{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "setuptools"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "78.1.1"
   ],
   "id": "GHSA-5rjg-fvgr-3xxf",
   "severity": "high",
   "title": "setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write",
   "url": "https://github.com/advisories/GHSA-5rjg-fvgr-3xxf"
  },
  {
   "affects": [
    "msgpack"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.2.1"
   ],
   "id": "GHSA-6v7p-g79w-8964",
   "severity": "high",
   "title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error",
   "url": "https://github.com/advisories/GHSA-6v7p-g79w-8964"
  },
  {
   "affects": [
    "setuptools"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "83.0.0"
   ],
   "id": "GHSA-h35f-9h28-mq5c",
   "severity": "medium",
   "title": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+",
   "url": "https://github.com/advisories/GHSA-h35f-9h28-mq5c"
  }
 ],
 "findings_changed_at": "2026-08-26T19:59:54Z",
 "image": "pip",
 "inputs": {
  "sbom_sha256": "76934e4162ead03bf1912a6e5082c0517c70a945f3276465be9581e88684a8ff"
 },
 "platform_digest": "sha256:53b7e18762db8c354258cb1af1d6cfa7bcedd7e3e44a172edd0016f36d20d18b",
 "project": "pip",
 "receipt_sha256": "4dd0ab7632f597d6821ede67816a08c7c6e69c1ccdcb7a1cb6868b318e3a19c9",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 2,
  "low": 0,
  "medium": 1,
  "unknown": 0
 },
 "suppressed": [],
 "version": "26.2.1",
 "vex_applied": [
  "pip-26.2.1-arm64.vex.json",
  "pip-26.2.1-arm64.ubuntu-vex.json"
 ]
}
