{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "libssh2"
   ],
   "cvss": 8.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66032",
   "severity": "high",
   "title": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session.",
   "url": "https://ubuntu.com/security/CVE-2026-66032"
  },
  {
   "affects": [
    "libssh2"
   ],
   "cvss": 8.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66033",
   "severity": "high",
   "title": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66033"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 8.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66046",
   "severity": "high",
   "title": "Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2)\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66046"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 8.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-76641",
   "severity": "high",
   "title": "Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate.",
   "url": "https://ubuntu.com/security/CVE-2026-76641"
  },
  {
   "affects": [
    "libxml2"
   ],
   "cvss": 7.8,
   "distro_severity": "negligible",
   "fix_state": "wont-fix",
   "fixed_in": [],
   "id": "CVE-2026-11979",
   "severity": "high",
   "title": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.",
   "url": "https://ubuntu.com/security/CVE-2026-11979"
  },
  {
   "affects": [
    "libssh2"
   ],
   "cvss": 7.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66034",
   "severity": "high",
   "title": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66034"
  },
  {
   "affects": [
    "libssh2"
   ],
   "cvss": 7.7,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66035",
   "severity": "high",
   "title": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66035"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-14456",
   "severity": "high",
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-41080",
   "severity": "high",
   "title": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
   "url": "https://ubuntu.com/security/CVE-2026-41080"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-45186",
   "severity": "high",
   "title": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
   "url": "https://ubuntu.com/security/CVE-2026-45186"
  },
  {
   "affects": [
    "curl"
   ],
   "cvss": 7.5,
   "distro_severity": "low",
   "fix_state": "wont-fix",
   "fixed_in": [],
   "id": "CVE-2026-8932",
   "severity": "high",
   "title": "libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.",
   "url": "https://ubuntu.com/security/CVE-2026-8932"
  },
  {
   "affects": [
    "acl"
   ],
   "cvss": 7.2,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-54370",
   "severity": "high",
   "title": "acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-54370"
  },
  {
   "affects": [
    "acl"
   ],
   "cvss": 7.1,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-54369",
   "severity": "high",
   "title": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-54369"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56132",
   "severity": "medium",
   "title": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
   "url": "https://ubuntu.com/security/CVE-2026-56132"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56403",
   "severity": "medium",
   "title": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
   "url": "https://ubuntu.com/security/CVE-2026-56403"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56404",
   "severity": "medium",
   "title": "libexpat before 2.8.2 has an integer overflow in addBinding.",
   "url": "https://ubuntu.com/security/CVE-2026-56404"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56405",
   "severity": "medium",
   "title": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
   "url": "https://ubuntu.com/security/CVE-2026-56405"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56406",
   "severity": "medium",
   "title": "libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.",
   "url": "https://ubuntu.com/security/CVE-2026-56406"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56407",
   "severity": "medium",
   "title": "libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.",
   "url": "https://ubuntu.com/security/CVE-2026-56407"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56408",
   "severity": "medium",
   "title": "libexpat before 2.8.2 has an integer overflow in copyString.",
   "url": "https://ubuntu.com/security/CVE-2026-56408"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56410",
   "severity": "medium",
   "title": "xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.",
   "url": "https://ubuntu.com/security/CVE-2026-56410"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56411",
   "severity": "medium",
   "title": "xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.",
   "url": "https://ubuntu.com/security/CVE-2026-56411"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56409",
   "severity": "medium",
   "title": "xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.",
   "url": "https://ubuntu.com/security/CVE-2026-56409"
  },
  {
   "affects": [
    "p11-kit"
   ],
   "cvss": 6.2,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-13757",
   "severity": "medium",
   "title": "A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-13757"
  },
  {
   "affects": [
    "p11-kit"
   ],
   "cvss": 6.2,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-18938",
   "severity": "medium",
   "title": "A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability.",
   "url": "https://ubuntu.com/security/CVE-2026-18938"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 6.2,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-72522",
   "severity": "medium",
   "title": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
   "url": "https://ubuntu.com/security/CVE-2026-72522"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-50219",
   "severity": "medium",
   "title": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
   "url": "https://ubuntu.com/security/CVE-2026-50219"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56412",
   "severity": "medium",
   "title": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.",
   "url": "https://ubuntu.com/security/CVE-2026-56412"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-76956",
   "severity": "medium",
   "title": "In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.",
   "url": "https://ubuntu.com/security/CVE-2026-76956"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2025-66382",
   "severity": "medium",
   "title": "In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.",
   "url": "https://ubuntu.com/security/CVE-2025-66382"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-32776",
   "severity": "medium",
   "title": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
   "url": "https://ubuntu.com/security/CVE-2026-32776"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-32777",
   "severity": "medium",
   "title": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
   "url": "https://ubuntu.com/security/CVE-2026-32777"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 5.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-32778",
   "severity": "medium",
   "title": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
   "url": "https://ubuntu.com/security/CVE-2026-32778"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 4.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-56131",
   "severity": "medium",
   "title": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
   "url": "https://ubuntu.com/security/CVE-2026-56131"
  },
  {
   "affects": [
    "expat"
   ],
   "cvss": 4.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-76957",
   "severity": "medium",
   "title": "libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.",
   "url": "https://ubuntu.com/security/CVE-2026-76957"
  },
  {
   "affects": [
    "libarchive"
   ],
   "cvss": 2.9,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-16517",
   "severity": "low",
   "title": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-16517"
  },
  {
   "affects": [
    "cmake"
   ],
   "cvss": 1.9,
   "distro_severity": "negligible",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2025-9301",
   "severity": "low",
   "title": "A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion.",
   "url": "https://ubuntu.com/security/CVE-2025-9301"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": null,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-75803",
   "severity": "low",
   "title": "CVE-2026-75803",
   "url": "https://ubuntu.com/security/CVE-2026-75803"
  }
 ],
 "findings_changed_at": "2026-08-26T18:05:58Z",
 "image": "cmake",
 "inputs": {
  "sbom_sha256": "c7d31b7931fe0bab1f699a38a3acd9223bdf83dfaba3a31c04d6b5dae1e923fd"
 },
 "platform_digest": "sha256:3389c13a9566d1d8dc55d73b16d63c7d0cc0fb4f1ef5a034966da8773a231ac6",
 "project": "cmake",
 "receipt_sha256": "6ea3973105384812f09c0594dc76784504104a52b7fc8661bb891199176973e5",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 13,
  "low": 3,
  "medium": 22,
  "unknown": 0
 },
 "suppressed": [
  {
   "affects": [
    "zlib"
   ],
   "by": "vex",
   "id": "CVE-2026-27171"
  },
  {
   "affects": [
    "bzip2"
   ],
   "by": "vex",
   "id": "CVE-2026-42250"
  },
  {
   "affects": [
    "expat"
   ],
   "by": "vex",
   "id": "CVE-2026-4739"
  }
 ],
 "version": "4.2.3",
 "vex_applied": [
  "cmake-4.2.3-amd64.vex.json",
  "cmake-4.2.3-amd64.ubuntu-vex.json"
 ]
}
