q-578q-gf3m already lists GHSA-79wq-w74x-74ch in its own references, so the relationship is recorded one-directionally. I have since set cve_id on the repository advisory, so GHSA-79wq-w74x-74ch now also carries CVE-2026-75839 and the two records share a join key.

Requests

  1. Reconcile the duplicate. Please mark GHSA-5g3q-578q-gf3m as a duplicate of GHSA-79wq-w74x-74ch, or otherwise merge them so a single record represents CVE-2026-75839. The main goal is to avoid a third record being created for the same issue when this CVE is curated.

  2. Reporter credit, if your conventions allow it. The reviewed repository advisory credits manus-use as reporter; the unreviewed record has no credits. If credits can be carried over to whichever record ends up representing this CVE, I would appreciate it. I understand credits normally live on the reviewed advisory, so please treat this as a request rather than an expectation.

Happy to provide any further detail if useful. Thanks for maintaining the database.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions