Image Scan #168
Annotations
10 errors, 11 warnings, and 3 notices
|
Scan for vulnerabilities
CVE-2026-39822 - HIGH severity - os: golang: Go os.Root: Symlink following vulnerability allows directory traversal vulnerability in stdlib
|
|
Scan for vulnerabilities
CVE-2026-39822 - HIGH severity - os: golang: Go os.Root: Symlink following vulnerability allows directory traversal vulnerability in stdlib
|
|
Scan for vulnerabilities
GHSA-hrxh-6v49-42gf - HIGH severity - gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities vulnerability in google.golang.org/grpc
|
|
Scan for vulnerabilities
CVE-2026-56852 - HIGH severity - A norm.Iter can enter an infinite loop when handling input containing ... vulnerability in golang.org/x/text
|
|
Scan for vulnerabilities
CVE-2026-42154 - HIGH severity - github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint vulnerability in github.com/prometheus/prometheus
|
|
Scan for vulnerabilities
CVE-2026-42151 - HIGH severity - github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API vulnerability in github.com/prometheus/prometheus
|
|
Scan for vulnerabilities
CVE-2025-63811 - HIGH severity - An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allow ... vulnerability in github.com/dvsekhvalnov/jose2go
|
|
Scan for vulnerabilities
CVE-2026-42306 - HIGH severity - github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup vulnerability in github.com/docker/docker
|
|
Scan for vulnerabilities
CVE-2026-41567 - HIGH severity - docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload vulnerability in github.com/docker/docker
|
|
Scan for vulnerabilities
CVE-2026-34040 - HIGH severity - Moby: Moby: Authorization bypass vulnerability vulnerability in github.com/docker/docker
|
|
Complete job
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744, aws-actions/configure-aws-credentials@5fd3084fc36e372ff1fff382a39b10d03659f355, crazy-max/ghaction-container-scan@4d8e0acba576e46016cbd65b9ecfc604e85e3990. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Scan for vulnerabilities
CVE-2026-42505 - MEDIUM severity - crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello vulnerability in stdlib
|
|
Scan for vulnerabilities
CVE-2026-2303 - MEDIUM severity - CVE-2026-2303 affecting package telegraf for versions less than 1.29.4-21 vulnerability in go.mongodb.org/mongo-driver
|
|
Scan for vulnerabilities
CVE-2026-44903 - MEDIUM severity - Prometheus is an open-source monitoring system and time series databas ... vulnerability in github.com/prometheus/prometheus
|
|
Scan for vulnerabilities
CVE-2026-40179 - MEDIUM severity - Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer vulnerability in github.com/prometheus/prometheus
|
|
Scan for vulnerabilities
CVE-2026-41568 - MEDIUM severity - github.com/docker/docker: github.com/moby/moby: Moby: Denial of Service via race condition in docker cp mount setup vulnerability in github.com/docker/docker
|
|
Scan for vulnerabilities
CVE-2026-33997 - MEDIUM severity - moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installation vulnerability in github.com/docker/docker
|
|
Scan for vulnerabilities
GHSA-xmrv-pmrh-hhx2 - MEDIUM severity - Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder vulnerability in github.com/aws/aws-sdk-go-v2/service/s3
|
|
Scan for vulnerabilities
GHSA-xmrv-pmrh-hhx2 - MEDIUM severity - Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder vulnerability in github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs
|
|
Scan for vulnerabilities
GHSA-xmrv-pmrh-hhx2 - MEDIUM severity - Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder vulnerability in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
|
|
Scan for vulnerabilities
Dockerfile not provided. Skipping sarif scan result.
|
|
Scan for vulnerabilities
CVE-2026-46600 - UNKNOWN severity - Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... vulnerability in golang.org/x/net
|
|
Scan for vulnerabilities
GO-2026-5932 - UNKNOWN severity - The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues vulnerability in golang.org/x/crypto
|
|
Scan for vulnerabilities
CVE-2026-26958 - LOW severity - filippo.io/edwards25519: filippo.io/edwards25519: Cryptographic integrity bypass due to incorrect MultiScalarMult results vulnerability in filippo.io/edwards25519
|
background
wait
wait-all
cancel
parallel
Loading