{
 "arch": "arm64",
 "findings": [
  {
   "affects": [
    "openssl"
   ],
   "cvss": 7.5,
   "distro_severity": "medium",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-14456",
   "severity": "high",
   "title": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.",
   "url": "https://ubuntu.com/security/CVE-2026-14456"
  },
  {
   "affects": [
    "zlib"
   ],
   "cvss": 5.5,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-27171",
   "severity": "medium",
   "title": "zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.",
   "url": "https://ubuntu.com/security/CVE-2026-27171"
  },
  {
   "affects": [
    "json"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "2.19.9"
   ],
   "id": "GHSA-x2f5-4prf-w687",
   "severity": "low",
   "title": "Ruby json: JSON generator heap buffer overflow when streaming to an IO",
   "url": "https://github.com/advisories/GHSA-x2f5-4prf-w687"
  },
  {
   "affects": [
    "openssl"
   ],
   "cvss": null,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "CVE-2026-75803",
   "severity": "low",
   "title": "CVE-2026-75803",
   "url": "https://ubuntu.com/security/CVE-2026-75803"
  }
 ],
 "findings_changed_at": "2026-08-26T19:12:07Z",
 "image": "ruby",
 "inputs": {
  "sbom_sha256": "7c98c9b2091041213ee3269a70ecf74de91e9fbae130ce9c3fdc254ae850d287"
 },
 "platform_digest": "sha256:610a4ffb80efa5d0ecd9bff5f175ec5d314f57743a20ac07b0b3faa552c4f9c5",
 "project": "ruby",
 "receipt_sha256": "c74f2dedbfaedf8faa9b97512c29ae7db68aa7d6d7da8ad00655f0bc4d8ef7a9",
 "scanner": "grype",
 "severity_counts": {
  "critical": 0,
  "high": 1,
  "low": 2,
  "medium": 1,
  "unknown": 0
 },
 "suppressed": [],
 "version": "3.4.10",
 "vex_applied": [
  "ruby-3.4.10-arm64.vex.json",
  "ruby-3.4.10-arm64.ubuntu-vex.json"
 ]
}
