{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "bison"
   ],
   "cvss": 6.8,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56389",
   "severity": "medium",
   "title": "GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables.",
   "url": "https://ubuntu.com/security/CVE-2026-56389"
  },
  {
   "affects": [
    "bison"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56390",
   "severity": "medium",
   "title": "GNU Bison improperly handles grammar\u2011defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller\u2011supplied output options.",
   "url": "https://ubuntu.com/security/CVE-2026-56390"
  }
 ],
 "findings_changed_at": "2026-08-26T18:05:58Z",
 "image": "bison",
 "inputs": {
  "sbom_sha256": "7358e2b51ca136533b286c63abcbfe58965d125d1cf8d13ece79f594744fe87d"
 },
 "platform_digest": "sha256:e6cad73ef00251dd386bb97a3afa18a2ee564ea429a6cb1f830e1f2f31db0cfb",
 "project": "bison",
 "receipt_sha256": "bdd318ba0ab1d456e640ad127af18dda3a17f4d54fcec46c270c456f114c93ab",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "low": 0,
  "medium": 2,
  "unknown": 0
 },
 "suppressed": [],
 "version": "3.8.2",
 "vex_applied": [
  "bison-3.8.2-amd64.vex.json",
  "bison-3.8.2-amd64.ubuntu-vex.json"
 ]
}
