Skip to content

CVE-2026-22028 Significant scoring difference between GHSA<>NVD #6841

Description

@noren95

Hello,

I am a vulnerability data analyst, and I have observed a significant difference in the CVSS scores of GHSA-36hm-qxxp-pg3m/CVE-2026-22028.
Score by NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Score by GHSA: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U

According to the description, component is vulnerable based on the following conditions:
1. Pass unmodified, unsanitized values from user-modifiable data sources (APIs, databases, local storage, etc.) directly into the render tree >> indicates a user action (implies UI:R)

The additional notes in the description imply that the affected scope is quite limited, which could reduce the general impact of the vulnerability - (makes more sense in the IMPACT metrics)

Since scoring could rely on different assessment approaches, this raises various questions and confusion among development teams - could you please provide a reasonable explanation on your end for this score assignment?

References
https://nvd.nist.gov/vuln/detail/CVE-2026-22028
GHSA-36hm-qxxp-pg3m

Thanks in advance!

Activity

  1. shelbyc commented on Feb 17, 2026

    @shelbyc
    Contributor

    Hi @noren95, I tried rescoring based on my own re-reading of GHSA-36hm-qxxp-pg3m with your observations in mind. Here's what I got:
    https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

    What do you think of this score?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions