Skip to content

Add CVSS 3.1 severity for GHSA-5pf6-2qwx-pxm2#6907

Open
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6907from
sunnypatell:add-cvss31-GHSA-5pf6-2qwx-pxm2
Open

Add CVSS 3.1 severity for GHSA-5pf6-2qwx-pxm2#6907
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6907from
sunnypatell:add-cvss31-GHSA-5pf6-2qwx-pxm2

Conversation

@sunnypatell
Copy link

adds NVD-sourced CVSS 3.1 severity score to this advisory which currently has no CVSS scoring.

  • source: NVD
  • score: 7.5 (HIGH)
  • vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Copilot AI review requested due to automatic review settings February 16, 2026 00:40
@github-actions github-actions bot changed the base branch from main to sunnypatell/advisory-improvement-6907 February 16, 2026 00:41
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request adds NVD-sourced CVSS 3.1 severity scoring to the GHSA-5pf6-2qwx-pxm2 advisory, which previously had an empty severity array. The advisory describes a credential leakage vulnerability in the Go SDK for CloudEvents.

Changes:

  • Added CVSS 3.1 severity score (7.5 HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N from NVD

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant