{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "CVE-2026-11856",
   "severity": "critical",
   "distro_severity": "medium",
   "fix_state": "wont-fix",
   "fixed_in": [],
   "cvss": 9.8,
   "affects": [
    "curl"
   ],
   "title": "Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-11856"
  },
  {
   "id": "CVE-2026-66032",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 8.7,
   "affects": [
    "libssh2"
   ],
   "title": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session.",
   "url": "https://ubuntu.com/security/CVE-2026-66032"
  },
  {
   "id": "CVE-2026-66033",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 8.7,
   "affects": [
    "libssh2"
   ],
   "title": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66033"
  },
  {
   "id": "CVE-2026-11979",
   "severity": "high",
   "distro_severity": "negligible",
   "fix_state": "wont-fix",
   "fixed_in": [],
   "cvss": 7.8,
   "affects": [
    "libxml2"
   ],
   "title": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.",
   "url": "https://ubuntu.com/security/CVE-2026-11979"
  },
  {
   "id": "CVE-2026-66034",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.7,
   "affects": [
    "libssh2"
   ],
   "title": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66034"
  },
  {
   "id": "CVE-2026-66035",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.7,
   "affects": [
    "libssh2"
   ],
   "title": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66035"
  },
  {
   "id": "CVE-2026-14456",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "id": "CVE-2026-54876",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.",
   "url": "https://ubuntu.com/security/CVE-2026-54876"
  },
  {
   "id": "CVE-2026-8932",
   "severity": "high",
   "distro_severity": "low",
   "fix_state": "wont-fix",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "curl"
   ],
   "title": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.",
   "url": "https://ubuntu.com/security/CVE-2026-8932"
  },
  {
   "id": "CVE-2026-13757",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.2,
   "affects": [
    "p11-kit"
   ],
   "title": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-13757"
  },
  {
   "id": "CVE-2026-18938",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.2,
   "affects": [
    "p11-kit"
   ],
   "title": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability.",
   "url": "https://ubuntu.com/security/CVE-2026-18938"
  }
 ],
 "severity_counts": {
  "critical": 1,
  "high": 8,
  "medium": 2,
  "low": 0,
  "unknown": 0
 },
 "suppressed": [
  {
   "id": "CVE-2026-27171",
   "affects": [
    "zlib"
   ],
   "by": "vex"
  },
  {
   "id": "CVE-2026-42250",
   "affects": [
    "bzip2"
   ],
   "by": "vex"
  }
 ]
}
