USN-8710-1

Source
https://ubuntu.com/security/notices/USN-8710-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8710-1
Upstream
Related
Published
2026-09-01T15:27:40Z
Modified
2026-09-02T02:41:27Z
Summary
libevent vulnerabilities
Details

Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a use-after-free, resulting in a denial of service or arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63381)

Rajat Raghav discovered that libevent incorrectly handled certain HTTP requests. An attacker could possibly use this issue to desynchronize HTTP request boundaries, resulting in HTTP request smuggling. (CVE-2026-63382)

Qiu Sihao discovered that libevent incorrectly handled certain malformed tagged RPC data. An attacker could possibly use this issue to trigger an out-of-bounds read, resulting in a denial of service. (CVE-2026-63383)

Qiu Sihao discovered that libevent incorrectly handled certain large payload lengths in tagged RPC data. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-63384)

Asaf Meizner discovered that libevent incorrectly handled certain HTTP URIs and header values. An attacker could possibly use this issue to cause HTTP messages to be interpreted inconsistently, resulting in security restrictions being bypassed. (CVE-2026-63385)

References

Affected packages

Ubuntu:22.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.12-stable-1ubuntu0.1

Affected versions

2.*
2.1.12-stable-1
2.1.12-stable-1build1
2.1.12-stable-1build2
2.1.12-stable-1build3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libevent-2.1-7",
            "binary_version": "2.1.12-stable-1ubuntu0.1"
        },
        {
            "binary_name": "libevent-core-2.1-7",
            "binary_version": "2.1.12-stable-1ubuntu0.1"
        },
        {
            "binary_name": "libevent-extra-2.1-7",
            "binary_version": "2.1.12-stable-1ubuntu0.1"
        },
        {
            "binary_name": "libevent-openssl-2.1-7",
            "binary_version": "2.1.12-stable-1ubuntu0.1"
        },
        {
            "binary_name": "libevent-pthreads-2.1-7",
            "binary_version": "2.1.12-stable-1ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63381",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"
Ubuntu:24.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.12-stable-9ubuntu2.1

Affected versions

2.*
2.1.12-stable-9
2.1.12-stable-9ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libevent-2.1-7t64",
            "binary_version": "2.1.12-stable-9ubuntu2.1"
        },
        {
            "binary_name": "libevent-core-2.1-7t64",
            "binary_version": "2.1.12-stable-9ubuntu2.1"
        },
        {
            "binary_name": "libevent-extra-2.1-7t64",
            "binary_version": "2.1.12-stable-9ubuntu2.1"
        },
        {
            "binary_name": "libevent-openssl-2.1-7t64",
            "binary_version": "2.1.12-stable-9ubuntu2.1"
        },
        {
            "binary_name": "libevent-pthreads-2.1-7t64",
            "binary_version": "2.1.12-stable-9ubuntu2.1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63381",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"
Ubuntu:26.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.12-stable-10ubuntu0.1

Affected versions

2.*
2.1.12-stable-10build1
2.1.12-stable-10build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libevent-2.1-7t64",
            "binary_version": "2.1.12-stable-10ubuntu0.1"
        },
        {
            "binary_name": "libevent-core-2.1-7t64",
            "binary_version": "2.1.12-stable-10ubuntu0.1"
        },
        {
            "binary_name": "libevent-extra-2.1-7t64",
            "binary_version": "2.1.12-stable-10ubuntu0.1"
        },
        {
            "binary_name": "libevent-openssl-2.1-7t64",
            "binary_version": "2.1.12-stable-10ubuntu0.1"
        },
        {
            "binary_name": "libevent-pthreads-2.1-7t64",
            "binary_version": "2.1.12-stable-10ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63381",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"
Ubuntu:Pro:14.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=esm-infra-legacy%2Ftrusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.21-stable-1ubuntu1.14.04.2+esm1

Affected versions

2.*
2.0.21-stable-1
2.0.21-stable-1ubuntu1
2.0.21-stable-1ubuntu1.14.04.1
2.0.21-stable-1ubuntu1.14.04.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libevent-2.0-5",
            "binary_version": "2.0.21-stable-1ubuntu1.14.04.2+esm1"
        },
        {
            "binary_name": "libevent-core-2.0-5",
            "binary_version": "2.0.21-stable-1ubuntu1.14.04.2+esm1"
        },
        {
            "binary_name": "libevent-extra-2.0-5",
            "binary_version": "2.0.21-stable-1ubuntu1.14.04.2+esm1"
        },
        {
            "binary_name": "libevent-openssl-2.0-5",
            "binary_version": "2.0.21-stable-1ubuntu1.14.04.2+esm1"
        },
        {
            "binary_name": "libevent-pthreads-2.0-5",
            "binary_version": "2.0.21-stable-1ubuntu1.14.04.2+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:14.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"
Ubuntu:Pro:16.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=esm-infra-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.21-stable-2ubuntu0.16.04.1+esm1

Affected versions

2.*
2.0.21-stable-2
2.0.21-stable-2ubuntu0.16.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libevent-2.0-5",
            "binary_version": "2.0.21-stable-2ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "libevent-core-2.0-5",
            "binary_version": "2.0.21-stable-2ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "libevent-extra-2.0-5",
            "binary_version": "2.0.21-stable-2ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "libevent-openssl-2.0-5",
            "binary_version": "2.0.21-stable-2ubuntu0.16.04.1+esm1"
        },
        {
            "binary_name": "libevent-pthreads-2.0-5",
            "binary_version": "2.0.21-stable-2ubuntu0.16.04.1+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:16.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"
Ubuntu:Pro:18.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.8-stable-4ubuntu0.1~esm1

Affected versions

2.*
2.1.8-stable-4
2.1.8-stable-4build1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libevent-2.1-6",
            "binary_version": "2.1.8-stable-4ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-core-2.1-6",
            "binary_version": "2.1.8-stable-4ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-extra-2.1-6",
            "binary_version": "2.1.8-stable-4ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-openssl-2.1-6",
            "binary_version": "2.1.8-stable-4ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-pthreads-2.1-6",
            "binary_version": "2.1.8-stable-4ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63381",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:18.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"
Ubuntu:Pro:20.04:LTS
libevent

Package

Name
libevent
Purl
pkg:deb/ubuntu/libevent?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.11-stable-1ubuntu0.1~esm1

Affected versions

2.*
2.1.8-stable-4build1
2.1.11-stable-1~exp0
2.1.11-stable-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libevent-2.1-7",
            "binary_version": "2.1.11-stable-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-core-2.1-7",
            "binary_version": "2.1.11-stable-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-extra-2.1-7",
            "binary_version": "2.1.11-stable-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-openssl-2.1-7",
            "binary_version": "2.1.11-stable-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "libevent-pthreads-2.1-7",
            "binary_version": "2.1.11-stable-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-63381",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63382",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63383",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63384",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-63385",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:20.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8710-1.json"