I'm not quite sure why we're getting this out of Repology's database dump:
[glib-networking]
cpes = ["gnome:glib", "gnome:glib-networking"]
url_patterns = #...
On their site, they only show vulns for the (correct) latter CPE. Maybe there's an ignore flag or something that we're missing.
https://repology.org/project/glib-networking/cves