{"id":"CVE-2026-56853","title":"net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)","summary":"A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTi…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-770","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.22","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","aws_load_balancer_operator","cert_manager_operator_for_red_hat_openshift","confidential_compute_attestation","deployment_validation_operator","exploit_intelligence","externaldns_operator","fence_agents_remediation_operator","file_integrity_operator","logical_volume_manager_storage","machine_deletion_remediation_operator","migration_toolkit_for_applications 8","multicluster_engine_for_kubernetes","network_observability_operator","node_healthcheck_operator","node_maintenance_operator","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","power_monitoring_for_red_hat_openshift","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","ai_inference_server","ansible_automation_platform 2","ceph_storage 5","ceph_storage 6","ceph_storage 7","ceph_storage 8","ceph_storage 9","certification_program_for_red_hat_enterprise_linux 9","connectivity_link 1","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","lightspeed_for_runtimes_operator","openshift_ai_rhoai","openshift_cluster_manager_cli","openshift_container_platform 4"],"patched":["rhem_1_1_for_rhel 10","rhem_1_2_for_rhel 10","rhem_1_1_for_rhel 9","rhem_1_2_for_rhel 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_codeready_linux_builder_v_10","custom_metric_autoscaler 2.19","logging_subsystem_for_red_hat_openshift 6.2","logging_subsystem_for_red_hat_openshift 6.6","multicluster_global_hub 1.4.9","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","openshift_api_for_data_protection 1.5","openshift_compliance_operator 1","openshift_developer_tools_and_services 1.6.4","advanced_cluster_security_for_kubernetes 4.10","advanced_cluster_security_for_kubernetes 4.11","developer_hub 1.9","edge_manager 1.1","edge_manager 1.2","hardened_images","migration_toolkit 1.8","multiarch_tuning 1.3.4","openshift_ai 2.25","openshift_builds 1.8.1","openshift_container_platform 4.22","openshift_service_mesh 3.0","openshift_service_mesh 3.1","openshift_service_mesh 3.2","openshift_service_mesh 3.3"],"published":"2026-08-13","updated":"2026-09-23","sourceUpdated":"2026-09-23T03:19:07+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56853.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56853.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-56853"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515827"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-56853"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853"},{"url":"https://go.dev/cl/795540"},{"url":"https://go.dev/issue/80205"},{"url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"},{"url":"https://pkg.go.dev/vuln/GO-2026-6089"},{"url":"https://access.redhat.com/errata/RHSA-2026:68334"},{"url":"https://access.redhat.com/errata/RHSA-2026:68335"},{"url":"https://access.redhat.com/errata/RHSA-2026:65918"},{"url":"https://access.redhat.com/errata/RHSA-2026:61882"},{"url":"https://access.redhat.com/errata/RHSA-2026:67517"},{"url":"https://access.redhat.com/errata/RHSA-2026:66459"},{"url":"https://access.redhat.com/errata/RHSA-2026:65335"},{"url":"https://access.redhat.com/errata/RHSA-2026:67974"},{"url":"https://access.redhat.com/errata/RHSA-2026:66327"},{"url":"https://access.redhat.com/errata/RHSA-2026:70103"},{"url":"https://access.redhat.com/errata/RHSA-2026:63332"},{"url":"https://access.redhat.com/errata/RHSA-2026:64777"},{"url":"https://access.redhat.com/errata/RHSA-2026:62578"},{"url":"https://access.redhat.com/errata/RHSA-2026:60306"},{"url":"https://access.redhat.com/errata/RHSA-2026:63022"},{"url":"https://access.redhat.com/errata/RHSA-2026:63119"},{"url":"https://access.redhat.com/errata/RHSA-2026:65534"},{"url":"https://access.redhat.com/errata/RHSA-2026:62631"},{"url":"https://access.redhat.com/errata/RHSA-2026:65116"},{"url":"https://access.redhat.com/errata/RHSA-2026:65895"},{"url":"https://access.redhat.com/errata/RHSA-2026:70201"},{"url":"https://access.redhat.com/errata/RHSA-2026:67464"},{"url":"https://access.redhat.com/errata/RHSA-2026:64818"},{"url":"https://access.redhat.com/errata/RHSA-2026:63163"},{"url":"https://access.redhat.com/errata/RHSA-2026:60305"},{"url":"https://access.redhat.com/errata/RHSA-2026:62407"},{"url":"https://access.redhat.com/errata/RHSA-2026:63124"},{"url":"https://access.redhat.com/errata/RHSA-2026:66016"},{"url":"https://access.redhat.com/errata/RHSA-2026:64786"},{"url":"https://access.redhat.com/errata/RHSA-2026:62602"},{"url":"https://access.redhat.com/errata/RHSA-2026:65359"},{"url":"https://access.redhat.com/errata/RHSA-2026:62754"},{"url":"https://access.redhat.com/errata/RHSA-2026:62405"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00568,"epssPercentile":0.45821,"aliases":["GO-2026-6089","BIT-golang-2026-56853"],"ecosystem":"go","ingestedAt":"2026-08-14T19:18:46.559Z","slug":"CVE-2026-56853","body":"## Overview\n\nA flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTimeout` is not correctly applied during this process. This oversight could allow a remote attacker to maintain open connections indefinitely, potentially leading to a Denial of Service (DoS) by exhausting server resources.\n\n## Vendor advisories\n\n- **RHSA-2026:68334** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68334)\n- **RHSA-2026:68335** · Red Hat · fixed in: RHEM 1.2 for RHEL 10, RHEM 1.2 for RHEL 9 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68335)\n- **RHSA-2026:65918** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:65918)\n- **RHSA-2026:61882** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:61882)\n- **RHSA-2026:67517** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67517)\n- **RHSA-2026:66459** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66459)\n- **RHSA-2026:65335** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65335)\n- **RHSA-2026:67974** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67974)\n- **RHSA-2026:66327** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66327)\n- **RHSA-2026:70103** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70103)\n- **RHSA-2026:63332** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:63332)\n- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, AWS Load Balancer Operator, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Deployment Validation Operator, Exploit Intelligence, … · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56853.json)\n- **RHSA-2026:64777** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64777)\n- **RHSA-2026:62578** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62578)\n- **RHSA-2026:60306** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60306)\n- **RHSA-2026:63022** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63022)\n- **RHSA-2026:63119** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63119)\n- **RHSA-2026:65534** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65534)\n- **RHSA-2026:62631** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62631)\n- **RHSA-2026:65116** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65116)\n\n**net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service** — rated Important by Red Hat. Released 2026-08-13, updated 2026-09-23.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- AWS Load Balancer Operator\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- Exploit Intelligence\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- File Integrity Operator\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 8\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- Node Maintenance Operator\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- Power monitoring for Red Hat OpenShift\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 7\n- Red Hat Ceph Storage 8\n- Red Hat Ceph Storage 9\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Connectivity Link 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Lightspeed for Runtimes Operator\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Cluster Manager CLI\n- Red Hat OpenShift Container Platform 4\n\nFixed:\n\n- RHEM 1.1 for RHEL 10\n- RHEM 1.2 for RHEL 10\n- RHEM 1.1 for RHEL 9\n- RHEM 1.2 for RHEL 9\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)\n- Custom Metric Autoscaler 2.19\n- Logging Subsystem for Red Hat OpenShift 6.2\n- Logging Subsystem for Red Hat OpenShift 6.6\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- OpenShift API for Data Protection 1.5\n- OpenShift Compliance Operator 1\n- OpenShift Developer Tools and Services 1.6.4\n- Red Hat Advanced Cluster Security for Kubernetes 4.10\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n- Red Hat Developer Hub 1.9\n- Red Hat Edge Manager 1.1\n- Red Hat Edge Manager 1.2\n- Red Hat Hardened Images\n- Red Hat Migration Toolkit 1.8\n- Red Hat Multiarch Tuning 1.3.4\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift Builds 1.8.1\n- Red Hat OpenShift Container Platform 4.22\n- Red Hat OpenShift Service Mesh 3.0\n- Red Hat OpenShift Service Mesh 3.1\n- Red Hat OpenShift Service Mesh 3.2\n- Red Hat OpenShift Service Mesh 3.3\n\nNo fix planned:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Secrets Management Console for Red Hat OpenShift\n- Zero Trust Workload Identity Manager - Tech Preview\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- AWS Load Balancer Operator\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- Exploit Intelligence\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- File Integrity Operator\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 8\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- Node Maintenance Operator\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- Power monitoring for Red Hat OpenShift\n- Red Hat 3scale API Management Platform 2\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 7\n- Red Hat Ceph Storage 8\n- Red Hat Ceph Storage 9\n- Red Hat Certification Program for Red Hat Enterprise Linux 9\n- Red Hat Connectivity Link 1\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Lightspeed for Runtimes Operator\n\nNot affected:\n\n- RHEM 1.1 for RHEL 10\n- RHEM 1.2 for RHEL 10\n- RHEM 1.1 for RHEL 9\n- RHEM 1.2 for RHEL 9\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Logging Subsystem for Red Hat OpenShift 6.2\n- Logging Subsystem for Red Hat OpenShift 6.6\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n\n## Remediation\n\nSee the following documentation for details on how to enable Red Hat Edge\nManager and more:\nhttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68334\nSee the following documentation for details on how to enable Red Hat Edge\nManager and more:\nhttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 https://access.redhat.com/errata/RHSA-2026:68335\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:65918\n\n## Package advisory (CVE-2026-56853)\n\nAffected packages:\n\n- `stdlib >= 1.27.0-0, < 1.27.0-rc.3`\n\nPatched in:\n\n- `stdlib 1.27.0-rc.3`\n\nSource: https://osv.dev/vulnerability/GO-2026-6089","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201793,"id":"CVE-2026-56853","ts":1789399725843,"field":"cvss","old":null,"new":"7.5"},{"seq":201792,"id":"CVE-2026-56853","ts":1789399725843,"field":"severity","old":"none","new":"high"},{"seq":200523,"id":"CVE-2026-56853","ts":1789397373769,"field":"cvss","old":"7.5","new":null},{"seq":200522,"id":"CVE-2026-56853","ts":1789397373769,"field":"severity","old":"high","new":"none"},{"seq":198440,"id":"CVE-2026-56853","ts":1789391968790,"field":"cvss","old":null,"new":"7.5"},{"seq":198439,"id":"CVE-2026-56853","ts":1789391968790,"field":"severity","old":"none","new":"high"},{"seq":196233,"id":"CVE-2026-56853","ts":1789383585195,"field":"cvss","old":"7.5","new":null},{"seq":196232,"id":"CVE-2026-56853","ts":1789383585195,"field":"severity","old":"high","new":"none"},{"seq":195162,"id":"CVE-2026-56853","ts":1789380475038,"field":"cvss","old":null,"new":"7.5"},{"seq":195161,"id":"CVE-2026-56853","ts":1789380475038,"field":"severity","old":"none","new":"high"},{"seq":193949,"id":"CVE-2026-56853","ts":1789378515348,"field":"cvss","old":"7.5","new":null},{"seq":193948,"id":"CVE-2026-56853","ts":1789378515348,"field":"severity","old":"high","new":"none"},{"seq":192736,"id":"CVE-2026-56853","ts":1789376407124,"field":"cvss","old":null,"new":"7.5"},{"seq":192735,"id":"CVE-2026-56853","ts":1789376407124,"field":"severity","old":"none","new":"high"},{"seq":191523,"id":"CVE-2026-56853","ts":1789373419681,"field":"cvss","old":"7.5","new":null},{"seq":191522,"id":"CVE-2026-56853","ts":1789373419681,"field":"severity","old":"high","new":"none"},{"seq":190308,"id":"CVE-2026-56853","ts":1789369299987,"field":"cvss","old":null,"new":"7.5"},{"seq":190307,"id":"CVE-2026-56853","ts":1789369299987,"field":"severity","old":"none","new":"high"},{"seq":189095,"id":"CVE-2026-56853","ts":1789368266951,"field":"cvss","old":"7.5","new":null},{"seq":189094,"id":"CVE-2026-56853","ts":1789368266951,"field":"severity","old":"high","new":"none"},{"seq":187878,"id":"CVE-2026-56853","ts":1789365143337,"field":"cvss","old":null,"new":"7.5"},{"seq":187877,"id":"CVE-2026-56853","ts":1789365143337,"field":"severity","old":"none","new":"high"},{"seq":186665,"id":"CVE-2026-56853","ts":1789363271388,"field":"cvss","old":"7.5","new":null},{"seq":186664,"id":"CVE-2026-56853","ts":1789363271388,"field":"severity","old":"high","new":"none"},{"seq":185451,"id":"CVE-2026-56853","ts":1789361101317,"field":"cvss","old":null,"new":"7.5"},{"seq":185450,"id":"CVE-2026-56853","ts":1789361101317,"field":"severity","old":"none","new":"high"},{"seq":184238,"id":"CVE-2026-56853","ts":1789358155653,"field":"cvss","old":"7.5","new":null},{"seq":184237,"id":"CVE-2026-56853","ts":1789358155653,"field":"severity","old":"high","new":"none"},{"seq":182489,"id":"CVE-2026-56853","ts":1789354222458,"field":"cvss","old":null,"new":"7.5"},{"seq":182488,"id":"CVE-2026-56853","ts":1789354222458,"field":"severity","old":"none","new":"high"},{"seq":181282,"id":"CVE-2026-56853","ts":1789353120592,"field":"cvss","old":"7.5","new":null},{"seq":181281,"id":"CVE-2026-56853","ts":1789353120592,"field":"severity","old":"high","new":"none"},{"seq":180075,"id":"CVE-2026-56853","ts":1789350169109,"field":"cvss","old":null,"new":"7.5"},{"seq":180074,"id":"CVE-2026-56853","ts":1789350169109,"field":"severity","old":"none","new":"high"},{"seq":178868,"id":"CVE-2026-56853","ts":1789348101381,"field":"cvss","old":"7.5","new":null},{"seq":178867,"id":"CVE-2026-56853","ts":1789348101381,"field":"severity","old":"high","new":"none"},{"seq":177661,"id":"CVE-2026-56853","ts":1789346277606,"field":"cvss","old":null,"new":"7.5"},{"seq":177660,"id":"CVE-2026-56853","ts":1789346277606,"field":"severity","old":"none","new":"high"},{"seq":176454,"id":"CVE-2026-56853","ts":1789343018765,"field":"cvss","old":"7.5","new":null},{"seq":176453,"id":"CVE-2026-56853","ts":1789343018765,"field":"severity","old":"high","new":"none"},{"seq":174571,"id":"CVE-2026-56853","ts":1789334771605,"field":"cvss","old":null,"new":"7.5"},{"seq":174570,"id":"CVE-2026-56853","ts":1789334771605,"field":"severity","old":"none","new":"high"},{"seq":173366,"id":"CVE-2026-56853","ts":1789333512057,"field":"cvss","old":"7.5","new":null},{"seq":173365,"id":"CVE-2026-56853","ts":1789333512057,"field":"severity","old":"high","new":"none"},{"seq":172180,"id":"CVE-2026-56853","ts":1789331018036,"field":"cvss","old":null,"new":"7.5"},{"seq":172179,"id":"CVE-2026-56853","ts":1789331018036,"field":"severity","old":"none","new":"high"},{"seq":170994,"id":"CVE-2026-56853","ts":1789328614576,"field":"cvss","old":"7.5","new":null},{"seq":170993,"id":"CVE-2026-56853","ts":1789328614576,"field":"severity","old":"high","new":"none"},{"seq":169789,"id":"CVE-2026-56853","ts":1789327050983,"field":"cvss","old":null,"new":"7.5"},{"seq":169788,"id":"CVE-2026-56853","ts":1789327050983,"field":"severity","old":"none","new":"high"}]}