{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "hickory-proto"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "GHSA-3v94-mw7p-v465",
   "severity": "high",
   "title": "hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses",
   "url": "https://github.com/advisories/GHSA-3v94-mw7p-v465"
  },
  {
   "affects": [
    "gix-pack"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.69.0"
   ],
   "id": "GHSA-x494-mj8g-cj27",
   "severity": "high",
   "title": "gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data",
   "url": "https://github.com/advisories/GHSA-x494-mj8g-cj27"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.79"
   ],
   "id": "GHSA-xp3w-r5p5-63rr",
   "severity": "high",
   "title": "rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs",
   "url": "https://github.com/advisories/GHSA-xp3w-r5p5-63rr"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 8.3,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.78"
   ],
   "id": "GHSA-hppc-g8h3-xhp3",
   "severity": "high",
   "title": "rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer",
   "url": "https://github.com/advisories/GHSA-hppc-g8h3-xhp3"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 8.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.78"
   ],
   "id": "GHSA-ghm9-cr32-g9qj",
   "severity": "high",
   "title": "rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check",
   "url": "https://github.com/advisories/GHSA-ghm9-cr32-g9qj"
  },
  {
   "affects": [
    "gix"
   ],
   "cvss": 7.8,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.83.0"
   ],
   "id": "GHSA-f26g-jm89-4g65",
   "severity": "high",
   "title": "gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules",
   "url": "https://github.com/advisories/GHSA-f26g-jm89-4g65"
  },
  {
   "affects": [
    "gix-fs"
   ],
   "cvss": 7.8,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.21.1"
   ],
   "id": "GHSA-f89h-2fjh-2r9q",
   "severity": "high",
   "title": "gix-fs: Symlink prefix-reuse allows worktree escape during checkout",
   "url": "https://github.com/advisories/GHSA-f89h-2fjh-2r9q"
  },
  {
   "affects": [
    "gix"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.83.0"
   ],
   "id": "GHSA-fr8x-3vfx-f45h",
   "severity": "high",
   "title": "gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository",
   "url": "https://github.com/advisories/GHSA-fr8x-3vfx-f45h"
  },
  {
   "affects": [
    "gix"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.83.0"
   ],
   "id": "GHSA-pg4w-g64p-qwhj",
   "severity": "high",
   "title": "gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository",
   "url": "https://github.com/advisories/GHSA-pg4w-g64p-qwhj"
  },
  {
   "affects": [
    "quinn-proto"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.11.15"
   ],
   "id": "GHSA-4w2j-m93h-cj5j",
   "severity": "high",
   "title": "Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly",
   "url": "https://github.com/advisories/GHSA-4w2j-m93h-cj5j"
  },
  {
   "affects": [
    "gix"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.83.0"
   ],
   "id": "GHSA-p3hw-mv63-rf9w",
   "severity": "high",
   "title": "gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure",
   "url": "https://github.com/advisories/GHSA-p3hw-mv63-rf9w"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.78"
   ],
   "id": "GHSA-8c75-8mhr-p7r9",
   "severity": "high",
   "title": "rust-openssl has incorrect bounds assertion in aes key wrap",
   "url": "https://github.com/advisories/GHSA-8c75-8mhr-p7r9"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.78"
   ],
   "id": "GHSA-pqf5-4pqq-29f5",
   "severity": "high",
   "title": "rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1",
   "url": "https://github.com/advisories/GHSA-pqf5-4pqq-29f5"
  },
  {
   "affects": [
    "hickory-proto"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.26.1"
   ],
   "id": "GHSA-q2qq-hmj6-3wpp",
   "severity": "medium",
   "title": "hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n\u00b2) name compression",
   "url": "https://github.com/advisories/GHSA-q2qq-hmj6-3wpp"
  },
  {
   "affects": [
    "actix-http"
   ],
   "cvss": 6.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.12.1"
   ],
   "id": "GHSA-xhj4-vrgc-hr34",
   "severity": "medium",
   "title": "actix-http has HTTP/1.1 CL.TE Request Smuggling",
   "url": "https://github.com/advisories/GHSA-xhj4-vrgc-hr34"
  },
  {
   "affects": [
    "cmov"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.4"
   ],
   "id": "GHSA-3rjw-m598-pq24",
   "severity": "medium",
   "title": "Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set",
   "url": "https://github.com/advisories/GHSA-3rjw-m598-pq24"
  },
  {
   "affects": [
    "jsonwebtoken"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "10.3.0"
   ],
   "id": "GHSA-h395-gr6q-cpjc",
   "severity": "medium",
   "title": "jsonwebtoken has Type Confusion that leads to potential authorization bypass",
   "url": "https://github.com/advisories/GHSA-h395-gr6q-cpjc"
  },
  {
   "affects": [
    "opentelemetry_sdk"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.32.1"
   ],
   "id": "GHSA-w9wp-h8wv-79jx",
   "severity": "medium",
   "title": "opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation",
   "url": "https://github.com/advisories/GHSA-w9wp-h8wv-79jx"
  },
  {
   "affects": [
    "serde_with"
   ],
   "cvss": 5.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.21.0"
   ],
   "id": "GHSA-7gcf-g7xr-8hxj",
   "severity": "medium",
   "title": "serde_with: KeyValueMap serialization panics on empty sequence or map entries",
   "url": "https://github.com/advisories/GHSA-7gcf-g7xr-8hxj"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 5.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.80"
   ],
   "id": "GHSA-phqj-4mhp-q6mq",
   "severity": "medium",
   "title": "rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers",
   "url": "https://github.com/advisories/GHSA-phqj-4mhp-q6mq"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 5.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.79"
   ],
   "id": "GHSA-xv59-967r-8726",
   "severity": "medium",
   "title": "rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding",
   "url": "https://github.com/advisories/GHSA-xv59-967r-8726"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 1.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.10.78"
   ],
   "id": "GHSA-xmgf-hq76-4vx2",
   "severity": "low",
   "title": "rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length",
   "url": "https://github.com/advisories/GHSA-xmgf-hq76-4vx2"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": null,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.4.46"
   ],
   "id": "GHSA-3pv8-6f4r-ffg2",
   "severity": "medium",
   "title": "tar has a PAX header desynchronization issue",
   "url": "https://github.com/advisories/GHSA-3pv8-6f4r-ffg2"
  }
 ],
 "findings_changed_at": "2026-08-25T15:06:51Z",
 "image": "codex",
 "inputs": {
  "sbom_sha256": "842d5deba226a5d9096b5b6b0427ddd894250eb747ceb3b4126382aa391e699a"
 },
 "platform_digest": "sha256:70960c88c641a8da16ab98d66ebfb6c4d7d011934bd5dfc877dd20f1d819a10e",
 "project": "codex",
 "receipt_sha256": "cd082f0941b4cd39f86b42065597a15f7b69bf37586a5422f75acc3bb2d32c3b",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 13,
  "low": 1,
  "medium": 9,
  "unknown": 0
 },
 "suppressed": [],
 "version": "0.149.1",
 "vex_applied": [
  "codex-0.149.1-arm64.vex.json",
  "codex-0.149.1-arm64.ubuntu-vex.json"
 ]
}
