We published a repository security advisory on 2026-10-01 and it has not appeared in the Advisory Database 36 hours later.
- Advisory: GHSA-gwfx-7pfc-xg68 in vaadin/web-components, state
published since 2026-10-01T05:07:48Z, 23 affected packages across Maven and npm
- CVE: CVE-2026-91860, published on cve.org on 2026-09-30
Looking it up as a global advisory returns 404. Querying by CVE id returns only GHSA-48v4-h5mw-72ww, the copy ingested automatically from NVD, which is unreviewed with no packages, so nothing matches it.
Our previous advisory, GHSA-94g8-xv23-7656, reached the database about three hours after publication. The difference this time is that the CVE record was published before the repository advisory, so the unreviewed copy already existed.
Could the repository advisory be published to the database, and GHSA-48v4-h5mw-72ww merged into it or withdrawn?
We published a repository security advisory on 2026-10-01 and it has not appeared in the Advisory Database 36 hours later.
publishedsince 2026-10-01T05:07:48Z, 23 affected packages across Maven and npmLooking it up as a global advisory returns 404. Querying by CVE id returns only GHSA-48v4-h5mw-72ww, the copy ingested automatically from NVD, which is
unreviewedwith no packages, so nothing matches it.Our previous advisory, GHSA-94g8-xv23-7656, reached the database about three hours after publication. The difference this time is that the CVE record was published before the repository advisory, so the unreviewed copy already existed.
Could the repository advisory be published to the database, and GHSA-48v4-h5mw-72ww merged into it or withdrawn?