{
  "metadata": {
    "@context": "https://openvex.dev/ns/v0.2.0",
    "@id": "https://packages.broadcom.com/photon/photon_cve_metadata/cve/2025/CVE-2025-26467",
    "author": "VMware Photon OS",
    "timestamp": "2026-08-20T05:10:54.125080",
    "version": 1
  },
  "statements": [
    {
      "vulnerability": {
        "@id": "https://nvd.nist.gov/vuln/detail/CVE-2025-26467",
        "name": "CVE-2025-26467"
      },
      "products": [
        {
          "@id": "pkg:rpm/photon/cassandra?arch=x86_64&photon=ph5"
        },
        {
          "@id": "pkg:rpm/photon/cassandra?arch=aarch64&photon=ph5"
        }
      ],
      "status": "not_affected",
      "status_notes": "Advisory is scoped only to Apache Cassandra 4.0.16, where the CASSANDRA-20090 fix was incorrectly merged (a \"bad merge\"). Photon ships 4.0.10, which never received that fix at all; when patched it go"
    },
    {
      "vulnerability": {
        "@id": "https://nvd.nist.gov/vuln/detail/CVE-2025-26467",
        "name": "CVE-2025-26467"
      },
      "products": [
        {
          "@id": "pkg:rpm/photon/cassandra?arch=x86_64&photon=ph5"
        },
        {
          "@id": "pkg:rpm/photon/cassandra?arch=aarch64&photon=ph5"
        }
      ],
      "status": "under_investigation"
    }
  ]
}