{"id":"ECHO-f83a-f1a3-51c1","upstream":["CVE-2026-19582"],"severity":[],"modified":"2026-08-31T14:30:19.360Z","affected":[{"package":{"ecosystem":"Echo","name":"binutils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.45.90.20260201+really2.45.50.20251201-1+e9"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-19582"}],"withdrawn":"2026-08-31T14:30:19.360Z","summary":"The CVE has been rejected by the assigning CNA (Red Hat, CVSS 0.0): per\nupstream security policy binutils treats its input as trusted, so no\nsecurity boundary is crossed. No fix exists upstream or in any Debian suite.\n"}