Summary
GHSA-5g3q-578q-gf3m (unreviewed) and GHSA-79wq-w74x-74ch (reviewed repository advisory) describe the same vulnerability and now carry the same CVE, CVE-2026-75839. Requesting the two be reconciled so a single record represents this CVE.
The two records
Both describe the same issue: the ArcadeDB Raft cluster-info endpoints (GetClusterHandler, PostBootstrapStateHandler) in com.arcadedb:arcadedb-server <= 26.7.3 authenticate but do not authorize, disclosing the full server database registry and per-database metadata to any authenticated user. Fixed in 26.8.1. Same affected package, same version range, same fixed version, same CWE-200.
Sequence of events
The vulnerability was reported privately to ArcadeDB and published as GHSA-79wq-w74x-74ch on 2026-08-04, crediting me as reporter. On 2026-08-18 a third-party CNA assigned CVE-2026-75839 based on that published advisory, and the resulting CVE record was ingested as the separate unreviewed advisory GHSA-5g3q-578q-gf3m (published 2026-08-18T12:31:22Z) with no credits.
GHSA-5g3q-578q-gf3m already lists GHSA-79wq-w74x-74ch in its own references, so the relationship is recorded one-directionally. I have since set cve_id on the repository advisory, so GHSA-79wq-w74x-74ch now also carries CVE-2026-75839 and the two records share a join key.
Requests
-
Reconcile the duplicate. Please mark GHSA-5g3q-578q-gf3m as a duplicate of GHSA-79wq-w74x-74ch, or otherwise merge them so a single record represents CVE-2026-75839. The main goal is to avoid a third record being created for the same issue when this CVE is curated.
-
Reporter credit, if your conventions allow it. The reviewed repository advisory credits manus-use as reporter; the unreviewed record has no credits. If credits can be carried over to whichever record ends up representing this CVE, I would appreciate it. I understand credits normally live on the reviewed advisory, so please treat this as a request rather than an expectation.
Happy to provide any further detail if useful. Thanks for maintaining the database.
Summary
GHSA-5g3q-578q-gf3m(unreviewed) andGHSA-79wq-w74x-74ch(reviewed repository advisory) describe the same vulnerability and now carry the same CVE,CVE-2026-75839. Requesting the two be reconciled so a single record represents this CVE.The two records
manus-use(reporter, accepted)repository_advisory_url: nullBoth describe the same issue: the ArcadeDB Raft cluster-info endpoints (
GetClusterHandler,PostBootstrapStateHandler) incom.arcadedb:arcadedb-server <= 26.7.3authenticate but do not authorize, disclosing the full server database registry and per-database metadata to any authenticated user. Fixed in 26.8.1. Same affected package, same version range, same fixed version, same CWE-200.Sequence of events
The vulnerability was reported privately to ArcadeDB and published as
GHSA-79wq-w74x-74chon 2026-08-04, crediting me as reporter. On 2026-08-18 a third-party CNA assignedCVE-2026-75839based on that published advisory, and the resulting CVE record was ingested as the separate unreviewed advisoryGHSA-5g3q-578q-gf3m(published 2026-08-18T12:31:22Z) with no credits.GHSA-5g3q-578q-gf3malready listsGHSA-79wq-w74x-74chin its own references, so the relationship is recorded one-directionally. I have since setcve_idon the repository advisory, soGHSA-79wq-w74x-74chnow also carriesCVE-2026-75839and the two records share a join key.Requests
Reconcile the duplicate. Please mark
GHSA-5g3q-578q-gf3mas a duplicate ofGHSA-79wq-w74x-74ch, or otherwise merge them so a single record represents CVE-2026-75839. The main goal is to avoid a third record being created for the same issue when this CVE is curated.Reporter credit, if your conventions allow it. The reviewed repository advisory credits
manus-useas reporter; the unreviewed record has no credits. If credits can be carried over to whichever record ends up representing this CVE, I would appreciate it. I understand credits normally live on the reviewed advisory, so please treat this as a request rather than an expectation.Happy to provide any further detail if useful. Thanks for maintaining the database.