{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "bison"
   ],
   "cvss": 6.8,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56389",
   "severity": "medium",
   "title": "GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables.",
   "url": "https://ubuntu.com/security/CVE-2026-56389"
  },
  {
   "affects": [
    "bison"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56390",
   "severity": "medium",
   "title": "GNU Bison improperly handles grammar\u2011defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller\u2011supplied output options.",
   "url": "https://ubuntu.com/security/CVE-2026-56390"
  }
 ],
 "findings_changed_at": "2026-08-26T18:05:58Z",
 "image": "bison",
 "inputs": {
  "sbom_sha256": "a6333f564a44063666558409b7fed23b740d92c449fa1a947e7346716e4aac27"
 },
 "platform_digest": "sha256:2301bca1af90c07d11cf914b8c7db9283b955183c3eee56ec99b07f436a07578",
 "project": "bison",
 "receipt_sha256": "4548ecb60d76985b1b36fc47a5fb26adf9c24ce2722de88f64da7297a2bee2e5",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "low": 0,
  "medium": 2,
  "unknown": 0
 },
 "suppressed": [],
 "version": "3.8.2",
 "vex_applied": [
  "bison-3.8.2-arm64.vex.json",
  "bison-3.8.2-arm64.ubuntu-vex.json"
 ]
}
