{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "tar"
   ],
   "cvss": 8.8,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.4"
   ],
   "id": "GHSA-r6q2-hw4h-h46w",
   "severity": "high",
   "title": "Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS",
   "url": "https://github.com/advisories/GHSA-r6q2-hw4h-h46w"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 8.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.7"
   ],
   "id": "GHSA-34x7-hfp2-rc4v",
   "severity": "high",
   "title": "node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
   "url": "https://github.com/advisories/GHSA-34x7-hfp2-rc4v"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 8.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.3"
   ],
   "id": "GHSA-8qq5-rm4j-mr97",
   "severity": "high",
   "title": "node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization",
   "url": "https://github.com/advisories/GHSA-8qq5-rm4j-mr97"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 8.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.11"
   ],
   "id": "GHSA-9ppj-qmqm-q256",
   "severity": "high",
   "title": "node-tar Symlink Path Traversal via Drive-Relative Linkpath",
   "url": "https://github.com/advisories/GHSA-9ppj-qmqm-q256"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 8.2,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.10"
   ],
   "id": "GHSA-qffp-2rhf-9h96",
   "severity": "high",
   "title": "tar has Hardlink Path Traversal via Drive-Relative Linkpath",
   "url": "https://github.com/advisories/GHSA-qffp-2rhf-9h96"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.5,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.19"
   ],
   "id": "GHSA-23hp-3jrh-7fpw",
   "severity": "high",
   "title": "node-tar: Decompression/parse DoS via unlimited input",
   "url": "https://github.com/advisories/GHSA-23hp-3jrh-7fpw"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.18"
   ],
   "id": "GHSA-8x88-c5mf-7j5w",
   "severity": "high",
   "title": "node-tar: Negative tar entry size causes infinite loop in archive replace",
   "url": "https://github.com/advisories/GHSA-8x88-c5mf-7j5w"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.21"
   ],
   "id": "GHSA-r292-9mhp-454m",
   "severity": "high",
   "title": "node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection",
   "url": "https://github.com/advisories/GHSA-r292-9mhp-454m"
  },
  {
   "affects": [
    "adm-zip"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.6.0"
   ],
   "id": "GHSA-xcpc-8h2w-3j85",
   "severity": "high",
   "title": "adm-zip: Crafted ZIP file triggers 4GB memory allocation",
   "url": "https://github.com/advisories/GHSA-xcpc-8h2w-3j85"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.8"
   ],
   "id": "GHSA-83g3-92jg-28cx",
   "severity": "high",
   "title": "Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction",
   "url": "https://github.com/advisories/GHSA-83g3-92jg-28cx"
  },
  {
   "affects": [
    "sharp"
   ],
   "cvss": 7.0,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "0.35.0"
   ],
   "id": "GHSA-f88m-g3jw-g9cj",
   "severity": "high",
   "title": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591",
   "url": "https://github.com/advisories/GHSA-f88m-g3jw-g9cj"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.16"
   ],
   "id": "GHSA-vmf3-w455-68vh",
   "severity": "medium",
   "title": "node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
   "url": "https://github.com/advisories/GHSA-vmf3-w455-68vh"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.17"
   ],
   "id": "GHSA-gvwx-54wh-qm9j",
   "severity": "medium",
   "title": "node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records",
   "url": "https://github.com/advisories/GHSA-gvwx-54wh-qm9j"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.18"
   ],
   "id": "GHSA-w8wr-v893-vjvp",
   "severity": "medium",
   "title": "node-tar: Process crash via PAX numeric path type confusion",
   "url": "https://github.com/advisories/GHSA-w8wr-v893-vjvp"
  }
 ],
 "findings_changed_at": "2026-08-25T14:52:54Z",
 "image": "omp",
 "inputs": {
  "sbom_sha256": "bd921ed463421e4a67f3f3a75d3d895004260dfdd05f2ecbfed6d2aab61d8df5"
 },
 "platform_digest": "sha256:c4440480f25d7cf68967054d16a3f4b881fda6cf89ee5f36afd3294e3d5be6ce",
 "project": "omp",
 "receipt_sha256": "41b40a63bf56a717cef29a7674e1ec41e5295cda8c26b8abb6fdca7b4ca444e0",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 11,
  "low": 0,
  "medium": 3,
  "unknown": 0
 },
 "suppressed": [],
 "version": "18.0.4",
 "vex_applied": [
  "omp-18.0.4-arm64.vex.json",
  "omp-18.0.4-arm64.ubuntu-vex.json"
 ]
}
