Re: CVE-2026-64607 announced?
"Piotr P. Karwasz" <[email protected]>
| Newsgroups | gmane.comp.jakarta.commons.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi sebb, On 10.08.2026 09:39, sebb wrote: > On Mon, 10 Aug 2026 at 07:48, Piotr P. Karwasz > <[email protected]> wrote: >> All the CVEs disclosed by the ASF *must* have a `vendor-advisory` link, >> which most often than not is a link to the PonyMail archive: >> >> https://www.cve.org/CVERecord?id=CVE-2026-64607 > > Which suggests that such queries should be directed to the > Httpcomponents project... Yes, I saw that Gary posted the question to the wrong list. I just wanted to point out that the answer to the question doesn't depend on the PMC: all PMCs must include a `vendor-advisory`, otherwise the CVE can not be switched to a PUBLIC state. Piotr