{
 "scanner": "grype",
 "at": "2026-08-19T12:22:41Z",
 "arch": "arm64",
 "findings": [
  {
   "id": "CVE-2026-14456",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "id": "CVE-2026-54876",
   "severity": "high",
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 7.5,
   "affects": [
    "openssl"
   ],
   "title": "Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.",
   "url": "https://ubuntu.com/security/CVE-2026-54876"
  },
  {
   "id": "GHSA-46q3-7gv7-qmgg",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.15"
   ],
   "cvss": 5.8,
   "affects": [
    "net-imap"
   ],
   "title": "Net::IMAP: Command Injection via ID command argument",
   "url": "https://github.com/advisories/GHSA-46q3-7gv7-qmgg"
  },
  {
   "id": "GHSA-8p34-64r3-mwg8",
   "severity": "medium",
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.15"
   ],
   "cvss": 5.8,
   "affects": [
    "net-imap"
   ],
   "title": "Net::IMAP: Command Injection via non-synchronizing literal in \"raw\" argument",
   "url": "https://github.com/advisories/GHSA-8p34-64r3-mwg8"
  },
  {
   "id": "CVE-2026-27171",
   "severity": "medium",
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "cvss": 5.5,
   "affects": [
    "zlib"
   ],
   "title": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
   "url": "https://ubuntu.com/security/CVE-2026-27171"
  },
  {
   "id": "GHSA-c4fp-cxrr-mj66",
   "severity": "low",
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.15"
   ],
   "cvss": 2.1,
   "affects": [
    "net-imap"
   ],
   "title": "Net::IMAP: Denial of Service via incomplete raw argument validation",
   "url": "https://github.com/advisories/GHSA-c4fp-cxrr-mj66"
  }
 ],
 "severity_counts": {
  "critical": 0,
  "high": 2,
  "medium": 3,
  "low": 1,
  "unknown": 0
 },
 "suppressed": []
}
