CVE-2025-6454: Overbroad Vulnerability Resolution

A vulnerability resolution service is being invoked with only a pipeline ID, scanner ID, and ingested IDs, without distinguishing the specific report type. This logic flaw can cause a Denial of Service of security reporting in systems where different types of reports (such as SBOM vs. continuous scanning) use the same underlying scanner ID, allowing active v

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2025-6454-overbroad-vulnerability-resolution --engine opengrep

Description

A vulnerability resolution service is being invoked with only a pipeline ID, scanner ID, and ingested IDs, without distinguishing the specific report type. This logic flaw can cause a Denial of Service of security reporting in systems where different types of reports (such as SBOM vs. continuous scanning) use the same underlying scanner ID, allowing active v