{"id":"CLEANSTART-2026-MM00120","summary":"Security fixes for CVE-2024-47535, CVE-2024-47561, CVE-2024-7254, CVE-2025-24970, CVE-2025-25193, CVE-2025-33042, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057, CVE-2025-67735, CVE-2025-68161, CVE-2026-41417, ghsa-3pxv-7cmr-fjr4, ghsa-445c-vh5m-36rj, ghsa-6hg6-v5c8-fphq, ghsa-72hv-8253-57qq, ghsa-pwqr-wmgm-9rr8, ghsa-w9fj-cfpg-grvv applied in versions: 13.8-r0, 13.9-r0","details":"Multiple security vulnerabilities affect the wavefront-proxy package. These issues are resolved in later releases. See references for individual vulnerability details.","modified":"2026-09-18T12:17:28.628535132Z","published":"2026-05-18T13:36:03.855524Z","withdrawn":"2026-09-18T11:59:01.768079Z","upstream":["CVE-2024-47535","CVE-2024-47561","CVE-2024-7254","CVE-2025-24970","CVE-2025-25193","CVE-2025-33042","CVE-2025-48924","CVE-2025-55163","CVE-2025-58056","CVE-2025-58057","CVE-2025-67735","CVE-2025-68161","CVE-2026-41417","ghsa-3pxv-7cmr-fjr4","ghsa-445c-vh5m-36rj","ghsa-6hg6-v5c8-fphq","ghsa-72hv-8253-57qq","ghsa-pwqr-wmgm-9rr8","ghsa-w9fj-cfpg-grvv"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-MM00120.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-47535"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-47561"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2024-7254"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-24970"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-25193"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-33042"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-48924"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-55163"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-58056"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-58057"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-67735"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-68161"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-41417"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-3pxv-7cmr-fjr4"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-445c-vh5m-36rj"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-6hg6-v5c8-fphq"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-72hv-8253-57qq"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-pwqr-wmgm-9rr8"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-w9fj-cfpg-grvv"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47535"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47561"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7254"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24970"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25193"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-33042"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55163"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58056"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58057"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67735"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68161"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41417"}],"affected":[{"package":{"name":"wavefront-proxy","ecosystem":"CleanStart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"13.9-r0"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-MM00120.json"}}],"schema_version":"1.9.0"}