[CVE-2025-23266] False positive on RHCOS #9795
dark-vex
started this conversation in
False Detection
Replies: 1 comment 2 replies
-
|
Hello @dark-vex Thanks for your report! Trivy finds RedHat vulnerabilities based on contentSets. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2025-23266
Description
Trivy does report the package
toolboxvulnerable to CVE-2025-23266 on OCP/RHCOSAccording to RHEL advisory and vex feed only RHEL 9/10 and RHEL AI are vulnerable.
Reproduction Steps
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions