{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "openssh"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-55655",
   "severity": "medium",
   "title": "A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.",
   "url": "https://ubuntu.com/security/CVE-2026-55655"
  },
  {
   "affects": [
    "openssh"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-73282",
   "severity": "medium",
   "title": "In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.",
   "url": "https://ubuntu.com/security/CVE-2026-73282"
  },
  {
   "affects": [
    "openssh"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-55654",
   "severity": "low",
   "title": "A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-55654"
  },
  {
   "affects": [
    "openssh"
   ],
   "cvss": 3.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-73281",
   "severity": "low",
   "title": "In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.",
   "url": "https://ubuntu.com/security/CVE-2026-73281"
  },
  {
   "affects": [
    "openssh"
   ],
   "cvss": 2.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-73283",
   "severity": "low",
   "title": "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.",
   "url": "https://ubuntu.com/security/CVE-2026-73283"
  }
 ],
 "findings_changed_at": "2026-08-26T12:56:45Z",
 "image": "openssh-sftp",
 "inputs": {
  "sbom_sha256": "06b74df700ca930ffbb11e0dc652ca1cda2b02e298a4151cbfd2aa8042e37979"
 },
 "platform_digest": "sha256:19104be9ac031f2a13a63df014b263222826c65f90330a23ad251436cf01276b",
 "project": "openssh",
 "receipt_sha256": "dfdd73882b3582bb5ea9e21fbf2989d221ba231133af2b9baf9059fed73a3aa5",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "low": 3,
  "medium": 2,
  "unknown": 0
 },
 "suppressed": [],
 "version": "10.2p1",
 "vex_applied": [
  "openssh-sftp-10.2p1-amd64.vex.json",
  "openssh-sftp-10.2p1-amd64.ubuntu-vex.json"
 ]
}
