{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "CVE-2026-14456",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "id": "CVE-2026-3644",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.13",
    "3.14.4",
    "3.15.0a8"
   ],
   "cvss": 7.5,
   "affects": [
    "python"
   ],
   "title": "The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3644"
  },
  {
   "id": "CVE-2026-41080",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
   "url": "https://ubuntu.com/security/CVE-2026-41080"
  },
  {
   "id": "CVE-2026-4224",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.13",
    "3.14.4",
    "3.15.0a8"
   ],
   "cvss": 7.5,
   "affects": [
    "python"
   ],
   "title": "When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4224"
  },
  {
   "id": "CVE-2026-45186",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "expat"
   ],
   "title": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
   "url": "https://ubuntu.com/security/CVE-2026-45186"
  },
  {
   "id": "CVE-2026-54876",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.",
   "url": "https://ubuntu.com/security/CVE-2026-54876"
  },
  {
   "id": "CVE-2026-7210",
   "severity": "high",
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.14",
    "3.14.6",
    "3.15.0b2"
   ],
   "cvss": 7.5,
   "affects": [
    "python"
   ],
   "title": "`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating\u2026",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
  },
  {
   "id": "CVE-2026-56132",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
   "url": "https://ubuntu.com/security/CVE-2026-56132"
  },
  {
   "id": "CVE-2026-56403",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
   "url": "https://ubuntu.com/security/CVE-2026-56403"
  },
  {
   "id": "CVE-2026-56404",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 has an integer overflow in addBinding.",
   "url": "https://ubuntu.com/security/CVE-2026-56404"
  },
  {
   "id": "CVE-2026-56405",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
   "url": "https://ubuntu.com/security/CVE-2026-56405"
  },
  {
   "id": "CVE-2026-56406",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
   "url": "https://ubuntu.com/security/CVE-2026-56406"
  },
  {
   "id": "CVE-2026-56407",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
   "url": "https://ubuntu.com/security/CVE-2026-56407"
  },
  {
   "id": "CVE-2026-56408",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 has an integer overflow in copyString.",
   "url": "https://ubuntu.com/security/CVE-2026-56408"
  },
  {
   "id": "CVE-2026-56410",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
   "url": "https://ubuntu.com/security/CVE-2026-56410"
  },
  {
   "id": "CVE-2026-56411",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.9,
   "affects": [
    "expat"
   ],
   "title": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
   "url": "https://ubuntu.com/security/CVE-2026-56411"
  },
  {
   "id": "CVE-2026-56409",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.5,
   "affects": [
    "expat"
   ],
   "title": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.",
   "url": "https://ubuntu.com/security/CVE-2026-56409"
  },
  {
   "id": "CVE-2026-72522",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 6.2,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
   "url": "https://ubuntu.com/security/CVE-2026-72522"
  },
  {
   "id": "CVE-2026-6019",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.14",
    "3.14.5rc1",
    "3.15.0b1"
   ],
   "cvss": 6.1,
   "affects": [
    "python"
   ],
   "title": "http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6019"
  },
  {
   "id": "CVE-2026-3446",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.13",
    "3.14.4",
    "3.15.0a8"
   ],
   "cvss": 6.0,
   "affects": [
    "python"
   ],
   "title": "When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3446"
  },
  {
   "id": "CVE-2025-15366",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.15",
    "3.14.7",
    "3.15.0a6"
   ],
   "cvss": 5.9,
   "affects": [
    "python"
   ],
   "title": "The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15366"
  },
  {
   "id": "CVE-2025-15367",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.0a6"
   ],
   "cvss": 5.9,
   "affects": [
    "python"
   ],
   "title": "The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15367"
  },
  {
   "id": "CVE-2026-50219",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
   "url": "https://ubuntu.com/security/CVE-2026-50219"
  },
  {
   "id": "CVE-2026-56412",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.",
   "url": "https://ubuntu.com/security/CVE-2026-56412"
  },
  {
   "id": "CVE-2025-13837",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.10",
    "3.14.1",
    "3.15.0a3"
   ],
   "cvss": 5.5,
   "affects": [
    "python"
   ],
   "title": "When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13837"
  },
  {
   "id": "CVE-2025-66382",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "expat"
   ],
   "title": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
   "url": "https://ubuntu.com/security/CVE-2025-66382"
  },
  {
   "id": "CVE-2026-32776",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
   "url": "https://ubuntu.com/security/CVE-2026-32776"
  },
  {
   "id": "CVE-2026-32777",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
   "url": "https://ubuntu.com/security/CVE-2026-32777"
  },
  {
   "id": "CVE-2026-32778",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
   "url": "https://ubuntu.com/security/CVE-2026-32778"
  },
  {
   "id": "CVE-2025-12781",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.10",
    "3.14.1",
    "3.15.0a2"
   ],
   "cvss": 5.3,
   "affects": [
    "python"
   ],
   "title": "When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish\u2026",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12781"
  },
  {
   "id": "CVE-2026-13595",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.3,
   "affects": [
    "util-linux"
   ],
   "title": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.",
   "url": "https://ubuntu.com/security/CVE-2026-13595"
  },
  {
   "id": "CVE-2026-3184",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.3,
   "affects": [
    "util-linux"
   ],
   "title": "A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.",
   "url": "https://ubuntu.com/security/CVE-2026-3184"
  },
  {
   "id": "CVE-2026-4360",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "unknown",
   "fixed_in": [],
   "cvss": 5.3,
   "affects": [
    "python"
   ],
   "title": "In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the\u2026",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4360"
  },
  {
   "id": "CVE-2026-56131",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.9,
   "affects": [
    "expat"
   ],
   "title": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
   "url": "https://ubuntu.com/security/CVE-2026-56131"
  },
  {
   "id": "CVE-2026-27456",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 4.7,
   "affects": [
    "util-linux"
   ],
   "title": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.",
   "url": "https://ubuntu.com/security/CVE-2026-27456"
  },
  {
   "id": "CVE-2025-13462",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.13",
    "3.14.4",
    "3.15.0a8"
   ],
   "cvss": 3.3,
   "affects": [
    "python"
   ],
   "title": "The \"tarfile\" module would still apply normalization of AREGTYPE (\\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13462"
  },
  {
   "id": "CVE-2026-4519",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.13",
    "3.14.4",
    "3.15.0a8"
   ],
   "cvss": 3.3,
   "affects": [
    "python"
   ],
   "title": "The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4519"
  },
  {
   "id": "CVE-2026-53612",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": null,
   "affects": [
    "util-linux"
   ],
   "title": "CVE-2026-53612",
   "url": "https://ubuntu.com/security/CVE-2026-53612"
  },
  {
   "id": "CVE-2026-53613",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": null,
   "affects": [
    "util-linux"
   ],
   "title": "CVE-2026-53613",
   "url": "https://ubuntu.com/security/CVE-2026-53613"
  },
  {
   "id": "CVE-2026-53614",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": null,
   "affects": [
    "util-linux"
   ],
   "title": "CVE-2026-53614",
   "url": "https://ubuntu.com/security/CVE-2026-53614"
  },
  {
   "id": "CVE-2026-53615",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": null,
   "affects": [
    "util-linux"
   ],
   "title": "CVE-2026-53615",
   "url": "https://ubuntu.com/security/CVE-2026-53615"
  },
  {
   "id": "CVE-2026-3479",
   "severity": "unknown",
   "distro_severity": "negligible",
   "fix_state": "fixed",
   "fixed_in": [
    "3.13.13",
    "3.14.4",
    "3.15.0a8"
   ],
   "cvss": 0.0,
   "affects": [
    "python"
   ],
   "title": "DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point.",
   "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3479"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 7,
  "medium": 32,
  "low": 2,
  "unknown": 1
 },
 "suppressed": [
  {
   "id": "CVE-2026-27171",
   "affects": [
    "zlib"
   ],
   "by": "vex"
  },
  {
   "id": "CVE-2026-42250",
   "affects": [
    "bzip2"
   ],
   "by": "vex"
  },
  {
   "id": "CVE-2026-4739",
   "affects": [
    "expat"
   ],
   "by": "vex"
  }
 ]
}
