{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "libxml2"
   ],
   "cvss": 7.8,
   "distro_severity": "negligible",
   "fix_state": "wont-fix",
   "fixed_in": [],
   "id": "CVE-2026-11979",
   "severity": "high",
   "title": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.",
   "url": "https://ubuntu.com/security/CVE-2026-11979"
  },
  {
   "affects": [
    "bind9"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-13204",
   "severity": "high",
   "title": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.",
   "url": "https://ubuntu.com/security/CVE-2026-13204"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-18798",
   "severity": "high",
   "title": "Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet.",
   "url": "https://ubuntu.com/security/CVE-2026-18798"
  },
  {
   "affects": [
    "lmdb"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-22185",
   "severity": "medium",
   "title": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load.",
   "url": "https://ubuntu.com/security/CVE-2026-22185"
  }
 ],
 "findings_changed_at": "2026-08-29T18:32:43Z",
 "image": "bind9",
 "inputs": {
  "sbom_sha256": "b5b203f96e5da4ecaa074e431fce8f1c440dfc5f68ee3efaaf05155fa3e58143"
 },
 "platform_digest": "sha256:06ecf5486e4d786d213baed755684baca81c43441a97c3248d37cc18b40c55da",
 "project": "bind9",
 "receipt_sha256": "b9e5dc3d5ba2bca3e7b506fc6be292e65ef888e4ee8f95f1f6ac5d08232bbdab",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 3,
  "low": 0,
  "medium": 1,
  "unknown": 0
 },
 "suppressed": [
  {
   "affects": [
    "zlib"
   ],
   "by": "vex",
   "id": "CVE-2026-27171"
  }
 ],
 "version": "9.20.24",
 "vex_applied": [
  "bind9-9.20.24-amd64.vex.json",
  "bind9-9.20.24-amd64.ubuntu-vex.json"
 ]
}
