Thanks @tbilou - I think I have reproduced your issue here.
grype demo.json
âś” Scanned for vulnerabilities [49 vulnerability matches]
├── by severity: 3 critical, 17 high, 20 medium, 6 low, 1 negligible (2 unknown)
└── by status: 41 fixed, 8 not-fixed, 0 ignored
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
golang.org/x/net v0.32.0 0.33.0 go-module GHSA-w32m-9786-jp63 High
libc6 2.35-0ubuntu3.8 deb CVE-2025-0395 Medium
libc6 2.35-0ubuntu3.8 deb CVE-2016-20013 Negligible
libssl3 3.0.2-0ubuntu1.18 deb CVE-2024-9143 Low
libssl3 3.0.2-0ubuntu1.18 deb CVE-2024-41996 Low
libssl3 3.0.2-0ubuntu1.18 deb CVE-2024-13176 Low
openjdk 17.0.13+12-LTS 1.8.0_441, 11.0.26, 17.0.14, 21.0.6, 23.0.2, 8.0.441 binary CVE-2025-21502 Medium
openssl 3.0.2 1.0.2zk, 1.1.1za, 3.0.15, 3.1.7, 3.2.3, 3.3.2 binary CVE-2024-5535 Critical
openssl 3.0.2 1.0.2zf, 1.1.1p, 3.0.4 binary CVE-2022-2068 Critical
openssl 3.0.2 1.0.2ze, 1.1.1o, 3.0.3 binary CVE-2022-1292 Critical
openssl 3.0.2 3.0.15, 3.1.7, 3.2.3, 3.3.2 binary CVE-2024-6119 High
openssl 3.0.2 1.1.1y, 3.0.14, 3.1.6, 3.2.2, 3.3.1 binary CVE-2024-4741 High
openssl 3.0.2 3.0.12, 3.1.4 binary CVE-2023-5363 High
openssl 3.0.2 1.1.1w, 3.0.11, 3.1.3 binary CVE-2023-4807 High
openssl 3.0.2 1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 binary CVE-2023-0464 High
openssl 3.0.2 3.0.8 binary CVE-2023-0401 High
openssl 3.0.2 1.0.2zg, 1.1.1t, 3.0.8 binary CVE-2023-0286 High
openssl 3.0.2 3.0.8 binary CVE-2023-0217 High
openssl 3.0.2 3.0.8 binary CVE-2023-0216 High
openssl 3.0.2 1.0.2zg, 1.1.1t, 3.0.8 binary CVE-2023-0215 High
openssl 3.0.2 1.1.1t, 3.0.8 binary CVE-2022-4450 High
openssl 3.0.2 3.0.8 binary CVE-2022-3996 High
openssl 3.0.2 3.0.7 binary CVE-2022-3786 High
openssl 3.0.2 3.0.7 binary CVE-2022-3602 High
openssl 3.0.2 3.0.6 binary CVE-2022-3358 High
openssl 3.0.2 3.0.3 binary CVE-2022-1473 High
openssl 3.0.2 1.0.2zl, 1.1.1zb, 3.0.16, 3.1.8, 3.2.4, 3.3.3 binary CVE-2024-9143 Medium
openssl 3.0.2 3.0.14, 3.1.6, 3.2.2, 3.3.1 binary CVE-2024-4603 Medium
openssl 3.0.2 1.0.2zj, 1.1.1x, 3.0.13, 3.1.5 binary CVE-2024-0727 Medium
openssl 3.0.2 3.0.13, 3.1.5, 3.2.1 binary CVE-2023-6237 Medium
openssl 3.0.2 3.0.13, 3.1.5, 3.2.1 binary CVE-2023-6129 Medium
openssl 3.0.2 1.0.2zj, 1.1.1x, 3.0.13, 3.1.5 binary CVE-2023-5678 Medium
openssl 3.0.2 3.0.10, 3.1.2 binary CVE-2023-3817 Medium
openssl 3.0.2 1.0.2zi, 1.1.1v, 3.0.10, 3.1.2 binary CVE-2023-3446 Medium
openssl 3.0.2 3.0.10, 3.1.2 binary CVE-2023-2975 Medium
openssl 3.0.2 1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 binary CVE-2023-2650 Medium
openssl 3.0.2 3.0.9, 3.1.1 binary CVE-2023-1255 Medium
openssl 3.0.2 1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 binary CVE-2023-0466 Medium
openssl 3.0.2 1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 binary CVE-2023-0465 Medium
openssl 3.0.2 1.0.2zg, 1.1.1t, 3.0.8 binary CVE-2022-4304 Medium
openssl 3.0.2 3.0.8 binary CVE-2022-4203 Medium
openssl 3.0.2 1.1.1q, 3.0.5 binary CVE-2022-2097 Medium
openssl 3.0.2 3.0.3 binary CVE-2022-1434 Medium
openssl 3.0.2 3.0.3 binary CVE-2022-1343 Medium
openssl 3.0.2 1.1.1y, 3.0.14, 3.1.6, 3.2.2 binary CVE-2024-2511 Unknown
openssl 3.0.2 1.0.2zl, 1.1.1zb, 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.1 binary CVE-2024-13176 Unknown
openssl 3.0.2-0ubuntu1.18 deb CVE-2024-9143 Low
openssl 3.0.2-0ubuntu1.18 deb CVE-2024-41996 Low
openssl 3.0.2-0ubuntu1.18 deb CVE-2024-13176 Low
I tried adding --distro ubuntu:22.04
but that didn’t help.