Sample record with placeholder names and timings. Real records carry real names, real hashes and a signature you can verify.

Download the PDF
Backportal
patch record · rec_2026-09-07_example_acme · sample
✓ signed
2026-09-07 11:02:45Z

CVE-XXXX-XXXXX on acme: notified, verified, patched and proven in 2 h 00

An authorization flaw in a self-hosted open-source tool. High, CVSS 8.1. Fixed upstream in 1.7.5 and 1.8.1. Upgrading remediates. Source: the upstream maintainers' advisory, GHSA and NVD. The flaw and the fix are theirs; the verdicts, the backport, the hunt and this record are Backportal's.

3
instances declared
2
affected and patched
0
indicators of exploitation
2 h 00
time to patch

Verdict per instance

InstanceVersionExposure contextVerdictAction
app-eu-11.6.9internet-facing, feature enabledaffectedpatched at 10:40Z
app-us-11.6.9internet-facing, feature enabledaffectedpatched at 10:40Z
app-internal1.7.5internal, feature disabledfixednone

Timeline

Time (UTC)StepWhat happened
2026-09-07 09:02:11ZNotifyAdvisory CVE-XXXX-XXXXX matched declared stack: example tool on 3 instances.
2026-09-07 09:05:40ZAssess2 instances affected (1.6.9). 1 not affected: 1.7.5 includes the fix, and the vulnerable feature is disabled there.
2026-09-07 09:11:02ZVerifyExploitability check confirmed the vulnerable condition reachable on app-eu-1 and app-us-1. No attack performed.
2026-09-07 10:40:27ZPatchUpstream fix commits backported onto fork acme/example-tool line 1.6. Build, upstream suite and CVE regression test passed. Merge request !412 merged.
2026-09-07 10:58:13ZHuntHunt queries run on 30 days of logs and application state on both affected instances. No indicators of exploitation.
2026-09-07 11:02:45ZProveRecord signed. OpenVEX statements published for 3 instances. Time to patch: 2 h 00 from advisory match.
page 1 of 2 · backportal.dev/report/sample

Evidence

Advisory
CVE-XXXX-XXXXX · upstream advisory, GHSA and NVD records linked · published T+0 · backportal.dev/cve/example-tool/cve-xxxx-xxxxx
Detection check
checks/example-tool/cve-xxxx-xxxxx/detect.sh · sha256 (recorded at run time) · run on 3 instances, level one, runner v0.3.1
Exploitability check
checks/example-tool/cve-xxxx-xxxxx/verify.sh · confirmed reachable on app-eu-1, app-us-1 · not run on app-internal (not affected) · no attack performed
Patch
The two upstream fix commits, credited to their authors, backported onto acme/example-tool line 1.6 · build passed · upstream suite passed · CVE regression test passed · merge request !412
Hunt
hunt/example-tool/cve-xxxx-xxxxx/*.sql · 30 days of logs and application state · 0 indicators of exploitation matched
VEX
3 OpenVEX statements: app-eu-1 fixed (patched), app-us-1 fixed (patched), app-internal not affected, justification vulnerable_code_not_in_execute_path

Signature

Signed by
acme runner key ed25519:…(sample) and Backportal ed25519:…(sample)
Record digest
sha256:(computed at signing time, sample)
Verify
backportal verify rec_2026-09-07_example_acme.json

Sources