{
 "scanner": "grype",
 "at": "2026-08-20T12:12:55Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "GHSA-xp3w-r5p5-63rr",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.79"
   ],
   "cvss": 8.7,
   "affects": [
    "openssl"
   ],
   "title": "rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs",
   "url": "https://github.com/advisories/GHSA-xp3w-r5p5-63rr"
  },
  {
   "id": "GHSA-xphw-cqx3-667j",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.2.16"
   ],
   "cvss": 7.3,
   "affects": [
    "thin-vec"
   ],
   "title": "thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics",
   "url": "https://github.com/advisories/GHSA-xphw-cqx3-667j"
  },
  {
   "id": "GHSA-vfvv-c25p-m7mm",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.8.16"
   ],
   "cvss": 6.9,
   "affects": [
    "rkyv"
   ],
   "title": "rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution",
   "url": "https://github.com/advisories/GHSA-vfvv-c25p-m7mm"
  },
  {
   "id": "GHSA-3rjw-m598-pq24",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.4"
   ],
   "cvss": 5.5,
   "affects": [
    "cmov"
   ],
   "title": "Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set",
   "url": "https://github.com/advisories/GHSA-3rjw-m598-pq24"
  },
  {
   "id": "GHSA-phqj-4mhp-q6mq",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.80"
   ],
   "cvss": 5.1,
   "affects": [
    "openssl"
   ],
   "title": "rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers",
   "url": "https://github.com/advisories/GHSA-phqj-4mhp-q6mq"
  },
  {
   "id": "GHSA-xv59-967r-8726",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.79"
   ],
   "cvss": 5.1,
   "affects": [
    "openssl"
   ],
   "title": "rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding",
   "url": "https://github.com/advisories/GHSA-xv59-967r-8726"
  },
  {
   "id": "GHSA-j39j-6gw9-jw6h",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.20.4"
   ],
   "cvss": 2.7,
   "affects": [
    "git2"
   ],
   "title": "git2 has potential undefined behavior when dereferencing Buf struct",
   "url": "https://github.com/advisories/GHSA-j39j-6gw9-jw6h"
  },
  {
   "id": "GHSA-xwfj-jgwm-7wp5",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.3.20"
   ],
   "cvss": 2.3,
   "affects": [
    "tracing-subscriber"
   ],
   "title": "Tracing logging user input may result in poisoning logs with ANSI escape sequences",
   "url": "https://github.com/advisories/GHSA-xwfj-jgwm-7wp5"
  },
  {
   "id": "GHSA-3pv8-6f4r-ffg2",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.4.46"
   ],
   "cvss": null,
   "affects": [
    "tar"
   ],
   "title": "tar has a PAX header desynchronization issue",
   "url": "https://github.com/advisories/GHSA-3pv8-6f4r-ffg2"
  },
  {
   "id": "GHSA-cq8v-f236-94qc",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.8.6"
   ],
   "cvss": null,
   "affects": [
    "rand"
   ],
   "title": "Rand is unsound with a custom logger using rand::rng()",
   "url": "https://github.com/advisories/GHSA-cq8v-f236-94qc"
  },
  {
   "id": "GHSA-cq8v-f236-94qc",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.9.3"
   ],
   "cvss": null,
   "affects": [
    "rand"
   ],
   "title": "Rand is unsound with a custom logger using rand::rng()",
   "url": "https://github.com/advisories/GHSA-cq8v-f236-94qc"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 2,
  "medium": 5,
  "low": 4,
  "unknown": 0
 },
 "suppressed": [
  {
   "id": "CVE-2026-27171",
   "affects": [
    "zlib"
   ],
   "by": "vex"
  }
 ]
}
