Skip to content

Add CVSS 3.1 severity for GHSA-5pf6-2qwx-pxm2#6907

Merged
advisory-database[bot] merged 1 commit intogithub:sunnypatell/advisory-improvement-6907from
sunnypatell:add-cvss31-GHSA-5pf6-2qwx-pxm2
Feb 17, 2026
Merged

Add CVSS 3.1 severity for GHSA-5pf6-2qwx-pxm2#6907
advisory-database[bot] merged 1 commit intogithub:sunnypatell/advisory-improvement-6907from
sunnypatell:add-cvss31-GHSA-5pf6-2qwx-pxm2

Conversation

@sunnypatell
Copy link

adds NVD-sourced CVSS 3.1 severity score to this advisory which currently has no CVSS scoring.

  • source: NVD
  • score: 7.5 (HIGH)
  • vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Copilot AI review requested due to automatic review settings February 16, 2026 00:40
@github-actions github-actions bot changed the base branch from main to sunnypatell/advisory-improvement-6907 February 16, 2026 00:41
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request adds NVD-sourced CVSS 3.1 severity scoring to the GHSA-5pf6-2qwx-pxm2 advisory, which previously had an empty severity array. The advisory describes a credential leakage vulnerability in the Go SDK for CloudEvents.

Changes:

  • Added CVSS 3.1 severity score (7.5 HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N from NVD

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@advisory-database advisory-database bot merged commit 8c8538a into github:sunnypatell/advisory-improvement-6907 Feb 17, 2026
7 of 8 checks passed
@advisory-database
Copy link
Contributor

Hi @sunnypatell! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments