{"id":"CGA-rx4f-9353-p5w7","modified":"2026-07-23T15:44:32.964111440Z","published":"2026-07-23T12:47:54Z","upstream":["CVE-2026-64649","GHSA-89xv-2m56-2m9x"],"affected":[{"package":{"name":"commercial-chainloop-frontend","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/commercial-chainloop-frontend?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2026-07-23T12:47:57Z","architecture":"aarch64","component_name":"next","component_version":"16.1.7","component_type":"npm","component_location":"/app/node_modules/next/package.json","component_purl":"pkg:npm/next@16.1.7","latest_event_status":"pending_upstream_fix"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-rx4f-9353-p5w7.json"}}],"schema_version":"1.7.5"}