Skip to content

[FP]: CVE-2026-54133 is for PHP, not Java #8617

Description

@marcelstoer

Package URl

pkg:maven/com.amazonaws/jmespath-java@1.11.277

CPE

cpe:2.3:a:jmespath:jmespath:1.11.277:*:*:*:*:*:*:*

CVE

CVE-2026-54133

ODC Integration

None

ODC Version

12.2.2

Description

The NVD has a correct CPE for the affected package: cpe:2.3:a:jmespath:jmespath:*:*:*:*:*:php:*:* (< 2.9.1). We match this against a Java package.

Related to #7139.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions