wso2 / wso2/docs-security

Question about CVE-2026-0637 being referenced in two different advisories

Open
#228 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
CSS
Stars
34
Forks
75
Avg merge
3d 3h
Merged PRs (30d)
5

Description

Hi Team,

I noticed what seems to be an inconsistency regarding CVE-2026-0637 in your security advisories documentation.

The same CVE appears in these two advisories:

From my reading, these advisories do not appear to describe the same vulnerability, yet they both reference CVE-2026-0637.

Could you please clarify:

  1. Whether CVE-2026-0637 is correctly assigned in both advisories;
  2. If one of the references is a typo or copy/paste error;
  3. Which advisory should be considered the canonical reference for this CVE.

Thank you for your help and for maintaining these security announcements.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by comparing the CVE-2026-0637 references in WSO2-2025-4829.md and WSO2-2025-4897.md. Check whether both advisories describe the same vulnerability, then ask the maintainers to confirm the correct assignment and canonical advisory. Done means the discrepancy is clarified and any confirmed documentation error is corrected.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.