Skip to content

False positives CVE-2025-58050 #568

@RobinDinkel

Description

@RobinDinkel

Describe the bug

Hey,

CVE-2025-58050 only affects version 10.45 of PCRE2. Other versions should not report any vulnerability.

Current behavior

jf docker scan nginxinc/nginx-unprivileged:1.29.1-alpine-slim shows:

Image

Reproduction steps

jf docker scan nginxinc/nginx-unprivileged:1.29.1-alpine-slim

Expected behavior

No CVE reported.

JFrog CLI-Security version

jf version 2.78.10

JFrog CLI version (if applicable)

jf version 2.78.10

Operating system type and version

Ubuntu 24.04

JFrog Xray version

3.118.23

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions