{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "amd64",
 "findings": [
  {
   "id": "CVE-2026-14456",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "id": "CVE-2026-54370",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.2,
   "affects": [
    "acl"
   ],
   "title": "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-54370"
  },
  {
   "id": "CVE-2026-54369",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.1,
   "affects": [
    "acl"
   ],
   "title": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-54369"
  },
  {
   "id": "CVE-2026-56391",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.6,
   "affects": [
    "coreutils"
   ],
   "title": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used.",
   "url": "https://ubuntu.com/security/CVE-2026-56391"
  },
  {
   "id": "CVE-2025-5278",
   "severity": "medium",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.4,
   "affects": [
    "coreutils"
   ],
   "title": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key\u2026",
   "url": "https://ubuntu.com/security/CVE-2025-5278"
  },
  {
   "id": "CVE-2026-56392",
   "severity": "low",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 1.8,
   "affects": [
    "coreutils"
   ],
   "title": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values.",
   "url": "https://ubuntu.com/security/CVE-2026-56392"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 3,
  "medium": 2,
  "low": 1,
  "unknown": 0
 },
 "suppressed": [
  {
   "id": "CVE-2026-27171",
   "affects": [
    "zlib"
   ],
   "by": "vex"
  },
  {
   "id": "CVE-2026-54371",
   "affects": [
    "attr"
   ],
   "by": "vex"
  },
  {
   "id": "CVE-2026-54876",
   "affects": [
    "openssl"
   ],
   "by": "vex"
  }
 ]
}
