{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://dcsf.net/vex.json",
  "author": "DataHouse / eTop sp. z o.o. <dat@etop.pl>",
  "role": "Document Creator",
  "timestamp": "2026-09-16T10:59:16.226Z",
  "version": 2,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2026-65638",
        "@id": "https://www.cve.org/CVERecord?id=CVE-2026-65638"
      },
      "products": [
        {
          "@id": "pkg:generic/datahouse/dcsf@15.10.25",
          "hashes": {
            "sha-256": "b7bdc84c464d09c21be037a176e813cb9bbc016f90f8b62b4ca7d5b2aed0d9d6"
          }
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The released Messenger removes the legacy reCAPTCHA verification and unblock command path. The former PHP challenge endpoint returns HTTP 403. The upstream request-URL shell injection path is absent. Authentic, unmodified release package and its managed templates. This does not attest to a particular server installation, residual administrator configuration, every vulnerability, or earlier DCSF releases.",
      "status_notes": "Fresh pinned-key signature, artifact digest and complete inventory verification, then SHA-256 comparison of all seven reviewed Messenger sources and Apache templates with the previously inspected advisory-specific source set. All seven files are byte-identical. Not a new live exploit test. Evidence: https://dcsf.net/security/messenger-assessment.json; upstream advisory: https://support.cpanel.net/hc/en-us/articles/43387915588375-Security-CVE-2026-65638-CSF-Security-Release"
    },
    {
      "vulnerability": {
        "name": "CVE-2026-67402",
        "@id": "https://www.cve.org/CVERecord?id=CVE-2026-67402"
      },
      "products": [
        {
          "@id": "pkg:generic/datahouse/dcsf@15.10.25",
          "hashes": {
            "sha-256": "b7bdc84c464d09c21be037a176e813cb9bbc016f90f8b62b4ca7d5b2aed0d9d6"
          }
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The packaged Apache HTTP and HTTPS templates do not map /usr/bin through ScriptAlias. They serve static GET/HEAD content, disable executable handlers and .htaccess overrides, and deny script extensions. Authentic, unmodified release package and its managed templates. This does not attest to a particular server installation, residual administrator configuration, every vulnerability, or earlier DCSF releases.",
      "status_notes": "Fresh pinned-key signature, artifact digest and complete inventory verification, then SHA-256 comparison of all seven reviewed Messenger sources and Apache templates with the previously inspected advisory-specific source set. All seven files are byte-identical. Not a new live exploit test. Evidence: https://dcsf.net/security/messenger-assessment.json; upstream advisory: https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026"
    }
  ]
}
