{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "setuptools"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "78.1.1"
   ],
   "id": "GHSA-5rjg-fvgr-3xxf",
   "severity": "high",
   "title": "setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write",
   "url": "https://github.com/advisories/GHSA-5rjg-fvgr-3xxf"
  },
  {
   "affects": [
    "msgpack"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.2.1"
   ],
   "id": "GHSA-6v7p-g79w-8964",
   "severity": "high",
   "title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error",
   "url": "https://github.com/advisories/GHSA-6v7p-g79w-8964"
  },
  {
   "affects": [
    "setuptools"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "83.0.0"
   ],
   "id": "GHSA-h35f-9h28-mq5c",
   "severity": "medium",
   "title": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+",
   "url": "https://github.com/advisories/GHSA-h35f-9h28-mq5c"
  }
 ],
 "findings_changed_at": "2026-08-26T19:59:54Z",
 "image": "pip",
 "inputs": {
  "sbom_sha256": "eacd958fdcadfe500f86c6f13fdb8c73362fc0413fa06f18ef8c4d8dfacca212"
 },
 "platform_digest": "sha256:c028bfadf0e99830386c4f7489b4015fe02ec9b493fbd35baf0a28f0448e9b77",
 "project": "pip",
 "receipt_sha256": "00ffd6a60d7dca5aa9ddd12c99f1d40c308325d54e6efee7488327fbbae25d01",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 2,
  "low": 0,
  "medium": 1,
  "unknown": 0
 },
 "suppressed": [],
 "version": "26.2.1",
 "vex_applied": [
  "pip-26.2.1-amd64.vex.json",
  "pip-26.2.1-amd64.ubuntu-vex.json"
 ]
}
