{
  "results": [
    {
      "source": {
        "path": "/home/runner/work/snap-pi-hole/snap-pi-hole/osv-sbom-input/sbom-stable-arm64.cdx.json",
        "type": "sbom"
      },
      "packages": [
        {
          "package": {
            "name": "bind9",
            "version": "1:9.20.24-1ubuntu0.2",
            "ecosystem": "Ubuntu"
          },
          "groups": [
            {
              "ids": [
                "UBUNTU-CVE-2026-13204"
              ],
              "aliases": [
                "CVE-2026-13204",
                "UBUNTU-CVE-2026-13204"
              ],
              "max_severity": "7.5"
            }
          ],
          "vulnerabilities": [
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "bind9utils",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "dnsutils",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "host",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "libbind9-90",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "libdns100",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "libisc95",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "libisccc90",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "libisccfg90",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "liblwres90",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      },
                      {
                        "binary_name": "lwresd",
                        "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.9.3.dfsg.P2-4ubuntu1",
                    "1:9.9.3.dfsg.P2-4ubuntu2",
                    "1:9.9.3.dfsg.P2-4ubuntu3",
                    "1:9.9.5.dfsg-2",
                    "1:9.9.5.dfsg-3",
                    "1:9.9.5.dfsg-3ubuntu0.1",
                    "1:9.9.5.dfsg-3ubuntu0.2",
                    "1:9.9.5.dfsg-3ubuntu0.3",
                    "1:9.9.5.dfsg-3ubuntu0.4",
                    "1:9.9.5.dfsg-3ubuntu0.5",
                    "1:9.9.5.dfsg-3ubuntu0.6",
                    "1:9.9.5.dfsg-3ubuntu0.7",
                    "1:9.9.5.dfsg-3ubuntu0.8",
                    "1:9.9.5.dfsg-3ubuntu0.9",
                    "1:9.9.5.dfsg-3ubuntu0.10",
                    "1:9.9.5.dfsg-3ubuntu0.11",
                    "1:9.9.5.dfsg-3ubuntu0.12",
                    "1:9.9.5.dfsg-3ubuntu0.13",
                    "1:9.9.5.dfsg-3ubuntu0.14",
                    "1:9.9.5.dfsg-3ubuntu0.15",
                    "1:9.9.5.dfsg-3ubuntu0.16",
                    "1:9.9.5.dfsg-3ubuntu0.17",
                    "1:9.9.5.dfsg-3ubuntu0.18",
                    "1:9.9.5.dfsg-3ubuntu0.19",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm1",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm2",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm3",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm4",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm5",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm6",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm7",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm9",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm10",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm11",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm12",
                    "1:9.9.5.dfsg-3ubuntu0.19+esm13"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "bind9utils",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "dnsutils",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "host",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libbind9-140",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libdns-export162",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libdns162",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libirs-export141",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libirs141",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libisc-export160",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libisc160",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libisccc-export140",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libisccc140",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libisccfg-export140",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "libisccfg140",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "liblwres141",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      },
                      {
                        "binary_name": "lwresd",
                        "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=esm-infra%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.9.5.dfsg-11ubuntu1",
                    "1:9.9.5.dfsg-12",
                    "1:9.9.5.dfsg-12.1",
                    "1:9.9.5.dfsg-12.1ubuntu1",
                    "1:9.10.3.dfsg.P2-4",
                    "1:9.10.3.dfsg.P2-5",
                    "1:9.10.3.dfsg.P4-3",
                    "1:9.10.3.dfsg.P4-4",
                    "1:9.10.3.dfsg.P4-5",
                    "1:9.10.3.dfsg.P4-8",
                    "1:9.10.3.dfsg.P4-8ubuntu1",
                    "1:9.10.3.dfsg.P4-8ubuntu1.1",
                    "1:9.10.3.dfsg.P4-8ubuntu1.2",
                    "1:9.10.3.dfsg.P4-8ubuntu1.3",
                    "1:9.10.3.dfsg.P4-8ubuntu1.4",
                    "1:9.10.3.dfsg.P4-8ubuntu1.5",
                    "1:9.10.3.dfsg.P4-8ubuntu1.6",
                    "1:9.10.3.dfsg.P4-8ubuntu1.7",
                    "1:9.10.3.dfsg.P4-8ubuntu1.8",
                    "1:9.10.3.dfsg.P4-8ubuntu1.9",
                    "1:9.10.3.dfsg.P4-8ubuntu1.10",
                    "1:9.10.3.dfsg.P4-8ubuntu1.11",
                    "1:9.10.3.dfsg.P4-8ubuntu1.12",
                    "1:9.10.3.dfsg.P4-8ubuntu1.14",
                    "1:9.10.3.dfsg.P4-8ubuntu1.15",
                    "1:9.10.3.dfsg.P4-8ubuntu1.16",
                    "1:9.10.3.dfsg.P4-8ubuntu1.17",
                    "1:9.10.3.dfsg.P4-8ubuntu1.18",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm1",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm2",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm3",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm5",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm6",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm8",
                    "1:9.10.3.dfsg.P4-8ubuntu1.19+esm9"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "bind9utils",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "dnsutils",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libbind9-160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libdns-export1100",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libdns1100",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libirs-export160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libirs160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libisc-export169",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libisc169",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libisccc-export160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libisccc160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libisccfg-export160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "libisccfg160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      },
                      {
                        "binary_name": "liblwres160",
                        "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=esm-infra%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.10.3.dfsg.P4-12.6ubuntu1",
                    "1:9.11.2.P1-1ubuntu2",
                    "1:9.11.2.P1-1ubuntu3",
                    "1:9.11.2.P1-1ubuntu4",
                    "1:9.11.2.P1-1ubuntu5",
                    "1:9.11.3+dfsg-1ubuntu1",
                    "1:9.11.3+dfsg-1ubuntu1.1",
                    "1:9.11.3+dfsg-1ubuntu1.2",
                    "1:9.11.3+dfsg-1ubuntu1.3",
                    "1:9.11.3+dfsg-1ubuntu1.5",
                    "1:9.11.3+dfsg-1ubuntu1.7",
                    "1:9.11.3+dfsg-1ubuntu1.8",
                    "1:9.11.3+dfsg-1ubuntu1.9",
                    "1:9.11.3+dfsg-1ubuntu1.10",
                    "1:9.11.3+dfsg-1ubuntu1.11",
                    "1:9.11.3+dfsg-1ubuntu1.12",
                    "1:9.11.3+dfsg-1ubuntu1.13",
                    "1:9.11.3+dfsg-1ubuntu1.14",
                    "1:9.11.3+dfsg-1ubuntu1.15",
                    "1:9.11.3+dfsg-1ubuntu1.16",
                    "1:9.11.3+dfsg-1ubuntu1.17",
                    "1:9.11.3+dfsg-1ubuntu1.18",
                    "1:9.11.3+dfsg-1ubuntu1.19+esm1",
                    "1:9.11.3+dfsg-1ubuntu1.19+esm2",
                    "1:9.11.3+dfsg-1ubuntu1.19+esm3",
                    "1:9.11.3+dfsg-1ubuntu1.19+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "isc-dhcp-client",
                        "binary_version": "4.3.5-3ubuntu7.4"
                      },
                      {
                        "binary_name": "isc-dhcp-client-ddns",
                        "binary_version": "4.3.5-3ubuntu7.4"
                      },
                      {
                        "binary_name": "isc-dhcp-common",
                        "binary_version": "4.3.5-3ubuntu7.4"
                      },
                      {
                        "binary_name": "isc-dhcp-relay",
                        "binary_version": "4.3.5-3ubuntu7.4"
                      },
                      {
                        "binary_name": "isc-dhcp-server",
                        "binary_version": "4.3.5-3ubuntu7.4"
                      },
                      {
                        "binary_name": "isc-dhcp-server-ldap",
                        "binary_version": "4.3.5-3ubuntu7.4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:18.04:LTS",
                    "name": "isc-dhcp",
                    "purl": "pkg:deb/ubuntu/isc-dhcp?arch=source\u0026distro=bionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "4.3.5-3ubuntu2",
                    "4.3.5-3ubuntu3",
                    "4.3.5-3ubuntu4",
                    "4.3.5-3ubuntu5",
                    "4.3.5-3ubuntu6",
                    "4.3.5-3ubuntu7",
                    "4.3.5-3ubuntu7.1",
                    "4.3.5-3ubuntu7.2",
                    "4.3.5-3ubuntu7.3",
                    "4.3.5-3ubuntu7.4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      },
                      {
                        "binary_name": "bind9-dnsutils",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      },
                      {
                        "binary_name": "bind9-libs",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      },
                      {
                        "binary_name": "bind9-utils",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      },
                      {
                        "binary_name": "bind9utils",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      },
                      {
                        "binary_name": "dnsutils",
                        "binary_version": "1:9.18.30-0ubuntu0.20.04.2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.11.5.P4+dfsg-5.1ubuntu2",
                    "1:9.11.5.P4+dfsg-5.1ubuntu3",
                    "1:9.11.5.P4+dfsg-5.1ubuntu4",
                    "1:9.11.5.P4+dfsg-5.1ubuntu5",
                    "1:9.11.14+dfsg-1ubuntu1",
                    "1:9.11.14+dfsg-3ubuntu1",
                    "1:9.16.0-1ubuntu3",
                    "1:9.16.0-1ubuntu4",
                    "1:9.16.0-1ubuntu5",
                    "1:9.16.1-0ubuntu1",
                    "1:9.16.1-0ubuntu2",
                    "1:9.16.1-0ubuntu2.1",
                    "1:9.16.1-0ubuntu2.2",
                    "1:9.16.1-0ubuntu2.3",
                    "1:9.16.1-0ubuntu2.4",
                    "1:9.16.1-0ubuntu2.6",
                    "1:9.16.1-0ubuntu2.7",
                    "1:9.16.1-0ubuntu2.8",
                    "1:9.16.1-0ubuntu2.9",
                    "1:9.16.1-0ubuntu2.10",
                    "1:9.16.1-0ubuntu2.11",
                    "1:9.16.1-0ubuntu2.12",
                    "1:9.16.1-0ubuntu2.14",
                    "1:9.16.1-0ubuntu2.15",
                    "1:9.16.1-0ubuntu2.16",
                    "1:9.16.48-0ubuntu0.20.04.1",
                    "1:9.18.28-0ubuntu0.20.04.1",
                    "1:9.18.30-0ubuntu0.20.04.1",
                    "1:9.18.30-0ubuntu0.20.04.2",
                    "1:9.18.30-0ubuntu0.20.04.2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libbind9-161",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libdns-export1109",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libdns1109",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libirs-export161",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libirs161",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libisc-export1105",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libisc1105",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libisccc-export161",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libisccc161",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libisccfg-export163",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "libisccfg163",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      },
                      {
                        "binary_name": "liblwres161",
                        "binary_version": "1:9.11.16+dfsg-3~ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:20.04:LTS",
                    "name": "bind9-libs",
                    "purl": "pkg:deb/ubuntu/bind9-libs?arch=source\u0026distro=focal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.11.16+dfsg-3~build1",
                    "1:9.11.16+dfsg-3~ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      },
                      {
                        "binary_name": "bind9-dnsutils",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      },
                      {
                        "binary_name": "bind9-libs",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      },
                      {
                        "binary_name": "bind9-utils",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      },
                      {
                        "binary_name": "bind9utils",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      },
                      {
                        "binary_name": "dnsutils",
                        "binary_version": "1:9.18.39-0ubuntu0.22.04.5"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.16.15-1ubuntu1",
                    "1:9.16.15-1ubuntu2",
                    "1:9.16.15-1ubuntu3",
                    "1:9.18.0-2ubuntu1",
                    "1:9.18.0-2ubuntu2",
                    "1:9.18.0-2ubuntu3",
                    "1:9.18.1-1ubuntu1",
                    "1:9.18.1-1ubuntu1.1",
                    "1:9.18.1-1ubuntu1.2",
                    "1:9.18.1-1ubuntu1.3",
                    "1:9.18.12-0ubuntu0.22.04.1",
                    "1:9.18.12-0ubuntu0.22.04.2",
                    "1:9.18.12-0ubuntu0.22.04.3",
                    "1:9.18.18-0ubuntu0.22.04.1",
                    "1:9.18.18-0ubuntu0.22.04.2",
                    "1:9.18.24-0ubuntu0.22.04.1",
                    "1:9.18.28-0ubuntu0.22.04.1",
                    "1:9.18.30-0ubuntu0.22.04.1",
                    "1:9.18.30-0ubuntu0.22.04.2",
                    "1:9.18.39-0ubuntu0.22.04.1",
                    "1:9.18.39-0ubuntu0.22.04.2",
                    "1:9.18.39-0ubuntu0.22.04.3",
                    "1:9.18.39-0ubuntu0.22.04.4",
                    "1:9.18.39-0ubuntu0.22.04.5"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libbind9-161",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libdns-export1110",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libdns1110",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libirs-export161",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libirs161",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libisc-export1105",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libisc1105",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libisccc-export161",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libisccc161",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libisccfg-export163",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "libisccfg163",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      },
                      {
                        "binary_name": "liblwres161",
                        "binary_version": "1:9.11.19+dfsg-2.1ubuntu3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "bind9-libs",
                    "purl": "pkg:deb/ubuntu/bind9-libs?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.11.19+dfsg-2.1ubuntu1",
                    "1:9.11.19+dfsg-2.1ubuntu2",
                    "1:9.11.19+dfsg-2.1ubuntu3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      },
                      {
                        "binary_name": "bind9-dnsutils",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      },
                      {
                        "binary_name": "bind9-libs",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      },
                      {
                        "binary_name": "bind9-utils",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      },
                      {
                        "binary_name": "bind9utils",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      },
                      {
                        "binary_name": "dnsutils",
                        "binary_version": "1:9.18.39-0ubuntu0.24.04.6"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.18.18-0ubuntu2",
                    "1:9.18.21-0ubuntu1",
                    "1:9.18.24-0ubuntu3",
                    "1:9.18.24-0ubuntu4",
                    "1:9.18.24-0ubuntu5",
                    "1:9.18.28-0ubuntu0.24.04.1",
                    "1:9.18.30-0ubuntu0.24.04.1",
                    "1:9.18.30-0ubuntu0.24.04.2",
                    "1:9.18.39-0ubuntu0.24.04.1",
                    "1:9.18.39-0ubuntu0.24.04.2",
                    "1:9.18.39-0ubuntu0.24.04.3",
                    "1:9.18.39-0ubuntu0.24.04.5",
                    "1:9.18.39-0ubuntu0.24.04.6"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "isc-dhcp-client",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-client-ddns",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-common",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-keama",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-relay",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-server",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-server-ldap",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "isc-dhcp",
                    "purl": "pkg:deb/ubuntu/isc-dhcp?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "4.4.3-P1-2ubuntu5",
                    "4.4.3-P1-4ubuntu1",
                    "4.4.3-P1-4ubuntu2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "bind9",
                        "binary_version": "1:9.20.24-1ubuntu0.2"
                      },
                      {
                        "binary_name": "bind9-dnsutils",
                        "binary_version": "1:9.20.24-1ubuntu0.2"
                      },
                      {
                        "binary_name": "bind9-host",
                        "binary_version": "1:9.20.24-1ubuntu0.2"
                      },
                      {
                        "binary_name": "bind9-libs",
                        "binary_version": "1:9.20.24-1ubuntu0.2"
                      },
                      {
                        "binary_name": "bind9-utils",
                        "binary_version": "1:9.20.24-1ubuntu0.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "bind9",
                    "purl": "pkg:deb/ubuntu/bind9?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1:9.20.11-1ubuntu2",
                    "1:9.20.11-1ubuntu3",
                    "1:9.20.18-1ubuntu1",
                    "1:9.20.18-1ubuntu2",
                    "1:9.20.18-1ubuntu2.1",
                    "1:9.20.24-1ubuntu0.1",
                    "1:9.20.24-1ubuntu0.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-13204.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "isc-dhcp-client",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-client-ddns",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-common",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-keama",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-relay",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-server",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      },
                      {
                        "binary_name": "isc-dhcp-server-ldap",
                        "binary_version": "4.4.3-P1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "isc-dhcp",
                    "purl": "pkg:deb/ubuntu/isc-dhcp?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "4.4.3-P1-4ubuntu2"
                  ]
                }
              ],
              "details": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.",
              "id": "UBUNTU-CVE-2026-13204",
              "modified": "2026-08-19T19:12:22.170284242Z",
              "published": "2026-07-22T15:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-13204"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-13204"
                },
                {
                  "type": "REPORT",
                  "url": "https://kb.isc.org/docs/cve-2026-13204"
                }
              ],
              "schema_version": "1.9.0",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-13204"
              ]
            }
          ]
        },
        {
          "package": {
            "name": "jq",
            "version": "1.8.1-4ubuntu2",
            "ecosystem": "Ubuntu"
          },
          "groups": [
            {
              "ids": [
                "UBUNTU-CVE-2025-9403"
              ],
              "aliases": [
                "CVE-2025-9403",
                "UBUNTU-CVE-2025-9403"
              ],
              "experimental_analysis": {
                "UBUNTU-CVE-2025-9403": {
                  "called": true,
                  "unimportant": true
                }
              },
              "max_severity": "5.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-40612"
              ],
              "aliases": [
                "CVE-2026-40612",
                "UBUNTU-CVE-2026-40612"
              ],
              "max_severity": "5.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-41256"
              ],
              "aliases": [
                "CVE-2026-41256",
                "UBUNTU-CVE-2026-41256"
              ],
              "max_severity": "5.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-41257"
              ],
              "aliases": [
                "CVE-2026-41257",
                "UBUNTU-CVE-2026-41257"
              ],
              "max_severity": "6.4"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-43894"
              ],
              "aliases": [
                "CVE-2026-43894",
                "UBUNTU-CVE-2026-43894"
              ],
              "max_severity": "6.2"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-43895"
              ],
              "aliases": [
                "CVE-2026-43895",
                "UBUNTU-CVE-2026-43895"
              ],
              "max_severity": "4.4"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-43896"
              ],
              "aliases": [
                "CVE-2026-43896",
                "UBUNTU-CVE-2026-43896"
              ],
              "max_severity": "6.2"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-44777"
              ],
              "aliases": [
                "CVE-2026-44777",
                "UBUNTU-CVE-2026-44777"
              ],
              "max_severity": "5.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-47770"
              ],
              "aliases": [
                "CVE-2026-47770",
                "UBUNTU-CVE-2026-47770"
              ],
              "max_severity": "6.8"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-49839"
              ],
              "aliases": [
                "CVE-2026-49839",
                "UBUNTU-CVE-2026-49839"
              ],
              "max_severity": "7.1"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-54679"
              ],
              "aliases": [
                "CVE-2026-54679",
                "UBUNTU-CVE-2026-54679"
              ],
              "max_severity": "6.9"
            }
          ],
          "vulnerabilities": [
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-9403.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ],
                    "priority_reason": "affects test suite"
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.",
              "id": "UBUNTU-CVE-2025-9403",
              "modified": "2026-05-21T06:15:06.798433441Z",
              "published": "2025-08-25T03:15:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2025-9403"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2025-9403"
                },
                {
                  "type": "REPORT",
                  "url": "https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing"
                },
                {
                  "type": "REPORT",
                  "url": "https://vuldb.com/?ctiid.321239"
                },
                {
                  "type": "REPORT",
                  "url": "https://vuldb.com/?id.321239"
                },
                {
                  "type": "REPORT",
                  "url": "https://vuldb.com/?submit.633170"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P",
                  "type": "CVSS_V4"
                },
                {
                  "score": "negligible",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2025-9403"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40612.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.",
              "id": "UBUNTU-CVE-2026-40612",
              "modified": "2026-05-21T06:15:06.953304496Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-40612"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-40612"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P",
                  "type": "CVSS_V4"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-40612"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41256.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed.",
              "id": "UBUNTU-CVE-2026-41256",
              "modified": "2026-06-24T06:15:05.378768568Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-41256"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-41256"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/commit/5a015deae35d19e3ebbc65db6c157a80e76df738"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-41256"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41257.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.",
              "id": "UBUNTU-CVE-2026-41257",
              "modified": "2026-06-24T06:15:05.461657281Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-41257"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-41257"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/commit/01b3cded76daacbfddb7f8763700b0803bcb5c6f"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                  "type": "CVSS_V4"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-41257"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43894.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit).",
              "id": "UBUNTU-CVE-2026-43894",
              "modified": "2026-05-21T06:15:07.593010998Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-43894"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-43894"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-43894"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43895.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens.",
              "id": "UBUNTU-CVE-2026-43895",
              "modified": "2026-06-24T06:15:05.470572176Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-43895"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-43895"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/commit/9d223f153c3632a207fa071caaa6292da33ae361"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-43895"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-43896.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects.",
              "id": "UBUNTU-CVE-2026-43896",
              "modified": "2026-06-24T06:15:05.481266861Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-43896"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-43896"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/commit/532ccea6080ed6758f39fe9f6208a44b665023d2"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-43896"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44777.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.",
              "id": "UBUNTU-CVE-2026-44777",
              "modified": "2026-06-24T06:15:05.427937821Z",
              "published": "2026-05-11T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-44777"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-44777"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/commit/f58787c41835d9b17795730cb04925fdba25c71c"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P",
                  "type": "CVSS_V4"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-44777"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47770.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.",
              "id": "UBUNTU-CVE-2026-47770",
              "modified": "2026-06-29T23:15:42.427262808Z",
              "published": "2026-06-25T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-47770"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-47770"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/commit/7122866869960b55cea3646bc91334ef55787831"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/pull/3539"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-47770"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49839.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2.",
              "id": "UBUNTU-CVE-2026-49839",
              "modified": "2026-06-29T23:15:15.843424525Z",
              "published": "2026-06-25T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-49839"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-49839"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-49839"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.3-1.1ubuntu1.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.2-8",
                    "1.3-1",
                    "1.3-1.1ubuntu1",
                    "1.3-1.1ubuntu1.1",
                    "1.3-1.1ubuntu1.1+esm3",
                    "1.3-1.1ubuntu1.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-1ubuntu0.1+esm4"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4-2.1",
                    "1.5+dfsg-1",
                    "1.5+dfsg-1ubuntu0.1",
                    "1.5+dfsg-1ubuntu0.1+esm2",
                    "1.5+dfsg-1ubuntu0.1+esm3",
                    "1.5+dfsg-1ubuntu0.1+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.5+dfsg-2ubuntu0.1~esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2",
                    "1.5+dfsg-2ubuntu0.1~esm1",
                    "1.5+dfsg-2ubuntu0.1~esm2",
                    "1.5+dfsg-2ubuntu0.1~esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-1ubuntu0.20.04.1+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5+dfsg-2build1",
                    "1.6-1",
                    "1.6-1ubuntu0.20.04.1",
                    "1.6-1ubuntu0.20.04.1+esm1",
                    "1.6-1ubuntu0.20.04.1+esm2",
                    "1.6-1ubuntu0.20.04.1+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.6-2.1ubuntu3.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-2.1ubuntu2",
                    "1.6-2.1ubuntu3",
                    "1.6-2.1ubuntu3.1",
                    "1.6-2.1ubuntu3.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.7.1-3ubuntu0.24.04.2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.6-3",
                    "1.7-1",
                    "1.7.1-2",
                    "1.7.1-3",
                    "1.7.1-3build1",
                    "1.7.1-3ubuntu0.24.04.1",
                    "1.7.1-3ubuntu0.24.04.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-3ubuntu1.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.7.1-3ubuntu1",
                    "1.7.1-6ubuntu1",
                    "1.8.1-3ubuntu1",
                    "1.8.1-3ubuntu1.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54679.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "jq",
                        "binary_version": "1.8.1-4ubuntu2"
                      },
                      {
                        "binary_name": "libjq1",
                        "binary_version": "1.8.1-4ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "jq",
                    "purl": "pkg:deb/ubuntu/jq?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.1-3ubuntu1",
                    "1.8.1-4ubuntu1",
                    "1.8.1-4ubuntu2"
                  ]
                }
              ],
              "details": "jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2.",
              "id": "UBUNTU-CVE-2026-54679",
              "modified": "2026-06-29T23:19:14.010135578Z",
              "published": "2026-06-25T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-54679"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-54679"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-54679"
              ]
            }
          ]
        },
        {
          "package": {
            "name": "libssh2",
            "version": "1.11.1-1ubuntu0.26.04.3",
            "ecosystem": "Ubuntu"
          },
          "groups": [
            {
              "ids": [
                "UBUNTU-CVE-2026-66032"
              ],
              "aliases": [
                "CVE-2026-66032",
                "UBUNTU-CVE-2026-66032"
              ],
              "max_severity": "8.8"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-66033"
              ],
              "aliases": [
                "CVE-2026-66033",
                "UBUNTU-CVE-2026-66033"
              ],
              "max_severity": "8.7"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-66034"
              ],
              "aliases": [
                "CVE-2026-66034",
                "UBUNTU-CVE-2026-66034"
              ],
              "max_severity": "7.7"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-66035"
              ],
              "aliases": [
                "CVE-2026-66035",
                "UBUNTU-CVE-2026-66035"
              ],
              "max_severity": "7.7"
            }
          ],
          "vulnerabilities": [
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.4.3-2ubuntu0.2+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4.3-1",
                    "1.4.3-2",
                    "1.4.3-2ubuntu0.1",
                    "1.4.3-2ubuntu0.2",
                    "1.4.3-2ubuntu0.2+esm1",
                    "1.4.3-2ubuntu0.2+esm2",
                    "1.4.3-2ubuntu0.2+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.5.0-2ubuntu0.1+esm2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5.0-2",
                    "1.5.0-2ubuntu0.1",
                    "1.5.0-2ubuntu0.1+esm1",
                    "1.5.0-2ubuntu0.1+esm2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:18.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=bionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-1",
                    "1.8.0-1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-2.1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:20.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=focal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-2.1build1",
                    "1.8.0-2.1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.10.0-3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.9.0-3",
                    "1.10.0-2",
                    "1.10.0-2build1",
                    "1.10.0-3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.0-4.1ubuntu0.24.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.0-2",
                    "1.11.0-3",
                    "1.11.0-4",
                    "1.11.0-4.1build1",
                    "1.11.0-4.1build2",
                    "1.11.0-4.1ubuntu0.24.04.1",
                    "1.11.0-4.1ubuntu0.24.04.2",
                    "1.11.0-4.1ubuntu0.24.04.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66032.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.1-1ubuntu0.26.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.1-1build1",
                    "1.11.1-1build2",
                    "1.11.1-1ubuntu0.26.04.1",
                    "1.11.1-1ubuntu0.26.04.2",
                    "1.11.1-1ubuntu0.26.04.3"
                  ]
                }
              ],
              "details": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.",
              "id": "UBUNTU-CVE-2026-66032",
              "modified": "2026-07-29T08:01:44Z",
              "published": "2026-07-24T17:17:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-66032"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-66032"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/pull/2180"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-66032"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.4.3-2ubuntu0.2+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4.3-1",
                    "1.4.3-2",
                    "1.4.3-2ubuntu0.1",
                    "1.4.3-2ubuntu0.2",
                    "1.4.3-2ubuntu0.2+esm1",
                    "1.4.3-2ubuntu0.2+esm2",
                    "1.4.3-2ubuntu0.2+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.5.0-2ubuntu0.1+esm2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5.0-2",
                    "1.5.0-2ubuntu0.1",
                    "1.5.0-2ubuntu0.1+esm1",
                    "1.5.0-2ubuntu0.1+esm2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:18.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=bionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-1",
                    "1.8.0-1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-2.1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:20.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=focal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-2.1build1",
                    "1.8.0-2.1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.10.0-3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.9.0-3",
                    "1.10.0-2",
                    "1.10.0-2build1",
                    "1.10.0-3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.0-4.1ubuntu0.24.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.0-2",
                    "1.11.0-3",
                    "1.11.0-4",
                    "1.11.0-4.1build1",
                    "1.11.0-4.1build2",
                    "1.11.0-4.1ubuntu0.24.04.1",
                    "1.11.0-4.1ubuntu0.24.04.2",
                    "1.11.0-4.1ubuntu0.24.04.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66033.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.1-1ubuntu0.26.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.1-1build1",
                    "1.11.1-1build2",
                    "1.11.1-1ubuntu0.26.04.1",
                    "1.11.1-1ubuntu0.26.04.2",
                    "1.11.1-1ubuntu0.26.04.3"
                  ]
                }
              ],
              "details": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.",
              "id": "UBUNTU-CVE-2026-66033",
              "modified": "2026-07-29T08:01:44Z",
              "published": "2026-07-24T17:17:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-66033"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-66033"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/pull/2401"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-66033"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.4.3-2ubuntu0.2+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4.3-1",
                    "1.4.3-2",
                    "1.4.3-2ubuntu0.1",
                    "1.4.3-2ubuntu0.2",
                    "1.4.3-2ubuntu0.2+esm1",
                    "1.4.3-2ubuntu0.2+esm2",
                    "1.4.3-2ubuntu0.2+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.5.0-2ubuntu0.1+esm2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5.0-2",
                    "1.5.0-2ubuntu0.1",
                    "1.5.0-2ubuntu0.1+esm1",
                    "1.5.0-2ubuntu0.1+esm2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:18.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=bionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-1",
                    "1.8.0-1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-2.1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:20.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=focal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-2.1build1",
                    "1.8.0-2.1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.10.0-3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.9.0-3",
                    "1.10.0-2",
                    "1.10.0-2build1",
                    "1.10.0-3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.0-4.1ubuntu0.24.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.0-2",
                    "1.11.0-3",
                    "1.11.0-4",
                    "1.11.0-4.1build1",
                    "1.11.0-4.1build2",
                    "1.11.0-4.1ubuntu0.24.04.1",
                    "1.11.0-4.1ubuntu0.24.04.2",
                    "1.11.0-4.1ubuntu0.24.04.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66034.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.1-1ubuntu0.26.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.1-1build1",
                    "1.11.1-1build2",
                    "1.11.1-1ubuntu0.26.04.1",
                    "1.11.1-1ubuntu0.26.04.2",
                    "1.11.1-1ubuntu0.26.04.3"
                  ]
                }
              ],
              "details": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.",
              "id": "UBUNTU-CVE-2026-66034",
              "modified": "2026-07-29T08:01:44Z",
              "published": "2026-07-24T17:17:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-66034"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-66034"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/pull/2202"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-66034"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.4.3-2ubuntu0.2+esm3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.4.3-1",
                    "1.4.3-2",
                    "1.4.3-2ubuntu0.1",
                    "1.4.3-2ubuntu0.2",
                    "1.4.3-2ubuntu0.2+esm1",
                    "1.4.3-2ubuntu0.2+esm2",
                    "1.4.3-2ubuntu0.2+esm3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.5.0-2ubuntu0.1+esm2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=esm-apps%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.5.0-2",
                    "1.5.0-2ubuntu0.1",
                    "1.5.0-2ubuntu0.1+esm1",
                    "1.5.0-2ubuntu0.1+esm2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:18.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=bionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-1",
                    "1.8.0-1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.8.0-2.1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:20.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=focal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.8.0-2.1build1",
                    "1.8.0-2.1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1",
                        "binary_version": "1.10.0-3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.9.0-3",
                    "1.10.0-2",
                    "1.10.0-2build1",
                    "1.10.0-3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.0-4.1ubuntu0.24.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.0-2",
                    "1.11.0-3",
                    "1.11.0-4",
                    "1.11.0-4.1build1",
                    "1.11.0-4.1build2",
                    "1.11.0-4.1ubuntu0.24.04.1",
                    "1.11.0-4.1ubuntu0.24.04.2",
                    "1.11.0-4.1ubuntu0.24.04.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-66035.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libssh2-1t64",
                        "binary_version": "1.11.1-1ubuntu0.26.04.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "libssh2",
                    "purl": "pkg:deb/ubuntu/libssh2?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "1.11.1-1build1",
                    "1.11.1-1build2",
                    "1.11.1-1ubuntu0.26.04.1",
                    "1.11.1-1ubuntu0.26.04.2",
                    "1.11.1-1ubuntu0.26.04.3"
                  ]
                }
              ],
              "details": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.",
              "id": "UBUNTU-CVE-2026-66035",
              "modified": "2026-07-29T08:01:44Z",
              "published": "2026-07-24T17:17:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-66035"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-66035"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/pull/2198"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-66035"
              ]
            }
          ]
        },
        {
          "package": {
            "name": "libxml2",
            "version": "2.15.2+dfsg-0.1ubuntu0.1",
            "ecosystem": "Ubuntu"
          },
          "groups": [
            {
              "ids": [
                "UBUNTU-CVE-2026-11979"
              ],
              "aliases": [
                "CVE-2026-11979",
                "UBUNTU-CVE-2026-11979"
              ],
              "experimental_analysis": {
                "UBUNTU-CVE-2026-11979": {
                  "called": true,
                  "unimportant": true
                }
              },
              "max_severity": "7.8"
            }
          ],
          "vulnerabilities": [
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2",
                        "binary_version": "2.9.1+dfsg1-3ubuntu4.13+esm11"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.9.1+dfsg1-3ubuntu4.13+esm11"
                      },
                      {
                        "binary_name": "python-libxml2",
                        "binary_version": "2.9.1+dfsg1-3ubuntu4.13+esm11"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:14.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=esm-infra-legacy%2Ftrusty"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.9.1+dfsg1-3ubuntu2",
                    "2.9.1+dfsg1-3ubuntu3",
                    "2.9.1+dfsg1-3ubuntu4",
                    "2.9.1+dfsg1-3ubuntu4.1",
                    "2.9.1+dfsg1-3ubuntu4.2",
                    "2.9.1+dfsg1-3ubuntu4.3",
                    "2.9.1+dfsg1-3ubuntu4.4",
                    "2.9.1+dfsg1-3ubuntu4.5",
                    "2.9.1+dfsg1-3ubuntu4.6",
                    "2.9.1+dfsg1-3ubuntu4.7",
                    "2.9.1+dfsg1-3ubuntu4.8",
                    "2.9.1+dfsg1-3ubuntu4.9",
                    "2.9.1+dfsg1-3ubuntu4.10",
                    "2.9.1+dfsg1-3ubuntu4.11",
                    "2.9.1+dfsg1-3ubuntu4.12",
                    "2.9.1+dfsg1-3ubuntu4.13",
                    "2.9.1+dfsg1-3ubuntu4.13+esm1",
                    "2.9.1+dfsg1-3ubuntu4.13+esm2",
                    "2.9.1+dfsg1-3ubuntu4.13+esm3",
                    "2.9.1+dfsg1-3ubuntu4.13+esm4",
                    "2.9.1+dfsg1-3ubuntu4.13+esm5",
                    "2.9.1+dfsg1-3ubuntu4.13+esm6",
                    "2.9.1+dfsg1-3ubuntu4.13+esm7",
                    "2.9.1+dfsg1-3ubuntu4.13+esm8",
                    "2.9.1+dfsg1-3ubuntu4.13+esm9",
                    "2.9.1+dfsg1-3ubuntu4.13+esm10",
                    "2.9.1+dfsg1-3ubuntu4.13+esm11"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2",
                        "binary_version": "2.9.3+dfsg1-1ubuntu0.7+esm12"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.9.3+dfsg1-1ubuntu0.7+esm12"
                      },
                      {
                        "binary_name": "python-libxml2",
                        "binary_version": "2.9.3+dfsg1-1ubuntu0.7+esm12"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:16.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=esm-infra%2Fxenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.9.2+zdfsg1-4",
                    "2.9.2+zdfsg1-4ubuntu1",
                    "2.9.2+zdfsg1-4ubuntu2",
                    "2.9.2+zdfsg1-4ubuntu3",
                    "2.9.3+dfsg1-1",
                    "2.9.3+dfsg1-1ubuntu0.1",
                    "2.9.3+dfsg1-1ubuntu0.2",
                    "2.9.3+dfsg1-1ubuntu0.3",
                    "2.9.3+dfsg1-1ubuntu0.4",
                    "2.9.3+dfsg1-1ubuntu0.5",
                    "2.9.3+dfsg1-1ubuntu0.6",
                    "2.9.3+dfsg1-1ubuntu0.7",
                    "2.9.3+dfsg1-1ubuntu0.7+esm1",
                    "2.9.3+dfsg1-1ubuntu0.7+esm2",
                    "2.9.3+dfsg1-1ubuntu0.7+esm3",
                    "2.9.3+dfsg1-1ubuntu0.7+esm4",
                    "2.9.3+dfsg1-1ubuntu0.7+esm5",
                    "2.9.3+dfsg1-1ubuntu0.7+esm6",
                    "2.9.3+dfsg1-1ubuntu0.7+esm7",
                    "2.9.3+dfsg1-1ubuntu0.7+esm8",
                    "2.9.3+dfsg1-1ubuntu0.7+esm9",
                    "2.9.3+dfsg1-1ubuntu0.7+esm10",
                    "2.9.3+dfsg1-1ubuntu0.7+esm11",
                    "2.9.3+dfsg1-1ubuntu0.7+esm12"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2",
                        "binary_version": "2.9.4+dfsg1-6.1ubuntu1.9+esm7"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.9.4+dfsg1-6.1ubuntu1.9+esm7"
                      },
                      {
                        "binary_name": "python-libxml2",
                        "binary_version": "2.9.4+dfsg1-6.1ubuntu1.9+esm7"
                      },
                      {
                        "binary_name": "python3-libxml2",
                        "binary_version": "2.9.4+dfsg1-6.1ubuntu1.9+esm7"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=esm-infra%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.9.4+dfsg1-4ubuntu1",
                    "2.9.4+dfsg1-5ubuntu1",
                    "2.9.4+dfsg1-5ubuntu2",
                    "2.9.4+dfsg1-5.1ubuntu1",
                    "2.9.4+dfsg1-5.2ubuntu1",
                    "2.9.4+dfsg1-6.1ubuntu1",
                    "2.9.4+dfsg1-6.1ubuntu1.2",
                    "2.9.4+dfsg1-6.1ubuntu1.3",
                    "2.9.4+dfsg1-6.1ubuntu1.4",
                    "2.9.4+dfsg1-6.1ubuntu1.5",
                    "2.9.4+dfsg1-6.1ubuntu1.6",
                    "2.9.4+dfsg1-6.1ubuntu1.7",
                    "2.9.4+dfsg1-6.1ubuntu1.8",
                    "2.9.4+dfsg1-6.1ubuntu1.9",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm1",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm2",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm3",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm4",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm5",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm6",
                    "2.9.4+dfsg1-6.1ubuntu1.9+esm7"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2",
                        "binary_version": "2.9.10+dfsg-5ubuntu0.20.04.10+esm4"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.9.10+dfsg-5ubuntu0.20.04.10+esm4"
                      },
                      {
                        "binary_name": "python-libxml2",
                        "binary_version": "2.9.10+dfsg-5ubuntu0.20.04.10+esm4"
                      },
                      {
                        "binary_name": "python3-libxml2",
                        "binary_version": "2.9.10+dfsg-5ubuntu0.20.04.10+esm4"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=esm-infra%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.9.4+dfsg1-7ubuntu3",
                    "2.9.4+dfsg1-7ubuntu5",
                    "2.9.4+dfsg1-8ubuntu1",
                    "2.9.4+dfsg1-8ubuntu2",
                    "2.9.4+dfsg1-8ubuntu3",
                    "2.9.10+dfsg-1ubuntu3",
                    "2.9.10+dfsg-4build1",
                    "2.9.10+dfsg-5",
                    "2.9.10+dfsg-5ubuntu0.20.04.1",
                    "2.9.10+dfsg-5ubuntu0.20.04.2",
                    "2.9.10+dfsg-5ubuntu0.20.04.3",
                    "2.9.10+dfsg-5ubuntu0.20.04.4",
                    "2.9.10+dfsg-5ubuntu0.20.04.5",
                    "2.9.10+dfsg-5ubuntu0.20.04.6",
                    "2.9.10+dfsg-5ubuntu0.20.04.7",
                    "2.9.10+dfsg-5ubuntu0.20.04.8",
                    "2.9.10+dfsg-5ubuntu0.20.04.9",
                    "2.9.10+dfsg-5ubuntu0.20.04.10",
                    "2.9.10+dfsg-5ubuntu0.20.04.10+esm1",
                    "2.9.10+dfsg-5ubuntu0.20.04.10+esm2",
                    "2.9.10+dfsg-5ubuntu0.20.04.10+esm3",
                    "2.9.10+dfsg-5ubuntu0.20.04.10+esm4"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2",
                        "binary_version": "2.9.13+dfsg-1ubuntu0.12"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.9.13+dfsg-1ubuntu0.12"
                      },
                      {
                        "binary_name": "python3-libxml2",
                        "binary_version": "2.9.13+dfsg-1ubuntu0.12"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.9.12+dfsg-4",
                    "2.9.12+dfsg-5",
                    "2.9.12+dfsg-6",
                    "2.9.13+dfsg-1",
                    "2.9.13+dfsg-1build1",
                    "2.9.13+dfsg-1ubuntu0.1",
                    "2.9.13+dfsg-1ubuntu0.2",
                    "2.9.13+dfsg-1ubuntu0.3",
                    "2.9.13+dfsg-1ubuntu0.4",
                    "2.9.13+dfsg-1ubuntu0.5",
                    "2.9.13+dfsg-1ubuntu0.6",
                    "2.9.13+dfsg-1ubuntu0.7",
                    "2.9.13+dfsg-1ubuntu0.8",
                    "2.9.13+dfsg-1ubuntu0.9",
                    "2.9.13+dfsg-1ubuntu0.10",
                    "2.9.13+dfsg-1ubuntu0.11",
                    "2.9.13+dfsg-1ubuntu0.12"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2",
                        "binary_version": "2.9.14+dfsg-1.3ubuntu3.8"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.9.14+dfsg-1.3ubuntu3.8"
                      },
                      {
                        "binary_name": "python3-libxml2",
                        "binary_version": "2.9.14+dfsg-1.3ubuntu3.8"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.9.14+dfsg-1.3",
                    "2.9.14+dfsg-1.3build1",
                    "2.9.14+dfsg-1.3build2",
                    "2.9.14+dfsg-1.3build3",
                    "2.9.14+dfsg-1.3ubuntu1",
                    "2.9.14+dfsg-1.3ubuntu2",
                    "2.9.14+dfsg-1.3ubuntu3",
                    "2.9.14+dfsg-1.3ubuntu3.1",
                    "2.9.14+dfsg-1.3ubuntu3.2",
                    "2.9.14+dfsg-1.3ubuntu3.3",
                    "2.9.14+dfsg-1.3ubuntu3.4",
                    "2.9.14+dfsg-1.3ubuntu3.5",
                    "2.9.14+dfsg-1.3ubuntu3.6",
                    "2.9.14+dfsg-1.3ubuntu3.7",
                    "2.9.14+dfsg-1.3ubuntu3.8"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2-16",
                        "binary_version": "2.14.5+dfsg-0.2ubuntu0.2"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.14.5+dfsg-0.2ubuntu0.2"
                      },
                      {
                        "binary_name": "python3-libxml2",
                        "binary_version": "2.14.5+dfsg-0.2ubuntu0.2"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.12.7+dfsg+really2.9.14-0.4",
                    "2.12.7+dfsg+really2.9.14-0.4ubuntu0.1",
                    "2.12.7+dfsg+really2.9.14-1",
                    "2.14.3+dfsg-0exp1",
                    "2.14.3+dfsg-0exp2",
                    "2.14.3+dfsg-0exp3",
                    "2.14.4+dfsg-0exp1",
                    "2.14.5+dfsg-0exp1",
                    "2.14.5+dfsg-0exp2",
                    "2.14.5+dfsg-0.1",
                    "2.14.5+dfsg-0.2",
                    "2.14.5+dfsg-0.2ubuntu0.1",
                    "2.14.5+dfsg-0.2ubuntu0.2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-11979.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libxml2-16",
                        "binary_version": "2.15.2+dfsg-0.1ubuntu0.1"
                      },
                      {
                        "binary_name": "libxml2-source",
                        "binary_version": "2.15.2+dfsg-0.1ubuntu0.1"
                      },
                      {
                        "binary_name": "libxml2-utils",
                        "binary_version": "2.15.2+dfsg-0.1ubuntu0.1"
                      },
                      {
                        "binary_name": "python3-libxml2",
                        "binary_version": "2.15.2+dfsg-0.1ubuntu0.1"
                      }
                    ],
                    "priority_reason": "This is only a crash in a command line tool with no security impact."
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "libxml2",
                    "purl": "pkg:deb/ubuntu/libxml2?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.14.5+dfsg-0.2",
                    "2.14.5+dfsg-0.2build1",
                    "2.15.1+dfsg-0.3",
                    "2.15.1+dfsg-0.4",
                    "2.15.1+dfsg-1",
                    "2.15.1+dfsg-2",
                    "2.15.1+dfsg-2ubuntu1",
                    "2.15.1+dfsg-2ubuntu2",
                    "2.15.2+dfsg-0.1",
                    "2.15.2+dfsg-0.1ubuntu0.1"
                  ]
                }
              ],
              "details": "libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.",
              "id": "UBUNTU-CVE-2026-11979",
              "modified": "2026-07-07T21:03:18.551932826Z",
              "published": "2026-06-29T14:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-11979"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-11979"
                },
                {
                  "type": "REPORT",
                  "url": "https://cert.pl/en/posts/2026/06/CVE-2026-11979"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "negligible",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-11979"
              ]
            }
          ]
        },
        {
          "package": {
            "name": "lmdb",
            "version": "0.9.31-1build2",
            "ecosystem": "Ubuntu"
          },
          "groups": [
            {
              "ids": [
                "UBUNTU-CVE-2026-22185"
              ],
              "aliases": [
                "CVE-2026-22185",
                "UBUNTU-CVE-2026-22185"
              ],
              "max_severity": "4.6"
            }
          ],
          "vulnerabilities": [
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.17-3"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.17-3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.15-1",
                    "0.9.16-1",
                    "0.9.17-1",
                    "0.9.17-3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.21-1ubuntu0.1"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.21-1ubuntu0.1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:18.04:LTS",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=bionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.21-1",
                    "0.9.21-1ubuntu0.1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.24-1"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.24-1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:20.04:LTS",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=focal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.23-0ubuntu1",
                    "0.9.24-1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.24-1build2"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.24-1build2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:22.04:LTS",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=jammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.24-1",
                    "0.9.24-1build1",
                    "0.9.24-1build2"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.31-1build1"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.31-1build1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:24.04:LTS",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=noble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.31-1",
                    "0.9.31-1build1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.31-1build1"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.31-1build1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.31-1build1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "liblmdb0",
                        "binary_version": "0.9.31-1build2"
                      },
                      {
                        "binary_name": "lmdb-utils",
                        "binary_version": "0.9.31-1build2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "lmdb",
                    "purl": "pkg:deb/ubuntu/lmdb?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "0.9.31-1build1",
                    "0.9.31-1build2"
                  ]
                }
              ],
              "details": "OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.",
              "id": "UBUNTU-CVE-2026-22185",
              "modified": "2026-05-20T16:24:12.483007033Z",
              "published": "2026-01-07T21:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-22185"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-22185"
                },
                {
                  "type": "REPORT",
                  "url": "https://seclists.org/fulldisclosure/2026/Jan/5"
                },
                {
                  "type": "REPORT",
                  "url": "https://seclists.org/fulldisclosure/2026/Jan/8"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                  "type": "CVSS_V4"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-22185"
              ]
            }
          ]
        },
        {
          "package": {
            "name": "mbedtls",
            "version": "3.6.5-0.1ubuntu2",
            "ecosystem": "Ubuntu"
          },
          "groups": [
            {
              "ids": [
                "UBUNTU-CVE-2018-1000520"
              ],
              "aliases": [
                "CVE-2018-1000520",
                "UBUNTU-CVE-2018-1000520"
              ],
              "max_severity": "7.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2021-24119"
              ],
              "aliases": [
                "CVE-2021-24119",
                "UBUNTU-CVE-2021-24119"
              ],
              "max_severity": "4.9"
            },
            {
              "ids": [
                "UBUNTU-CVE-2025-49087"
              ],
              "aliases": [
                "CVE-2025-49087",
                "UBUNTU-CVE-2025-49087"
              ],
              "max_severity": "4.0"
            },
            {
              "ids": [
                "UBUNTU-CVE-2025-49600"
              ],
              "aliases": [
                "CVE-2025-49600",
                "UBUNTU-CVE-2025-49600"
              ],
              "max_severity": "4.9"
            },
            {
              "ids": [
                "UBUNTU-CVE-2025-49601"
              ],
              "aliases": [
                "CVE-2025-49601",
                "UBUNTU-CVE-2025-49601"
              ],
              "max_severity": "6.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2025-66442"
              ],
              "aliases": [
                "CVE-2025-66442",
                "UBUNTU-CVE-2025-66442"
              ],
              "max_severity": "5.1"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-25832"
              ],
              "aliases": [
                "CVE-2026-25832",
                "UBUNTU-CVE-2026-25832"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-25833"
              ],
              "aliases": [
                "CVE-2026-25833",
                "UBUNTU-CVE-2026-25833"
              ],
              "max_severity": "7.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-25834"
              ],
              "aliases": [
                "CVE-2026-25834",
                "UBUNTU-CVE-2026-25834"
              ],
              "max_severity": "6.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-25835"
              ],
              "aliases": [
                "CVE-2026-25835",
                "UBUNTU-CVE-2026-25835"
              ],
              "max_severity": "7.7"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34871"
              ],
              "aliases": [
                "CVE-2026-34871",
                "UBUNTU-CVE-2026-34871"
              ],
              "max_severity": "6.7"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34872"
              ],
              "aliases": [
                "CVE-2026-34872",
                "UBUNTU-CVE-2026-34872"
              ],
              "max_severity": "9.1"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34873"
              ],
              "aliases": [
                "CVE-2026-34873",
                "UBUNTU-CVE-2026-34873"
              ],
              "max_severity": "9.1"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34874"
              ],
              "aliases": [
                "CVE-2026-34874",
                "UBUNTU-CVE-2026-34874"
              ],
              "max_severity": "7.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34875"
              ],
              "aliases": [
                "CVE-2026-34875",
                "UBUNTU-CVE-2026-34875"
              ],
              "max_severity": "9.8"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34876"
              ],
              "aliases": [
                "CVE-2026-34876",
                "UBUNTU-CVE-2026-34876"
              ],
              "max_severity": "7.5"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-34877"
              ],
              "aliases": [
                "CVE-2026-34877",
                "UBUNTU-CVE-2026-34877"
              ],
              "max_severity": "9.8"
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-35336"
              ],
              "aliases": [
                "CVE-2026-35336",
                "UBUNTU-CVE-2026-35336"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-49300"
              ],
              "aliases": [
                "CVE-2026-49300",
                "UBUNTU-CVE-2026-49300"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50579"
              ],
              "aliases": [
                "CVE-2026-50579",
                "UBUNTU-CVE-2026-50579"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50580"
              ],
              "aliases": [
                "CVE-2026-50580",
                "UBUNTU-CVE-2026-50580"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50581"
              ],
              "aliases": [
                "CVE-2026-50581",
                "UBUNTU-CVE-2026-50581"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50583"
              ],
              "aliases": [
                "CVE-2026-50583",
                "UBUNTU-CVE-2026-50583"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50584"
              ],
              "aliases": [
                "CVE-2026-50584",
                "UBUNTU-CVE-2026-50584"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50585"
              ],
              "aliases": [
                "CVE-2026-50585",
                "UBUNTU-CVE-2026-50585"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50586"
              ],
              "aliases": [
                "CVE-2026-50586",
                "UBUNTU-CVE-2026-50586"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50587"
              ],
              "aliases": [
                "CVE-2026-50587",
                "UBUNTU-CVE-2026-50587"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50588"
              ],
              "aliases": [
                "CVE-2026-50588",
                "UBUNTU-CVE-2026-50588"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50640"
              ],
              "aliases": [
                "CVE-2026-50640",
                "UBUNTU-CVE-2026-50640"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-50713"
              ],
              "aliases": [
                "CVE-2026-50713",
                "UBUNTU-CVE-2026-50713"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-54435"
              ],
              "aliases": [
                "CVE-2026-54435",
                "UBUNTU-CVE-2026-54435"
              ],
              "max_severity": ""
            },
            {
              "ids": [
                "UBUNTU-CVE-2026-54441"
              ],
              "aliases": [
                "CVE-2026-54441",
                "UBUNTU-CVE-2026-54441"
              ],
              "max_severity": ""
            }
          ],
          "vulnerabilities": [
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000520.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones should be.. This attack appear to be exploitable via Peers negotiate a TLS-ECDH-RSA-* ciphersuite. Any of the peers can then provide an ECDSA-signed certificate, when only an RSA-signed one should be accepted..",
              "id": "UBUNTU-CVE-2018-1000520",
              "modified": "2026-05-20T16:03:17.926467208Z",
              "published": "2018-06-26T16:29:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2018-1000520"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/ARMmbed/mbedtls/issues/1561"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000520"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "low",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2018-1000520"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-24119.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.",
              "id": "UBUNTU-CVE-2021-24119",
              "modified": "2026-05-20T16:04:48.948913829Z",
              "published": "2021-07-14T13:15:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2021-24119"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/ARMmbed/mbedtls/releases"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/UzL-ITS/util-lookup/blob/main/cve-vulnerability-publication.md"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2021-24119"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "low",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2021-24119"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49087.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49087.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.",
              "id": "UBUNTU-CVE-2025-49087",
              "modified": "2026-05-20T16:23:32.741955660Z",
              "published": "2025-07-20T19:15:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2025-49087"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2025-49087"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-5.md"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2025-49087"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49600.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49600.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbedtls_lms_verify allow an attacker (who can induce a hardware hash accelerator fault) to bypass LMS signature verification by reusing stale stack data, resulting in acceptance of an invalid signature. In mbedtls_lms_verify, the return values of the internal Merkle tree functions create_merkle_leaf_value and create_merkle_internal_value are not checked. These functions return an integer that indicates whether the call succeeded or not. If a failure occurs, the output buffer (Tc_candidate_root_node) may remain uninitialized, and the result of the signature verification is unpredictable. When the software implementation of SHA-256 is used, these functions will not fail. However, with hardware-accelerated hashing, an attacker could use fault injection against the accelerator to bypass verification.",
              "id": "UBUNTU-CVE-2025-49600",
              "modified": "2026-05-20T16:23:32.792976463Z",
              "published": "2025-07-04T15:15:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2025-49600"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2025-49600"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-3.md"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2025-49600"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49601.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49601.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_lms_import_public_key allows context-dependent attackers to trigger a crash or limited adjacent-memory disclosure by supplying a truncated LMS (Leighton-Micali Signature) public-key buffer under four bytes. An LMS public key starts with a 4-byte type indicator. The function mbedtls_lms_import_public_key reads this type indicator before validating the size of its input.",
              "id": "UBUNTU-CVE-2025-49601",
              "modified": "2026-05-20T16:23:32.804422293Z",
              "published": "2025-07-04T15:15:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2025-49601"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2025-49601"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/Mbed-TLS/mbedtls-docs/blob/main/security-advisories/mbedtls-security-advisory-2025-06-4.md"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
                  "type": "CVSS_V3"
                },
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2025-49601"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-66442.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.",
              "id": "UBUNTU-CVE-2025-66442",
              "modified": "2026-05-20T16:23:42.039606963Z",
              "published": "2026-04-01T20:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2025-66442"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2025-66442"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/Mbed-TLS/TF-PSA-Crypto/releases"
                },
                {
                  "type": "REPORT",
                  "url": "https://github.com/Mbed-TLS/mbedtls/releases"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-compiler-induced-constant-time-violations/"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2025-66442"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25832.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25832.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25832.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25832.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25832.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25832.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-25832",
              "modified": "2026-07-23T09:30:17.669747273Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-25832"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-25832"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-25832"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25833.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function",
              "id": "UBUNTU-CVE-2026-25833",
              "modified": "2026-05-20T16:24:47.512840217Z",
              "published": "2026-04-01T19:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-25833"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-25833"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-25833"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25834.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.",
              "id": "UBUNTU-CVE-2026-25834",
              "modified": "2026-05-20T16:24:47.450700739Z",
              "published": "2026-04-01T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-25834"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-25834"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-25834"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-25835.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).",
              "id": "UBUNTU-CVE-2026-25835",
              "modified": "2026-05-20T16:24:48.011985694Z",
              "published": "2026-04-01T19:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-25835"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-25835"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-25835"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34871.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).",
              "id": "UBUNTU-CVE-2026-34871",
              "modified": "2026-05-20T16:25:35.064049519Z",
              "published": "2026-04-01T19:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34871"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34871"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34871"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34872.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).",
              "id": "UBUNTU-CVE-2026-34872",
              "modified": "2026-05-20T16:25:34.985186677Z",
              "published": "2026-04-01T20:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34872"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34872"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ffdh-peerkey-checks/"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34872"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34873.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.",
              "id": "UBUNTU-CVE-2026-34873",
              "modified": "2026-05-20T16:25:35.076700080Z",
              "published": "2026-04-01T21:17:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34873"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34873"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-client-impersonation-while-resuming-tls13-session/"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34873"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34874.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.",
              "id": "UBUNTU-CVE-2026-34874",
              "modified": "2026-05-20T16:25:35.664929771Z",
              "published": "2026-04-01T19:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34874"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34874"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34874"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34875.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.",
              "id": "UBUNTU-CVE-2026-34875",
              "modified": "2026-05-20T16:25:35.655751890Z",
              "published": "2026-04-01T18:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34875"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34875"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34875"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34876.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue affects the public multipart CCM API in Mbed TLS 3.x, where mbedtls_ccm_finish() can be invoked directly by applications. In Mbed TLS 4.x versions prior to the fix, the same missing validation exists in the internal implementation; however, the function is not exposed as part of the public API. Exploitation requires application-level invocation of the multipart CCM API.",
              "id": "UBUNTU-CVE-2026-34876",
              "modified": "2026-05-20T16:25:34.747303116Z",
              "published": "2026-04-02T16:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34876"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34876"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ccm-finish-boundary-check/"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34876"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.2-3ubuntu1"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.2-3ubuntu1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:25.10",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=questing"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34877.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.",
              "id": "UBUNTU-CVE-2026-34877",
              "modified": "2026-05-20T16:25:35.721211055Z",
              "published": "2026-04-02T17:16:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-34877"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-34877"
                },
                {
                  "type": "REPORT",
                  "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-serialized-data/"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "type": "CVSS_V3"
                },
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-34877"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35336.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35336.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35336.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35336.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35336.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-35336.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-35336",
              "modified": "2026-07-23T09:30:17.705056959Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-35336"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-35336"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-35336"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49300.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49300.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49300.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49300.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49300.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-49300.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-49300",
              "modified": "2026-07-23T09:30:22.084660354Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-49300"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-49300"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-49300"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50579.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50579.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50579.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50579.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50579.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50579.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50579",
              "modified": "2026-07-23T09:30:22.711640742Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50579"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50579"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50579"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50580.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50580.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50580.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50580.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50580.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50580.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50580",
              "modified": "2026-07-23T09:30:26.629417527Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50580"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50580"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50580"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50581.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50581.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50581.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50581.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50581.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50581.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50581",
              "modified": "2026-07-23T09:30:17.416750152Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50581"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50581"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50581"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50583.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50583.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50583.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50583.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50583.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50583.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50583",
              "modified": "2026-07-23T09:30:26.678582324Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50583"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50583"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50583"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50584.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50584.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50584.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50584.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50584.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50584.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50584",
              "modified": "2026-07-23T09:30:26.629210623Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50584"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50584"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50584"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50585.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50585.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50585.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50585.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50585.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50585.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50585",
              "modified": "2026-07-23T09:30:25.749025475Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50585"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50585"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50585"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50586.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50586.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50586.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50586.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50586.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50586.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50586",
              "modified": "2026-07-23T09:30:25.752697843Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50586"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50586"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50586"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50587.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50587.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50587.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50587.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50587.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50587.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50587",
              "modified": "2026-07-23T09:30:25.723561716Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50587"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50587"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50587"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50588.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50588.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50588.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50588.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50588.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50588.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50588",
              "modified": "2026-07-23T09:30:25.717959092Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50588"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50588"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50588"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50640.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50640.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50640.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50640.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50640.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50640.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50640",
              "modified": "2026-07-23T09:30:26.631163026Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50640"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50640"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50640"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50713.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50713.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50713.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50713.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50713.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-50713.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-50713",
              "modified": "2026-07-23T09:30:22.984589168Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-50713"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-50713"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-50713"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54435.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54435.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54435.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54435.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54435.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54435.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-54435",
              "modified": "2026-07-23T09:30:27.237114078Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-54435"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-54435"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-54435"
              ]
            },
            {
              "affected": [
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54441.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.2.1-2ubuntu0.3"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:16.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=xenial"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.1.2-1",
                    "2.2.0-1",
                    "2.2.1-1",
                    "2.2.1-2",
                    "2.2.1-2ubuntu0.1",
                    "2.2.1-2ubuntu0.2",
                    "2.2.1-2ubuntu0.3"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54441.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto1",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls10",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.8.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:18.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fbionic"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.5.1-1ubuntu1",
                    "2.6.0-1",
                    "2.7.0-2",
                    "2.8.0-1",
                    "2.8.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54441.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto3",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedtls12",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      },
                      {
                        "binary_name": "libmbedx509-0",
                        "binary_version": "2.16.4-1ubuntu2+esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:20.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Ffocal"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.2-1",
                    "2.16.3-1",
                    "2.16.4-1ubuntu2",
                    "2.16.4-1ubuntu2+esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54441.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1",
                        "binary_version": "2.28.0-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:22.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fjammy"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.16.9-0.1ubuntu1",
                    "2.16.11-0.1ubuntu1",
                    "2.16.11-0.3",
                    "2.28.0-1",
                    "2.28.0-1build1",
                    "2.28.0-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54441.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto7t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedtls14t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      },
                      {
                        "binary_name": "libmbedx509-1t64",
                        "binary_version": "2.28.8-1ubuntu0.1~esm1"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:Pro:24.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=esm-apps%2Fnoble"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "2.28.3-1",
                    "2.28.6-1ubuntu1",
                    "2.28.7-1ubuntu1",
                    "2.28.7-1.1ubuntu1",
                    "2.28.8-1",
                    "2.28.8-1ubuntu0.1~esm1"
                  ]
                },
                {
                  "database_specific": {
                    "source": "https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54441.json"
                  },
                  "ecosystem_specific": {
                    "binaries": [
                      {
                        "binary_name": "libmbedcrypto16",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedtls21",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      },
                      {
                        "binary_name": "libmbedx509-7",
                        "binary_version": "3.6.5-0.1ubuntu2"
                      }
                    ]
                  },
                  "package": {
                    "ecosystem": "Ubuntu:26.04:LTS",
                    "name": "mbedtls",
                    "purl": "pkg:deb/ubuntu/mbedtls?arch=source\u0026distro=resolute"
                  },
                  "ranges": [
                    {
                      "events": [
                        {
                          "introduced": "0"
                        }
                      ],
                      "type": "ECOSYSTEM"
                    }
                  ],
                  "versions": [
                    "3.6.2-3ubuntu1",
                    "3.6.5-0.1ubuntu1",
                    "3.6.5-0.1ubuntu2"
                  ]
                }
              ],
              "details": "[Unknown description]",
              "id": "UBUNTU-CVE-2026-54441",
              "modified": "2026-07-23T09:30:27.225153617Z",
              "published": "2026-07-23T00:00:00Z",
              "references": [
                {
                  "type": "REPORT",
                  "url": "https://ubuntu.com/security/CVE-2026-54441"
                },
                {
                  "type": "REPORT",
                  "url": "https://www.cve.org/CVERecord?id=CVE-2026-54441"
                }
              ],
              "schema_version": "1.7.5",
              "severity": [
                {
                  "score": "medium",
                  "type": "Ubuntu"
                }
              ],
              "upstream": [
                "CVE-2026-54441"
              ]
            }
          ]
        }
      ]
    }
  ],
  "experimental_config": {
    "licenses": {
      "summary": false,
      "allowlist": null
    }
  }
}
