{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "p11-kit"
   ],
   "cvss": 6.2,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-13757",
   "severity": "medium",
   "title": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-13757"
  },
  {
   "affects": [
    "p11-kit"
   ],
   "cvss": 6.2,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-18938",
   "severity": "medium",
   "title": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability.",
   "url": "https://ubuntu.com/security/CVE-2026-18938"
  },
  {
   "affects": [
    "wget"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2021-31879",
   "severity": "medium",
   "title": "GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.",
   "url": "https://ubuntu.com/security/CVE-2021-31879"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-13595",
   "severity": "medium",
   "title": "A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.",
   "url": "https://ubuntu.com/security/CVE-2026-13595"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-3184",
   "severity": "medium",
   "title": "A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.",
   "url": "https://ubuntu.com/security/CVE-2026-3184"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": 4.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-27456",
   "severity": "medium",
   "title": "util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.",
   "url": "https://ubuntu.com/security/CVE-2026-27456"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": null,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-53612",
   "severity": "medium",
   "title": "CVE-2026-53612",
   "url": "https://ubuntu.com/security/CVE-2026-53612"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": null,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-53613",
   "severity": "medium",
   "title": "CVE-2026-53613",
   "url": "https://ubuntu.com/security/CVE-2026-53613"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": null,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-53614",
   "severity": "medium",
   "title": "CVE-2026-53614",
   "url": "https://ubuntu.com/security/CVE-2026-53614"
  },
  {
   "affects": [
    "util-linux"
   ],
   "cvss": null,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-53615",
   "severity": "medium",
   "title": "CVE-2026-53615",
   "url": "https://ubuntu.com/security/CVE-2026-53615"
  }
 ],
 "findings_changed_at": "2026-08-21T22:02:01Z",
 "image": "wget",
 "inputs": {
  "sbom_sha256": "d30ad9ef6c86e129177f1395e1aa8fdda441b2a905ba136ab8451486358aa3f4"
 },
 "platform_digest": "sha256:d4378635cb203bd2eb388e53bff9d4cb4fbe9a5b544a9c675c8dfc9b1b8ec03a",
 "project": "wget",
 "receipt_sha256": "4f1a2e7b84b7f2017e8a145ba15a70a1c0866f884a945de2d1cb23215d0c6f3c",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "low": 0,
  "medium": 10,
  "unknown": 0
 },
 "suppressed": [
  {
   "affects": [
    "zlib"
   ],
   "by": "vex",
   "id": "CVE-2026-27171"
  }
 ],
 "version": "1.25.0",
 "vex_applied": [
  "wget-1.25.0-arm64.vex.json",
  "wget-1.25.0-arm64.ubuntu-vex.json"
 ]
}
