{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "setuptools"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "78.1.1"
   ],
   "id": "GHSA-5rjg-fvgr-3xxf",
   "severity": "high",
   "title": "setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write",
   "url": "https://github.com/advisories/GHSA-5rjg-fvgr-3xxf"
  },
  {
   "affects": [
    "msgpack"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.2.1"
   ],
   "id": "GHSA-6v7p-g79w-8964",
   "severity": "high",
   "title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error",
   "url": "https://github.com/advisories/GHSA-6v7p-g79w-8964"
  },
  {
   "affects": [
    "setuptools"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "83.0.0"
   ],
   "id": "GHSA-h35f-9h28-mq5c",
   "severity": "medium",
   "title": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+",
   "url": "https://github.com/advisories/GHSA-h35f-9h28-mq5c"
  }
 ],
 "findings_changed_at": "2026-08-23T22:37:06Z",
 "image": "pip",
 "inputs": {
  "sbom_sha256": "f72115d886b3c2999c1cd650b3fc008b63f73a915b33e27ae469674891454cff"
 },
 "platform_digest": "sha256:fdada6be065ff934f892667ad98e20fefdca57ded8144a63acc50dc8adb8aca8",
 "project": "pip",
 "receipt_sha256": "10a43602f4fe82bf4f182593b32e8cc7d3ecb027723c7a6175aedaa7788603fa",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 2,
  "low": 0,
  "medium": 1,
  "unknown": 0
 },
 "suppressed": [],
 "version": "26.2.1",
 "vex_applied": [
  "pip-26.2.1-amd64.vex.json",
  "pip-26.2.1-amd64.ubuntu-vex.json"
 ]
}
