{"id":"ECHO-f08c-7e47-8652","upstream":["CVE-2026-56392"],"severity":[],"modified":"2026-07-26T15:08:53.253Z","affected":[{"package":{"ecosystem":"Echo","name":"coreutils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.7-3"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-56392"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-56392"}],"withdrawn":"2026-07-26T15:08:53.253Z","summary":"The vulnerable unexpand(1) code path (multibyte -t handling) was\nintroduced upstream in GNU coreutils 9.11. Debian trixie ships\ncoreutils 9.7-3, which predates it, so this CVE cannot be triggered in\nour build. No Echo patch is required. Re-evaluate if this spec is ever\nrebased to coreutils >= 9.11.\n"}