{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:OJGZ6XUGHEXQNYLJQHT2WT6TBR","short_pith_number":"pith:OJGZ6XUG","canonical_record":{"source":{"id":"2603.25997","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.SE","submitted_at":"2026-03-27T01:24:34Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"27bae9c17c6ff613c1da72d4475cc7cd1367e7d02ef8438875c7d3492394cac5","abstract_canon_sha256":"b742b0a38f2d4bdf57481cd7ecbd49d74181ccfb373237d670bf6e5caab64f2c"},"schema_version":"1.0"},"canonical_sha256":"724d9f5e86392f06e16981e7ab4fd30c507906f441a298d7d5f0214e518da843","source":{"kind":"arxiv","id":"2603.25997","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2603.25997","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"arxiv_version","alias_value":"2603.25997v2","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.25997","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"pith_short_12","alias_value":"OJGZ6XUGHEXQ","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"pith_short_16","alias_value":"OJGZ6XUGHEXQNYLJ","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"pith_short_8","alias_value":"OJGZ6XUG","created_at":"2026-07-31T01:33:23Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:OJGZ6XUGHEXQNYLJQHT2WT6TBR","target":"record","payload":{"canonical_record":{"source":{"id":"2603.25997","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.SE","submitted_at":"2026-03-27T01:24:34Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"27bae9c17c6ff613c1da72d4475cc7cd1367e7d02ef8438875c7d3492394cac5","abstract_canon_sha256":"b742b0a38f2d4bdf57481cd7ecbd49d74181ccfb373237d670bf6e5caab64f2c"},"schema_version":"1.0"},"canonical_sha256":"724d9f5e86392f06e16981e7ab4fd30c507906f441a298d7d5f0214e518da843","receipt":{"kind":"pith_receipt","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"724d9f5e86392f06e16981e7ab4fd30c507906f441a298d7d5f0214e518da843","last_reissued_at":"2026-07-31T01:33:23.429873Z","signature_status":"unsigned_v0","first_computed_at":"2026-07-31T01:33:23.429873Z"},"source_kind":"arxiv","source_id":"2603.25997","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-31T01:33:23Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iEMg70jF9wXyv7Q7vDo48lTEULf5wlCgONm8OTpQc07IqYTVU7ngV+hf38a85UJHWGC9o8UNaRXyrOfiJEQsDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T19:28:15.730108Z"},"content_sha256":"7af91015bf90dce437deb729a46db4ec43ec4fce57e40c707f8a6ae16ff7241b","schema_version":"1.0","event_id":"sha256:7af91015bf90dce437deb729a46db4ec43ec4fce57e40c707f8a6ae16ff7241b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:OJGZ6XUGHEXQNYLJQHT2WT6TBR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Assessing the Cross-Version Applicability of Java Library Vulnerability Exploits","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.SE","authors_text":"Jiayuan Zhou, Qi Zhan, Xiaohu Yang, Xing Hu, Xin Xia, Zirui Chen","submitted_at":"2026-03-27T01:24:34Z","abstract_excerpt":"Open-source software supply chain security relies heavily on assessing affected versions of library vulnerabilities. While prior studies have leveraged exploits for verifying vulnerability affected versions, they point out a key limitation that exploits are version-specific and cannot be directly applied across library versions. Despite being widely acknowledged, this limitation has not been systematically validated at scale, leaving the actual applicability of exploits across versions unexplored. To fill this gap, we conduct the first large-scale empirical study on exploit applicability acros"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.25997","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2603.25997/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-31T01:33:23Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3007km8/p3xfxhqtxBv5R7ynEgWTad34b1DGRx1vwYr5gz0iNgkQyD1tPMWe5oQCdBorraRzGuSPZ5SeP1l2Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T19:28:15.731197Z"},"content_sha256":"3ee3b9faf700f0e529da89638b6647bb5851521aeeba39ad161dcc067b68ee03","schema_version":"1.0","event_id":"sha256:3ee3b9faf700f0e529da89638b6647bb5851521aeeba39ad161dcc067b68ee03"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR/bundle.json","state_url":"https://pith.science/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-04T19:28:15Z","links":{"resolver":"https://pith.science/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR","bundle":"https://pith.science/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR/bundle.json","state":"https://pith.science/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/OJGZ6XUGHEXQNYLJQHT2WT6TBR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:OJGZ6XUGHEXQNYLJQHT2WT6TBR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b742b0a38f2d4bdf57481cd7ecbd49d74181ccfb373237d670bf6e5caab64f2c","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.SE","submitted_at":"2026-03-27T01:24:34Z","title_canon_sha256":"27bae9c17c6ff613c1da72d4475cc7cd1367e7d02ef8438875c7d3492394cac5"},"schema_version":"1.0","source":{"id":"2603.25997","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2603.25997","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"arxiv_version","alias_value":"2603.25997v2","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.25997","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"pith_short_12","alias_value":"OJGZ6XUGHEXQ","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"pith_short_16","alias_value":"OJGZ6XUGHEXQNYLJ","created_at":"2026-07-31T01:33:23Z"},{"alias_kind":"pith_short_8","alias_value":"OJGZ6XUG","created_at":"2026-07-31T01:33:23Z"}],"graph_snapshots":[{"event_id":"sha256:3ee3b9faf700f0e529da89638b6647bb5851521aeeba39ad161dcc067b68ee03","target":"graph","created_at":"2026-07-31T01:33:23Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2603.25997/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Open-source software supply chain security relies heavily on assessing affected versions of library vulnerabilities. While prior studies have leveraged exploits for verifying vulnerability affected versions, they point out a key limitation that exploits are version-specific and cannot be directly applied across library versions. Despite being widely acknowledged, this limitation has not been systematically validated at scale, leaving the actual applicability of exploits across versions unexplored. To fill this gap, we conduct the first large-scale empirical study on exploit applicability acros","authors_text":"Jiayuan Zhou, Qi Zhan, Xiaohu Yang, Xing Hu, Xin Xia, Zirui Chen","cross_cats":["cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.SE","submitted_at":"2026-03-27T01:24:34Z","title":"Assessing the Cross-Version Applicability of Java Library Vulnerability Exploits"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.25997","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7af91015bf90dce437deb729a46db4ec43ec4fce57e40c707f8a6ae16ff7241b","target":"record","created_at":"2026-07-31T01:33:23Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b742b0a38f2d4bdf57481cd7ecbd49d74181ccfb373237d670bf6e5caab64f2c","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.SE","submitted_at":"2026-03-27T01:24:34Z","title_canon_sha256":"27bae9c17c6ff613c1da72d4475cc7cd1367e7d02ef8438875c7d3492394cac5"},"schema_version":"1.0","source":{"id":"2603.25997","kind":"arxiv","version":2}},"canonical_sha256":"724d9f5e86392f06e16981e7ab4fd30c507906f441a298d7d5f0214e518da843","receipt":{"builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"724d9f5e86392f06e16981e7ab4fd30c507906f441a298d7d5f0214e518da843","first_computed_at":"2026-07-31T01:33:23.429873Z","kind":"pith_receipt","last_reissued_at":"2026-07-31T01:33:23.429873Z","receipt_version":"0.3","signature_status":"unsigned_v0"},"source_id":"2603.25997","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7af91015bf90dce437deb729a46db4ec43ec4fce57e40c707f8a6ae16ff7241b","sha256:3ee3b9faf700f0e529da89638b6647bb5851521aeeba39ad161dcc067b68ee03"],"state_sha256":"8aab2ecc4e53ff04aede1f7255957a33fffac78a01fbf8ac8e6d66625e363767"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"95M3TcEFA3xZMrPxQR1zanlOoEodKQPnvcRcHVYEqfSUaje2T3QnAI5IRFxQm54nDcHwV8w4HK+sXC/AvSeWDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-04T19:28:15.773741Z","bundle_sha256":"20f1c68e90de604c04ce852e3a4f97af1fb868dd71fd432927e4e59d25a6cd4b"}}