{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "cpio"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2023-7216",
   "severity": "medium",
   "title": "A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive.",
   "url": "https://ubuntu.com/security/CVE-2023-7216"
  },
  {
   "affects": [
    "cpio"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66484",
   "severity": "medium",
   "title": "GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66484"
  },
  {
   "affects": [
    "cpio"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66485",
   "severity": "medium",
   "title": "GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname\u2026",
   "url": "https://ubuntu.com/security/CVE-2026-66485"
  },
  {
   "affects": [
    "cpio"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-66486",
   "severity": "medium",
   "title": "GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping.",
   "url": "https://ubuntu.com/security/CVE-2026-66486"
  }
 ],
 "findings_changed_at": "2026-08-26T12:56:45Z",
 "image": "cpio",
 "inputs": {
  "sbom_sha256": "c908ce46a5d70ba49a97e621a255116b860b4c3284b7d96016b3928d49f56fb0"
 },
 "platform_digest": "sha256:911b21c5aebc22bbaa4fc10aa196c892359f210f8f6aa9eb6cddf04aa7c0892e",
 "project": "cpio",
 "receipt_sha256": "0e1e38c5235f34b87f1e5008913b64624f37bf21f99a3b6bbd615a81ad6e017e",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 0,
  "low": 0,
  "medium": 4,
  "unknown": 0
 },
 "suppressed": [],
 "version": "2.15",
 "vex_applied": [
  "cpio-2.15-arm64.vex.json",
  "cpio-2.15-arm64.ubuntu-vex.json"
 ]
}
