)]}'
{"ossa/OSSA-2026-029.yaml":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"d9f4c76e911d1dcb5d2720b1d33c9a9fe041dfec","unresolved":false,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"affected-products:"},{"line_number":18,"context_line":"  - product: zaqar"},{"line_number":19,"context_line":"    version: \u0027\u003e\u003d12.0.0 \u003c20.0.1, \u003d\u003d21.0.0, \u003d\u003d22.0.0\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"vulnerabilities:"},{"line_number":22,"context_line":"  - cve-id: CVE-2026-pending"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e608c302_bdbb25b4","line":19,"updated":"2026-07-23 18:39:32.000000000","message":"The epoxy fix was in 20.1.1, not 20.0.1.","commit_id":"936a18ffed5b073b83d64965e8a72ad47929e438"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"2068255485ac1080df8c11df6ed94baff9458986","unresolved":false,"context_lines":[{"line_number":16,"context_line":""},{"line_number":17,"context_line":"affected-products:"},{"line_number":18,"context_line":"  - product: zaqar"},{"line_number":19,"context_line":"    version: \u0027\u003e\u003d12.0.0 \u003c20.0.1, \u003d\u003d21.0.0, \u003d\u003d22.0.0\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"vulnerabilities:"},{"line_number":22,"context_line":"  - cve-id: CVE-2026-pending"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"51397946_413a77f4","line":19,"in_reply_to":"e608c302_bdbb25b4","updated":"2026-07-23 18:44:41.000000000","message":"AH! ty for flagging this. fixed","commit_id":"936a18ffed5b073b83d64965e8a72ad47929e438"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"04baafc31609798e9dacea0571f37e77e03cc47e","unresolved":false,"context_lines":[{"line_number":13,"context_line":"  header was intended to support an alternative authentication"},{"line_number":14,"context_line":"  mechanism, but the backend validation was never implemented,"},{"line_number":15,"context_line":"  resulting in a complete authentication bypass. All deployments"},{"line_number":16,"context_line":"  running Zaqar 12.0.0 or later are affected."},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"affected-products:"},{"line_number":19,"context_line":"  - product: zaqar"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"5ac09d8f_bd386aa5","line":16,"updated":"2026-07-23 18:46:13.000000000","message":"Nit: This is technically not true if they\u0027ve upgraded to one of the fixed versions, but I think it would take a very pedantic reading to not grok that.","commit_id":"2e788fb06970122c78584a0ae871bd0d71da7a07"}]}
