{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "amd64",
 "findings": [
  {
   "id": "CVE-2023-7216",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.3,
   "affects": [
    "cpio"
   ],
   "title": "A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive.",
   "url": "https://ubuntu.com/security/CVE-2023-7216"
  },
  {
   "id": "CVE-2026-66484",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.6,
   "affects": [
    "cpio"
   ],
   "title": "GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66484"
  },
  {
   "id": "CVE-2026-66485",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.6,
   "affects": [
    "cpio"
   ],
   "title": "GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66485"
  },
  {
   "id": "CVE-2026-66486",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.6,
   "affects": [
    "cpio"
   ],
   "title": "GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping.",
   "url": "https://ubuntu.com/security/CVE-2026-66486"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "medium": 4,
  "low": 0,
  "unknown": 0
 },
 "suppressed": []
}
