CHW-2002 VulnerabilityBlocked

package blocked because it contains a known vulnerability at or above the configured severity threshold; upgrade the package or lower the threshold

Default message: package blocked because it contains a known vulnerability at or above the configured severity threshold; upgrade the package or lower the threshold
HTTP status: 403 (client)
Reason: VULNERABILITY_DETECTED

Problem. The requested package contains one or more known vulnerabilities at or above the repository’s configured severity floor. Cause. The vulnerability database (Trivy DB / OSV feeds) returned a finding for this coordinate that meets the block threshold. Fix. Upgrade to a patched version, add an exception for this CVE in the vulnerability-override table, or lower the severity threshold for the repository. HTTP 403.