{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-14456",
   "severity": "high",
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "affects": [
    "net-imap"
   ],
   "cvss": 5.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.15"
   ],
   "id": "GHSA-46q3-7gv7-qmgg",
   "severity": "medium",
   "title": "Net::IMAP: Command Injection via ID command argument",
   "url": "https://github.com/advisories/GHSA-46q3-7gv7-qmgg"
  },
  {
   "affects": [
    "net-imap"
   ],
   "cvss": 5.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.15"
   ],
   "id": "GHSA-8p34-64r3-mwg8",
   "severity": "medium",
   "title": "Net::IMAP: Command Injection via non-synchronizing literal in \"raw\" argument",
   "url": "https://github.com/advisories/GHSA-8p34-64r3-mwg8"
  },
  {
   "affects": [
    "zlib"
   ],
   "cvss": 5.5,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-27171",
   "severity": "medium",
   "title": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
   "url": "https://ubuntu.com/security/CVE-2026-27171"
  },
  {
   "affects": [
    "net-imap"
   ],
   "cvss": 2.1,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "0.5.15"
   ],
   "id": "GHSA-c4fp-cxrr-mj66",
   "severity": "low",
   "title": "Net::IMAP: Denial of Service via incomplete raw argument validation",
   "url": "https://github.com/advisories/GHSA-c4fp-cxrr-mj66"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": null,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-75803",
   "severity": "low",
   "title": "CVE-2026-75803",
   "url": "https://ubuntu.com/security/CVE-2026-75803"
  }
 ],
 "findings_changed_at": "2026-08-26T19:12:07Z",
 "image": "ruby",
 "inputs": {
  "sbom_sha256": "dc4b84cdad272a4e64f0e3f1703bc3398372275bc9c65a9d2698c8b2dfaab59a"
 },
 "platform_digest": "sha256:a7c7fd4435c87df3a2478024b452db68a392ff35f77e01b8724e542ad59167ba",
 "project": "ruby",
 "receipt_sha256": "26adbc6e7e8b39db1cf10958d334c8e391c8738be4460106c4457a964d999a00",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 1,
  "low": 2,
  "medium": 3,
  "unknown": 0
 },
 "suppressed": [],
 "version": "3.3.12",
 "vex_applied": [
  "ruby-3.3.12-arm64.vex.json",
  "ruby-3.3.12-arm64.ubuntu-vex.json"
 ]
}
