{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "CVE-2026-14456",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "id": "CVE-2026-55655",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.1,
   "affects": [
    "openssh"
   ],
   "title": "A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.",
   "url": "https://ubuntu.com/security/CVE-2026-55655"
  },
  {
   "id": "CVE-2026-73282",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.8,
   "affects": [
    "openssh"
   ],
   "title": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
   "url": "https://ubuntu.com/security/CVE-2026-73282"
  },
  {
   "id": "CVE-2026-55654",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 3.7,
   "affects": [
    "openssh"
   ],
   "title": "A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-55654"
  },
  {
   "id": "CVE-2026-73281",
   "severity": "low",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 3.5,
   "affects": [
    "openssh"
   ],
   "title": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.",
   "url": "https://ubuntu.com/security/CVE-2026-73281"
  },
  {
   "id": "CVE-2026-73283",
   "severity": "low",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 2.5,
   "affects": [
    "openssh"
   ],
   "title": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
   "url": "https://ubuntu.com/security/CVE-2026-73283"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 1,
  "medium": 2,
  "low": 3,
  "unknown": 0
 },
 "suppressed": [
  {
   "id": "CVE-2026-27171",
   "affects": [
    "zlib"
   ],
   "by": "vex"
  },
  {
   "id": "CVE-2026-54876",
   "affects": [
    "openssl"
   ],
   "by": "vex"
  }
 ]
}
