{"id":"CGA-h3fc-hvmg-m7gv","modified":"2026-07-17T20:12:27.838289443Z","published":"2026-05-18T18:20:30Z","withdrawn":"2026-07-17T20:12:27.838289303Z","related":["CVE-2026-41159","GHSA-87f9-hvmw-gh4p"],"affected":[{"package":{"name":"langfuse-2-worker","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/langfuse-2-worker"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.95.12-r23"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-h3fc-hvmg-m7gv.json"}},{"package":{"name":"langfuse-fips-2-worker","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/langfuse-fips-2-worker"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.95.12-r25"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-h3fc-hvmg-m7gv.json"}},{"package":{"name":"librechat","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/librechat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.4-r7"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-h3fc-hvmg-m7gv.json"}}],"schema_version":"1.7.5"}