{"id":"ECHO-f08c-7e47-8652","summary":"The vulnerable unexpand(1) code path (multibyte -t handling) was\nintroduced upstream in GNU coreutils 9.11. Debian trixie ships\ncoreutils 9.7-3, which predates it, so this CVE cannot be triggered in\nour build. No Echo patch is required. Re-evaluate if this spec is ever\nrebased to coreutils \u003e= 9.11.\n","modified":"2026-09-15T00:47:45.128766246Z","published":"2026-07-26T15:08:53.253Z","withdrawn":"2026-07-26T15:08:53.253Z","upstream":["CVE-2026-56392"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-56392"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-56392"}],"affected":[{"package":{"name":"coreutils","ecosystem":"Echo","purl":"pkg:deb/echo/coreutils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.7-3"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-f08c-7e47-8652.json"}}],"schema_version":"1.9.0"}