csaf_ndaal:ndaal-sa-2026-620
NONE csaf_ndaal
Description
Dependency-currency bump of rustls from 0.23.42 to 0.23.45 in ndaal nvulnlookup 1.2.72. Informational: no security defect is fixed or introduced, and the advisory is scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE).
Timeline
- Published
- 2026-09-16 00:00 UTC
- Last Modified
- 2026-09-16
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"$schema": "https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json",
"document": {
"category": "csaf_base",
"csaf_version": "2.1",
"distribution": {
"tlp": {
"label": "CLEAR"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Dependency-currency bump of rustls from 0.23.42 to 0.23.45 in ndaal nvulnlookup 1.2.72. Informational: no security defect is fixed or introduced, and the advisory is scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE)."
},
{
"category": "description",
"text": "rustls moved 0.23.42 -> 0.23.45 within the existing semantic-versioning requirement in the workspace manifest — no manifest requirement changed, only the locked version. The bump arrived via `cargo update`, which relocked 142 packages to their latest semver-compatible releases. This advisory records the rustls move specifically so the CSAF feed carries a per-crate history rather than only a bulk entry."
},
{
"category": "details",
"text": "Verified before publication: `cargo check --workspace --all-features` exits 0 against the relocked tree. rustls is a DIRECT workspace dependency, which is why it is documented individually; the 117 transitive moves in the same relock are recorded together in the companion bulk advisory."
},
{
"category": "general",
"text": "Recommended action: none required for security. Operators building from source will pick up 0.23.45 automatically from the committed Cargo.lock."
},
{
"category": "other",
"text": "CVSS applicability: a dependency-currency bump with no security impact, scored CVSS v3.1 0.0 (NONE) and CVSS v4.0 0.0 (NONE) with every impact metric NONE. The score is intentionally zero to signal 'informational, no vulnerability' while still carrying a machine-readable metric. Status: final."
},
{
"category": "legal_disclaimer",
"text": "THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY. ndaal Gesellschaft fuer Sicherheit in der Informationstechnik mbH & Co KG DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS INFORMATION INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS."
}
],
"publisher": {
"category": "vendor",
"contact_details": "security@ndaal.eu",
"issuing_authority": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG Security Team",
"name": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG",
"namespace": "https://ndaal.eu/csaf"
},
"references": [
{
"category": "self",
"summary": "This advisory in CSAF 2.1 format",
"url": "https://gitlab.com/vPierre/ndaal_public_csaf_information/-/raw/main/csaf/2026/620/ndaal-sa-2026-620.json"
},
{
"category": "external",
"summary": "CHANGELOG 1.2.72",
"url": "https://gitlab.com/vPierre/ndaal_public_nvulnlookup/-/raw/main/vulnerability-lookup-rs/CHANGELOG.md"
},
{
"category": "external",
"summary": "nvulnlookup release repository",
"url": "https://gitlab.com/vPierre/ndaal_public_nvulnlookup_release2/-/tree/main/release"
}
],
"title": "ndaal Informational Advisory: rustls 0.23.42 -> 0.23.45 dependency-currency bump (nvulnlookup 1.2.72)",
"tracking": {
"current_release_date": "2026-09-16T00:00:00.000Z",
"generator": {
"engine": {
"name": "ndaal CSAF Generator",
"version": "1.0.0"
}
},
"id": "ndaal-sa-2026-620",
"initial_release_date": "2026-09-16T00:00:00.000Z",
"revision_history": [
{
"date": "2026-09-16T00:00:00.000Z",
"number": "1.0.0",
"summary": "Initial advisory. Informational, no security impact, CVSS v3.1 0.0 / v4.0 0.0 (NONE). Status: final."
}
],
"status": "final",
"version": "1.0.0"
},
"x_extensions": [
{
"$schema": "https://ndaal.eu/.well-known/csaf/extensions/dashboard-branding_1.0.0.json",
"category": "informational",
"content": {
"dashboard_short_name": "ndaal",
"publisher_brand": "ndaal Advisories Database"
},
"critical": false
}
]
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "0.23.45",
"product": {
"name": "rustls 0.23.45 — dependency-currency bump in nvulnlookup 1.2.72, no security impact.",
"product_id": "CSAFPID-0001",
"product_identification_helper": {
"purls": [
"pkg:cargo/rustls@0.23.45"
]
}
}
}
],
"category": "product_name",
"name": "rustls"
}
],
"category": "vendor",
"name": "ndaal Gesellschaft für Sicherheit in der Informationstechnik mbH & Co KG"
}
]
},
"vulnerabilities": [
{
"flags": [
{
"label": "vulnerable_code_not_present",
"product_ids": [
"CSAFPID-0001"
]
}
],
"ids": [
{
"system_name": "ndaal Advisory ID",
"text": "ndaal-sa-2026-620"
}
],
"metrics": [
{
"content": {
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 0.0,
"baseSeverity": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"cvss_v4": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 0.0,
"baseSeverity": "NONE",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
},
"products": [
"CSAFPID-0001"
]
}
],
"notes": [
{
"category": "description",
"text": "rustls moved 0.23.42 -> 0.23.45 within the existing semantic-versioning requirement in the workspace manifest — no manifest requirement changed, only the locked version. The bump arrived via `cargo update`, which relocked 142 packages to their latest semver-compatible releases. This advisory records the rustls move specifically so the CSAF feed carries a per-crate history rather than only a bulk entry."
}
],
"product_status": {
"known_not_affected": [
"CSAFPID-0001"
]
},
"threats": [
{
"category": "impact",
"details": "None. Dependency-currency bump with no security impact (CVSS v3.1 0.0 / v4.0 0.0, NONE).",
"product_ids": [
"CSAFPID-0001"
]
}
],
"title": "ndaal Informational Advisory: rustls 0.23.42 -> 0.23.45 dependency-currency bump (nvulnlookup 1.2.72)"
}
]
}