{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "GHSA-mwp4-54f8-5fhr",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "10.3.1"
   ],
   "cvss": 7.7,
   "affects": [
    "ip-address"
   ],
   "title": "ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
   "url": "https://github.com/advisories/GHSA-mwp4-54f8-5fhr"
  },
  {
   "id": "GHSA-mh99-v99m-4gvg",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.0.8"
   ],
   "cvss": 7.5,
   "affects": [
    "brace-expansion"
   ],
   "title": "brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
   "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg"
  },
  {
   "id": "GHSA-rgw5-rvv9-x895",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.0.9"
   ],
   "cvss": 7.5,
   "affects": [
    "brace-expansion"
   ],
   "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
   "url": "https://github.com/advisories/GHSA-rgw5-rvv9-x895"
  },
  {
   "id": "GHSA-22jq-vg5j-6vgg",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "10.2.1"
   ],
   "cvss": 6.9,
   "affects": [
    "ip-address"
   ],
   "title": "ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks",
   "url": "https://github.com/advisories/GHSA-22jq-vg5j-6vgg"
  },
  {
   "id": "GHSA-4xrf-jv44-h6hh",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "10.2.2"
   ],
   "cvss": 6.9,
   "affects": [
    "ip-address"
   ],
   "title": "ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks",
   "url": "https://github.com/advisories/GHSA-4xrf-jv44-h6hh"
  },
  {
   "id": "GHSA-r292-9mhp-454m",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.21"
   ],
   "cvss": 5.3,
   "affects": [
    "tar"
   ],
   "title": "node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection",
   "url": "https://github.com/advisories/GHSA-r292-9mhp-454m"
  },
  {
   "id": "GHSA-8xcm-r25x-g524",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "cvss": 4.8,
   "affects": [
    "undici"
   ],
   "title": "undici vulnerable to downstream response desynchronization via retry interceptor",
   "url": "https://github.com/advisories/GHSA-8xcm-r25x-g524"
  },
  {
   "id": "GHSA-v3r7-h72x-cjcm",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "cvss": 4.8,
   "affects": [
    "undici"
   ],
   "title": "undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields",
   "url": "https://github.com/advisories/GHSA-v3r7-h72x-cjcm"
  },
  {
   "id": "GHSA-m8rv-5g2x-5cg5",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "cvss": 4.2,
   "affects": [
    "undici"
   ],
   "title": "undici vulnerable to CRLF Injection via blob-like body 'type' property",
   "url": "https://github.com/advisories/GHSA-m8rv-5g2x-5cg5"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 3,
  "medium": 6,
  "low": 0,
  "unknown": 0
 },
 "suppressed": []
}
