Skip to content

Conversation

@bernardoamc-stripe
Copy link

Small change to add the associated [CVE-2025-12967(https://nvd.nist.gov/vuln/detail/CVE-2025-12967) to the aliases field.

Interestingly, it is already listed within the advisory itself: GHSA-7xw4-g7mm-r4hh

@github-actions github-actions bot changed the base branch from main to bernardoamc-stripe/advisory-improvement-6480 November 27, 2025 22:09
@shelbyc
Copy link
Contributor

shelbyc commented Dec 8, 2025

Hi @bernardoamc-stripe, I can't add CVE-2025-12967 to GHSA-7xw4-g7mm-r4hh because CVE-2025-12967 is already attached to GHSA-4jvf-wx3f-2x8q in the GitHub Advisory Database backend, so that GHSA-4jvf-wx3f-2x8q is the advisory that appears when a user hovers over CVE-2025-12967. Any number of advisories, such as GHSA-7xw4-g7mm-r4hh, can indicate that they discuss how CVE-2025-12967 affects various products, but only one advisory can have CVE-2025-12967 as an alias. Thank you for your interest in GHSA-7xw4-g7mm-r4hh, and I hope this explanation helps.

@shelbyc shelbyc closed this Dec 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants