{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_base","csaf_version":"2.1","distribution":{"tlp":{"label":"CLEAR"}},"lang":"en","notes":[{"category":"summary","text":"Transitive dependency-currency refresh in ndaal nvulnlookup 1.2.72: 117 locked packages moved to their latest semver-compatible releases. Informational, CVSS v3.1 0.0 / v4.0 0.0 (NONE)."},{"category":"description","text":"`cargo update` relocked 142 packages; 25 of them are direct workspace dependencies and each has its own advisory. The remaining 117 are transitive and are recorded here together, matching the precedent set by ndaal-sa-2026-517. No manifest requirement changed."},{"category":"details","text":"Notable transitive moves include the AWS-LC cryptographic backend used under rustls (aws-lc-rs, aws-lc-sys). Full list (first 40): aho-corasick 1.1.4->1.1.5, android_system_properties 0.1.5->0.1.6, ar_archive_writer 0.5.2->0.5.3, askama_derive 0.16.0->0.16.1, askama_macros 0.16.0->0.16.1, askama_parser 0.16.0->0.16.1, async-compression 0.4.42->0.4.47, aws-lc-rs 1.17.3->1.18.1, aws-lc-sys 0.43.0->0.45.0, bitflags 2.13.1->2.13.2, bon 3.9.3->3.10.1, bon-macros 3.9.3->3.10.1, cc 1.3.0->1.4.6, chacha20 0.10.1->0.10.2, clap_builder 4.6.2->4.6.7, clap_derive 4.6.4->4.6.7, clap_lex 1.1.0->1.1.1, combine 4.6.7->4.6.8, compression-codecs 0.4.38->0.4.42, compression-core 0.4.32->0.4.33, console 0.16.4->0.16.6, cookie 0.18.1->0.18.2, cpufeatures 0.3.0->0.3.1, crc32fast 1.5.0->1.5.2, crossbeam-channel 0.5.16->0.5.17, crossbeam-deque 0.8.7->0.8.8, crossbeam-epoch 0.9.20->0.9.21, crossbeam-utils 0.8.22->0.8.23, darling 0.20.11->0.24.1, darling_core 0.20.11->0.24.1, darling_macro 0.20.11->0.24.1, data-encoding 2.11.0->2.11.1, displaydoc 0.2.6->0.2.7, either 1.16.0->1.18.0, encoding_rs 0.8.35->0.8.41, fastrand 2.4.1->2.5.0, find-msvc-tools 0.1.9->0.1.12, futures-channel 0.3.33->0.3.34, futures-core 0.3.33->0.3.34, futures-executor 0.3.33->0.3.34. Verified: `cargo check --workspace --all-features` exits 0 against the relocked tree."},{"category":"general","text":"Recommended action: none required for security. The locked versions ship in Cargo.lock."},{"category":"other","text":"CVSS applicability: a dependency-currency bump with no security impact, scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE) with every impact metric NONE. The score is intentionally zero to signal 'informational, no vulnerability' while still carrying a machine-readable metric. Status: final."},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY. ndaal Gesellschaft fuer Sicherheit in der Informationstechnik mbH & Co KG DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS INFORMATION INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS."}],"publisher":{"category":"vendor","contact_details":"security@ndaal.eu","issuing_authority":"ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG Security Team","name":"ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG","namespace":"https://ndaal.eu/csaf"},"references":[{"category":"self","summary":"This advisory in CSAF 2.1 format","url":"https://gitlab.com/vPierre/ndaal_public_csaf_information/-/raw/main/csaf/2026/628/ndaal-sa-2026-628.json"},{"category":"external","summary":"CHANGELOG 1.2.72","url":"https://gitlab.com/vPierre/ndaal_public_nvulnlookup/-/raw/main/vulnerability-lookup-rs/CHANGELOG.md"},{"category":"external","summary":"nvulnlookup release repository","url":"https://gitlab.com/vPierre/ndaal_public_nvulnlookup_release2/-/tree/main/release"}],"title":"ndaal Informational Advisory: transitive dependency-currency refresh via cargo update (nvulnlookup 1.2.72)","tracking":{"current_release_date":"2026-09-16T00:00:00.000Z","generator":{"engine":{"name":"ndaal CSAF Generator","version":"1.0.0"}},"id":"ndaal-sa-2026-628","initial_release_date":"2026-09-16T00:00:00.000Z","revision_history":[{"date":"2026-09-16T00:00:00.000Z","number":"1.0.0","summary":"Initial advisory. Informational, no security impact, CVSS v3.1 0.0 / v4.0 0.0 (NONE). Status: final."}],"status":"final","version":"1.0.0"},"x_extensions":[{"$schema":"https://ndaal.eu/.well-known/csaf/extensions/dashboard-branding_1.0.0.json","category":"informational","content":{"dashboard_short_name":"ndaal","publisher_brand":"ndaal Advisories Database"},"critical":false}]},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"1.2.72","product":{"name":"ndaal nvulnlookup 1.2.72 — transitive dependency refresh, no security impact.","product_id":"CSAFPID-0001","product_identification_helper":{"purls":["pkg:cargo/vl-web@1.2.72"]}}}],"category":"product_name","name":"nvulnlookup"}],"category":"vendor","name":"ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG"}]},"vulnerabilities":[{"flags":[{"label":"vulnerable_code_not_present","product_ids":["CSAFPID-0001"]}],"ids":[{"system_name":"ndaal Advisory ID","text":"ndaal-sa-2026-628"}],"metrics":[{"content":{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"cvss_v4":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":0.0,"baseSeverity":"NONE","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"}},"products":["CSAFPID-0001"]}],"notes":[{"category":"description","text":"`cargo update` relocked 142 packages; 25 of them are direct workspace dependencies and each has its own advisory. The remaining 117 are transitive and are recorded here together, matching the precedent set by ndaal-sa-2026-517. No manifest requirement changed."}],"product_status":{"known_not_affected":["CSAFPID-0001"]},"threats":[{"category":"impact","details":"None. Dependency-currency bump with no security impact (CVSS v3.1 0.0 / v4.0 0.0, NONE).","product_ids":["CSAFPID-0001"]}],"title":"ndaal Informational Advisory: transitive dependency-currency refresh via cargo update (nvulnlookup 1.2.72)"}]}