{"id":"CGA-3688-64cj-cmp9","modified":"2026-07-17T18:32:27.155709808Z","published":"2026-06-23T20:29:19Z","upstream":["CVE-2021-32796","GHSA-5fg8-2547-mr8q"],"references":[{"type":"ADVISORY","url":"https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/"},{"type":"ADVISORY","url":"https://github.com/xmldom/xmldom/security/advisories/GHSA-5fg8-2547-mr8q"},{"type":"FIX","url":"https://github.com/xmldom/xmldom/commit/7b4b743917a892d407356e055b296dcd6d107e8b"}],"affected":[{"package":{"name":"wazuh-dashboard-security-plugin-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/wazuh-dashboard-security-plugin-fips?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.14.6-r1"}]}],"ecosystem_specific":{"components":[{"latest_event_status":"fixed","latest_event_timestamp":"2026-07-08T15:39:15Z","architecture":"aarch64","component_name":"xmldom","component_version":"0.3.0","component_type":"npm","component_location":"/usr/share/wazuh-dashboard/plugins/securityDashboards/yarn.lock","component_purl":"pkg:npm/xmldom@0.3.0"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-3688-64cj-cmp9.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}