{"id":"CGA-5qc5-c6vp-cj7c","modified":"2026-08-03T15:30:19.678445856Z","published":"2026-07-25T13:40:32Z","upstream":["CVE-2023-28155","GHSA-p8p7-x288-28g6"],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28155"},{"type":"WEB","url":"https://github.com/request/request/issues/3442"},{"type":"WEB","url":"https://github.com/cypress-io/request/pull/28"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/2500"},{"type":"WEB","url":"https://github.com/request/request/pull/3444"},{"type":"WEB","url":"https://github.com/cypress-io/request/commit/c5bcf21d40fb61feaff21a0e5a2b3934a440024f"},{"type":"WEB","url":"https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf"},{"type":"WEB","url":"https://github.com/cypress-io/request/blob/master/lib/redirect.js#L116"},{"type":"WEB","url":"https://github.com/cypress-io/request/releases/tag/v3.0.0"},{"type":"PACKAGE","url":"https://github.com/request/request"},{"type":"WEB","url":"https://github.com/request/request/blob/master/lib/redirect.js#L111"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230413-0007"}],"affected":[{"package":{"name":"kubeflow-centraldashboard","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/kubeflow-centraldashboard?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"architecture":"x86_64","component_name":"request","component_version":"2.88.0","component_type":"npm","component_location":"/app/package-lock.json","component_purl":"pkg:npm/request@2.88.0","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-07-30T12:28:13Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-5qc5-c6vp-cj7c.json"}},{"package":{"name":"kubeflow-centraldashboard","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/kubeflow-centraldashboard?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:npm/request@2.88.0","latest_event_status":"pending_upstream_fix","latest_event_timestamp":"2026-07-30T12:28:13Z","architecture":"x86_64","component_name":"request","component_version":"2.88.0","component_type":"npm","component_location":"/app/package-lock.json"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-5qc5-c6vp-cj7c.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}