{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-14456",
   "severity": "high",
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "affects": [
    "coreutils"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56391",
   "severity": "medium",
   "title": "GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used.",
   "url": "https://ubuntu.com/security/CVE-2026-56391"
  },
  {
   "affects": [
    "coreutils"
   ],
   "cvss": 4.4,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2025-5278",
   "severity": "medium",
   "title": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key\u2026",
   "url": "https://ubuntu.com/security/CVE-2025-5278"
  },
  {
   "affects": [
    "coreutils"
   ],
   "cvss": 1.8,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56392",
   "severity": "low",
   "title": "GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values.",
   "url": "https://ubuntu.com/security/CVE-2026-56392"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": null,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-75803",
   "severity": "low",
   "title": "CVE-2026-75803",
   "url": "https://ubuntu.com/security/CVE-2026-75803"
  }
 ],
 "findings_changed_at": "2026-08-26T13:57:23Z",
 "image": "coreutils-digest",
 "inputs": {
  "sbom_sha256": "42910f1cccd66079a500f0fecc3a8fd856cdc355c27a77f13f224252798c7b36"
 },
 "platform_digest": "sha256:59946fbd74c6638becda353d57f729c3f51c1e54dccd29c4eb6963eaa8be7f07",
 "project": "coreutils",
 "receipt_sha256": "1a88f08e008888f72a76d88036d6b757a4fb5a0d5b883d3e304e232a35fc2e18",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 1,
  "low": 2,
  "medium": 2,
  "unknown": 0
 },
 "suppressed": [
  {
   "affects": [
    "zlib"
   ],
   "by": "vex",
   "id": "CVE-2026-27171"
  }
 ],
 "version": "9.7",
 "vex_applied": [
  "coreutils-digest-9.7-amd64.vex.json",
  "coreutils-digest-9.7-amd64.ubuntu-vex.json"
 ]
}
