{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "github.com/containerd/containerd/v2"
   ],
   "cvss": 9.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "2.2.5"
   ],
   "id": "GHSA-cvxm-645q-p574",
   "severity": "critical",
   "title": "containerd: CRI checkpoint import allows local image tag poisoning",
   "url": "https://github.com/advisories/GHSA-cvxm-645q-p574"
  },
  {
   "affects": [
    "github.com/containerd/containerd"
   ],
   "cvss": 9.9,
   "distro_severity": "critical",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "GO-2026-5338",
   "severity": "critical",
   "title": "containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd",
   "url": "https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574"
  },
  {
   "affects": [
    "github.com/containerd/containerd"
   ],
   "cvss": 9.6,
   "distro_severity": "critical",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "GO-2026-5064",
   "severity": "critical",
   "title": "containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd",
   "url": "https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc"
  },
  {
   "affects": [
    "google.golang.org/grpc"
   ],
   "cvss": 8.8,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.82.1"
   ],
   "id": "GHSA-hrxh-6v49-42gf",
   "severity": "high",
   "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
   "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf"
  },
  {
   "affects": [
    "github.com/containerd/containerd"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.7.33"
   ],
   "id": "GHSA-xhf5-7wjv-pqxp",
   "severity": "high",
   "title": "containerd CRI \u2014 image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull",
   "url": "https://github.com/advisories/GHSA-xhf5-7wjv-pqxp"
  },
  {
   "affects": [
    "github.com/containerd/containerd/v2"
   ],
   "cvss": 8.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.2.5"
   ],
   "id": "GHSA-xhf5-7wjv-pqxp",
   "severity": "high",
   "title": "containerd CRI \u2014 image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull",
   "url": "https://github.com/advisories/GHSA-xhf5-7wjv-pqxp"
  },
  {
   "affects": [
    "github.com/containerd/containerd/v2"
   ],
   "cvss": 8.4,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.2.5"
   ],
   "id": "GHSA-33vj-92qq-66hc",
   "severity": "high",
   "title": "containerd CRI checkpoint restore CDI annotation smuggling",
   "url": "https://github.com/advisories/GHSA-33vj-92qq-66hc"
  },
  {
   "affects": [
    "oras.land/oras-go/v2"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.6.1"
   ],
   "id": "GHSA-jxpm-75mh-9fp7",
   "severity": "high",
   "title": "oras-go blob upload vulnerable to credential forwarding via unvalidated Location header",
   "url": "https://github.com/advisories/GHSA-jxpm-75mh-9fp7"
  },
  {
   "affects": [
    "oras.land/oras-go/v2"
   ],
   "cvss": 7.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.6.2"
   ],
   "id": "GHSA-fxhp-mv3v-67qp",
   "severity": "high",
   "title": "`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution",
   "url": "https://github.com/advisories/GHSA-fxhp-mv3v-67qp"
  },
  {
   "affects": [
    "github.com/go-git/go-git/v5"
   ],
   "cvss": 7.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.19.2"
   ],
   "id": "GHSA-hc8v-wwc9-vgxm",
   "severity": "high",
   "title": "go-git: Worktree operations may follow symlinks",
   "url": "https://github.com/advisories/GHSA-hc8v-wwc9-vgxm"
  },
  {
   "affects": [
    "github.com/containerd/containerd/v2"
   ],
   "cvss": 7.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.2.5"
   ],
   "id": "GHSA-rgh6-rfwx-v388",
   "severity": "high",
   "title": "Arbitrary host CRI log file read via symlink following in CRI checkpoint restore",
   "url": "https://github.com/advisories/GHSA-rgh6-rfwx-v388"
  },
  {
   "affects": [
    "oras.land/oras-go/v2"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "2.6.1"
   ],
   "id": "GHSA-8xwf-rjm4-xvhv",
   "severity": "medium",
   "title": "oras-go has file store write outside workingDir via symlink traversal",
   "url": "https://github.com/advisories/GHSA-8xwf-rjm4-xvhv"
  },
  {
   "affects": [
    "github.com/containerd/containerd"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.7.33"
   ],
   "id": "GHSA-jpcc-p29g-p8mq",
   "severity": "medium",
   "title": "containerd image-triggered runtime DoS via unbounded group parsing",
   "url": "https://github.com/advisories/GHSA-jpcc-p29g-p8mq"
  },
  {
   "affects": [
    "github.com/containerd/containerd/v2"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "2.2.5"
   ],
   "id": "GHSA-jpcc-p29g-p8mq",
   "severity": "medium",
   "title": "containerd image-triggered runtime DoS via unbounded group parsing",
   "url": "https://github.com/advisories/GHSA-jpcc-p29g-p8mq"
  },
  {
   "affects": [
    "oras.land/oras-go/v2"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "2.6.1"
   ],
   "id": "GHSA-vh4v-2xq2-g5cg",
   "severity": "medium",
   "title": "ORAS Go forwards registry credentials across registry redirects",
   "url": "https://github.com/advisories/GHSA-vh4v-2xq2-g5cg"
  },
  {
   "affects": [
    "github.com/containerd/containerd"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "GO-2026-5622",
   "severity": "medium",
   "title": "Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd",
   "url": "https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388"
  },
  {
   "affects": [
    "github.com/go-git/go-git/v5"
   ],
   "cvss": 6.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "5.19.2"
   ],
   "id": "GHSA-qgq7-7hm3-q39j",
   "severity": "medium",
   "title": "go-git: Malicious reference names may modify files outside the reference storage",
   "url": "https://github.com/advisories/GHSA-qgq7-7hm3-q39j"
  },
  {
   "affects": [
    "github.com/aws/aws-sdk-go-v2/service/s3"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.97.3"
   ],
   "id": "GHSA-xmrv-pmrh-hhx2",
   "severity": "medium",
   "title": "Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder",
   "url": "https://github.com/advisories/GHSA-xmrv-pmrh-hhx2"
  },
  {
   "affects": [
    "go.opentelemetry.io/otel"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.42.0",
    "1.44.0"
   ],
   "id": "GO-2026-5158",
   "severity": "medium",
   "title": "Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel",
   "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835"
  },
  {
   "affects": [
    "oras.land/oras-go/v2"
   ],
   "cvss": 2.1,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "2.6.1"
   ],
   "id": "GHSA-xf85-363p-868w",
   "severity": "low",
   "title": "oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens",
   "url": "https://github.com/advisories/GHSA-xf85-363p-868w"
  },
  {
   "affects": [
    "github.com/klauspost/compress"
   ],
   "cvss": null,
   "distro_severity": "unknown",
   "fix_state": "fixed",
   "fixed_in": [
    "1.18.7"
   ],
   "id": "GO-2026-5841",
   "severity": "unknown",
   "title": "Providing a specially crafted dictionary to s2.NewDict and using it to encode data can make the encoder read out of bounds.",
   "url": "https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw"
  },
  {
   "affects": [
    "golang.org/x/crypto"
   ],
   "cvss": null,
   "distro_severity": "unknown",
   "fix_state": "unknown",
   "fixed_in": [],
   "id": "GO-2026-5932",
   "severity": "unknown",
   "title": "The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.",
   "url": "https://go.dev/issue/44226"
  }
 ],
 "findings_changed_at": "2026-08-29T18:32:43Z",
 "image": "k9s",
 "inputs": {
  "sbom_sha256": "92d32c5dd7901e9db7d3550dea0f273438441453640c5e2f315fd1878d77d7b0"
 },
 "platform_digest": "sha256:629637cc4777f17f6fcca682cb77b17c531397e80f59bdea744f3366f60404db",
 "project": "k9s",
 "receipt_sha256": "f50dd66f7d6e16780e2e262b2137f706708559846f1db5e45c8634cb839e1466",
 "scanner": "grype",
 "severity_counts": {
  "critical": 3,
  "high": 8,
  "low": 1,
  "medium": 8,
  "unknown": 2
 },
 "suppressed": [],
 "version": "0.51.0",
 "vex_applied": [
  "k9s-0.51.0-arm64.vex.json",
  "k9s-0.51.0-arm64.ubuntu-vex.json"
 ]
}
