{
  "schema_version": 1,
  "app_id": "io.thepeoples.Sparrow",
  "slug": "sparrow",
  "version": "2.5.4",
  "scanned_at": "2026-09-02T04:30:52Z",
  "scanner": {
    "name": "trivy",
    "version": "0.73.0",
    "db_updated_at": "2026-09-01T19:20:44Z"
  },
  "input": {
    "kind": "tarball",
    "filename": "sparrowwallet-2.5.4-x86_64.tar.gz",
    "sha256": "c1a3180117866e48a19caf2d9ed6fe80fecec9fdf82b8fdbcc565d0d3aec7b6e",
    "extracted_without_scripts": true
  },
  "gate": {
    "result": "pass",
    "fail_on": "wrap CRITICAL"
  },
  "counts": {
    "wrap": {
      "critical": 0,
      "high": 0,
      "medium": 0,
      "low": 0,
      "unknown": 0
    },
    "vendor": {
      "critical": 0,
      "high": 4,
      "medium": 9,
      "low": 3,
      "unknown": 0
    }
  },
  "coverage": {
    "packages_seen": 75,
    "wrap": {
      "status": "inventoried",
      "packages_seen": 0,
      "notes": []
    },
    "vendor": {
      "status": "inventoried",
      "packages_seen": 75,
      "notes": [
        "jlink/jpackage module image",
        "jdk 25.0.2 from jpackage-state",
        "jdk 25.0.2 from runtime release",
        "read 44 pom.properties file(s) from jlink modules",
        "read 30 MANIFEST.MF versions without pom.properties",
        "trivy sbom on 75 derived PURLs"
      ]
    }
  },
  "findings": [
    {
      "id": "CVE-2024-6763",
      "severity": "MEDIUM",
      "pkg": "org.eclipse.jetty:jetty-http",
      "installed": "9.4.54.v20240208",
      "fixed": "12.0.12",
      "class": "vendor",
      "title": "org.eclipse.jetty:jetty-http: jetty: Jetty URI parsing of invalid authority"
    },
    {
      "id": "CVE-2025-11143",
      "severity": "LOW",
      "pkg": "org.eclipse.jetty:jetty-http",
      "installed": "9.4.54.v20240208",
      "fixed": "12.0.31, 12.1.5",
      "class": "vendor",
      "title": "org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing"
    },
    {
      "id": "CVE-2026-10532",
      "severity": "LOW",
      "pkg": "ch.qos.logback:logback-core",
      "installed": "1.5.32",
      "fixed": "1.5.34",
      "class": "vendor",
      "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ..."
    },
    {
      "id": "CVE-2026-2332",
      "severity": "HIGH",
      "pkg": "org.eclipse.jetty:jetty-http",
      "installed": "9.4.54.v20240208",
      "fixed": "12.1.7, 12.0.33, 11.0.29, 10.0.28, 9.4.60",
      "class": "vendor",
      "title": "org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing"
    },
    {
      "id": "CVE-2026-54512",
      "severity": "HIGH",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.18.8, 3.1.4, 2.21.4",
      "class": "vendor",
      "title": "jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass"
    },
    {
      "id": "CVE-2026-54513",
      "severity": "HIGH",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.18.8, 2.21.4, 3.1.4",
      "class": "vendor",
      "title": "jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution"
    },
    {
      "id": "CVE-2026-54514",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.18.8, 2.21.4, 3.1.4",
      "class": "vendor",
      "title": "jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution"
    },
    {
      "id": "CVE-2026-54515",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "3.1.4, 2.18.9, 2.21.5, 2.22.1",
      "class": "vendor",
      "title": "jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified"
    },
    {
      "id": "CVE-2026-54516",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.21.4, 3.1.4",
      "class": "vendor",
      "title": "jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties"
    },
    {
      "id": "CVE-2026-54517",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.21.4, 3.1.4",
      "class": "vendor",
      "title": "jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application"
    },
    {
      "id": "CVE-2026-54518",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.21.4",
      "class": "vendor",
      "title": "jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass"
    },
    {
      "id": "CVE-2026-59888",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.18.8, 2.21.4",
      "class": "vendor",
      "title": "com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records"
    },
    {
      "id": "CVE-2026-59889",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.21.5, 2.18.9, 2.22.1",
      "class": "vendor",
      "title": "jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization"
    },
    {
      "id": "CVE-2026-9828",
      "severity": "LOW",
      "pkg": "ch.qos.logback:logback-core",
      "installed": "1.5.32",
      "fixed": "1.5.33",
      "class": "vendor",
      "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ..."
    },
    {
      "id": "GHSA-mhm7-754m-9p8w",
      "severity": "MEDIUM",
      "pkg": "com.fasterxml.jackson.core:jackson-databind",
      "installed": "2.21.1",
      "fixed": "2.18.9, 2.21.5",
      "class": "vendor",
      "title": "jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`"
    },
    {
      "id": "GHSA-r7wm-3cxj-wff9",
      "severity": "HIGH",
      "pkg": "com.fasterxml.jackson.core:jackson-core",
      "installed": "2.21.1",
      "fixed": "2.18.8, 2.21.4",
      "class": "vendor",
      "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"
    }
  ]
}
