{
  "published": "2026-10-06T14:22:03Z",
  "modified": "2026-10-07T09:03:08Z",
  "schema_version": "1.7.5",
  "id": "CGA-hh95-fjr7-rf2x",
  "severity": [
    {
      "type": "CVSS_V4",
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
    }
  ],
  "upstream": [
    "CVE-2026-93749",
    "GHSA-68fv-2mgg-jv7q"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93749.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93749"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.vulncheck.com/advisories/source-map-js-through-1.2.1-event-loop-denial-of-service"
    },
    {
      "type": "REPORT",
      "url": "https://github.com/7rulnik/source-map-js/issues/76"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/7rulnik/source-map-js"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/7rulnik/source-map-js/blob/c1cd8904bb7bd0c7fb5879fcda48134d82a27934/lib/source-node.js#L115-L118"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Chainguard",
        "name": "semaphore",
        "purl": "pkg:apk/chainguard/semaphore?arch=aarch64"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.19.12-r5"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "components": [
          {
            "component_name": "source-map-js",
            "component_version": "1.2.1",
            "component_type": "npm",
            "component_location": "/usr/share/semaphore/embedded-ui/node_modules/source-map-js/package.json",
            "component_purl": "pkg:npm/source-map-js@1.2.1",
            "latest_event_status": "fixed",
            "latest_event_timestamp": "2026-10-07T09:03:08Z"
          }
        ]
      }
    }
  ]
}
