{
  "$schema": "https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json",
  "document": {
    "category": "csaf_base",
    "csaf_version": "2.1",
    "distribution": {
      "tlp": {
        "label": "CLEAR"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Dependency-currency bump of serde_json from 1.0.150 to 1.0.151 in ndaal nvulnlookup 1.2.72. Informational: no security defect is fixed or introduced, and the advisory is scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE)."
      },
      {
        "category": "description",
        "text": "serde_json moved 1.0.150 -> 1.0.151 within the existing semantic-versioning requirement in the workspace manifest — no manifest requirement changed, only the locked version. The bump arrived via `cargo update`, which relocked 142 packages to their latest semver-compatible releases. This advisory records the serde_json move specifically so the CSAF feed carries a per-crate history rather than only a bulk entry."
      },
      {
        "category": "details",
        "text": "Verified before publication: `cargo check --workspace --all-features` exits 0 against the relocked tree. serde_json is a DIRECT workspace dependency, which is why it is documented individually; the 117 transitive moves in the same relock are recorded together in the companion bulk advisory."
      },
      {
        "category": "general",
        "text": "Recommended action: none required for security. Operators building from source will pick up 1.0.151 automatically from the committed Cargo.lock."
      },
      {
        "category": "other",
        "text": "CVSS applicability: a dependency-currency bump with no security impact, scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE) with every impact metric NONE. The score is intentionally zero to signal 'informational, no vulnerability' while still carrying a machine-readable metric. Status: final."
      },
      {
        "category": "legal_disclaimer",
        "text": "THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY. ndaal Gesellschaft fuer Sicherheit in der Informationstechnik mbH & Co KG DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS INFORMATION INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS."
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "security@ndaal.eu",
      "issuing_authority": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG Security Team",
      "name": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG",
      "namespace": "https://ndaal.eu/csaf"
    },
    "references": [
      {
        "category": "self",
        "summary": "This advisory in CSAF 2.1 format",
        "url": "https://gitlab.com/vPierre/ndaal_public_csaf_information/-/raw/main/csaf/2026/621/ndaal-sa-2026-621.json"
      },
      {
        "category": "external",
        "summary": "CHANGELOG 1.2.72",
        "url": "https://gitlab.com/vPierre/ndaal_public_nvulnlookup/-/raw/main/vulnerability-lookup-rs/CHANGELOG.md"
      },
      {
        "category": "external",
        "summary": "nvulnlookup release repository",
        "url": "https://gitlab.com/vPierre/ndaal_public_nvulnlookup_release2/-/tree/main/release"
      }
    ],
    "title": "ndaal Informational Advisory: serde_json 1.0.150 -> 1.0.151 dependency-currency bump (nvulnlookup 1.2.72)",
    "tracking": {
      "current_release_date": "2026-09-16T00:00:00.000Z",
      "generator": {
        "engine": {
          "name": "ndaal CSAF Generator",
          "version": "1.0.0"
        }
      },
      "id": "ndaal-sa-2026-621",
      "initial_release_date": "2026-09-16T00:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-16T00:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial advisory. Informational, no security impact, CVSS v3.1 0.0 / v4.0 0.0 (NONE). Status: final."
        }
      ],
      "status": "final",
      "version": "1.0.0"
    },
    "x_extensions": [
      {
        "$schema": "https://ndaal.eu/.well-known/csaf/extensions/dashboard-branding_1.0.0.json",
        "category": "informational",
        "content": {
          "dashboard_short_name": "ndaal",
          "publisher_brand": "ndaal Advisories Database"
        },
        "critical": false
      }
    ]
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.151",
                "product": {
                  "name": "serde_json 1.0.151 — dependency-currency bump in nvulnlookup 1.2.72, no security impact.",
                  "product_id": "CSAFPID-0001",
                  "product_identification_helper": {
                    "purls": [
                      "pkg:cargo/serde_json@1.0.151"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "serde_json"
          }
        ],
        "category": "vendor",
        "name": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG"
      }
    ]
  },
  "vulnerabilities": [
    {
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "ndaal Advisory ID",
          "text": "ndaal-sa-2026-621"
        }
      ],
      "metrics": [
        {
          "content": {
            "cvss_v3": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "NONE",
              "baseScore": 0.0,
              "baseSeverity": "NONE",
              "confidentialityImpact": "NONE",
              "integrityImpact": "NONE",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
              "version": "3.1"
            },
            "cvss_v4": {
              "attackComplexity": "LOW",
              "attackRequirements": "NONE",
              "attackVector": "NETWORK",
              "baseScore": 0.0,
              "baseSeverity": "NONE",
              "privilegesRequired": "NONE",
              "subAvailabilityImpact": "NONE",
              "subConfidentialityImpact": "NONE",
              "subIntegrityImpact": "NONE",
              "userInteraction": "NONE",
              "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N",
              "version": "4.0",
              "vulnAvailabilityImpact": "NONE",
              "vulnConfidentialityImpact": "NONE",
              "vulnIntegrityImpact": "NONE"
            }
          },
          "products": [
            "CSAFPID-0001"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "serde_json moved 1.0.150 -> 1.0.151 within the existing semantic-versioning requirement in the workspace manifest — no manifest requirement changed, only the locked version. The bump arrived via `cargo update`, which relocked 142 packages to their latest semver-compatible releases. This advisory records the serde_json move specifically so the CSAF feed carries a per-crate history rather than only a bulk entry."
        }
      ],
      "product_status": {
        "known_not_affected": [
          "CSAFPID-0001"
        ]
      },
      "threats": [
        {
          "category": "impact",
          "details": "None. Dependency-currency bump with no security impact (CVSS v3.1 0.0 / v4.0 0.0, NONE).",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "title": "ndaal Informational Advisory: serde_json 1.0.150 -> 1.0.151 dependency-currency bump (nvulnlookup 1.2.72)"
    }
  ]
}