Skip to content

Commit d935f82

Browse files
authored
chore: vulnerabilities detected by Trivy (HIGH/CRITICAL)
1 parent db86384 commit d935f82

2 files changed

Lines changed: 5007 additions & 0 deletions

File tree

tmp/pr-body.md

Lines changed: 145 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,145 @@
1+
# 🛡️ Trivy Scan Report for branch `main`
2+
* File: go.mod
3+
• Vulnerability ID: CVE-2026-53488
4+
• Pkg: github.com/containerd/containerd v1.7.32
5+
• Severity: HIGH
6+
• Title: github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
7+
8+
* File: go.mod
9+
• Vulnerability ID: CVE-2025-15558
10+
• Pkg: github.com/docker/cli v24.0.7+incompatible
11+
• Severity: HIGH
12+
• Title: docker/cli: Docker CLI for Windows: Privilege escalation via malicious plugin binaries
13+
14+
* File: go.mod
15+
• Vulnerability ID: CVE-2024-41110
16+
• Pkg: github.com/docker/docker v24.0.7+incompatible
17+
• Severity: CRITICAL
18+
• Title: moby: Authz zero length regression
19+
20+
* File: go.mod
21+
• Vulnerability ID: CVE-2026-34040
22+
• Pkg: github.com/docker/docker v24.0.7+incompatible
23+
• Severity: HIGH
24+
• Title: Moby: Moby: Authorization bypass vulnerability
25+
26+
* File: go.mod
27+
• Vulnerability ID: CVE-2026-41567
28+
• Pkg: github.com/docker/docker v24.0.7+incompatible
29+
• Severity: HIGH
30+
• Title: docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload
31+
32+
* File: go.mod
33+
• Vulnerability ID: CVE-2026-42306
34+
• Pkg: github.com/docker/docker v24.0.7+incompatible
35+
• Severity: HIGH
36+
• Title: Moby is an open source container framework. In Docker Engine prior to ...
37+
38+
* File: go.mod
39+
• Vulnerability ID: CVE-2025-31133
40+
• Pkg: github.com/opencontainers/runc v1.2.0
41+
• Severity: HIGH
42+
• Title: runc: container escape via 'masked path' abuse due to mount race conditions
43+
44+
* File: go.mod
45+
• Vulnerability ID: CVE-2025-52565
46+
• Pkg: github.com/opencontainers/runc v1.2.0
47+
• Severity: HIGH
48+
• Title: runc: container escape with malicious config due to /dev/console mount and related races
49+
50+
* File: go.mod
51+
• Vulnerability ID: CVE-2025-52881
52+
• Pkg: github.com/opencontainers/runc v1.2.0
53+
• Severity: HIGH
54+
• Title: runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
55+
56+
* File: go.mod
57+
• Vulnerability ID: CVE-2026-39828
58+
• Pkg: golang.org/x/crypto v0.45.0
59+
• Severity: HIGH
60+
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
61+
62+
* File: go.mod
63+
• Vulnerability ID: CVE-2026-39829
64+
• Pkg: golang.org/x/crypto v0.45.0
65+
• Severity: HIGH
66+
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
67+
68+
* File: go.mod
69+
• Vulnerability ID: CVE-2026-39830
70+
• Pkg: golang.org/x/crypto v0.45.0
71+
• Severity: HIGH
72+
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
73+
74+
* File: go.mod
75+
• Vulnerability ID: CVE-2026-39831
76+
• Pkg: golang.org/x/crypto v0.45.0
77+
• Severity: HIGH
78+
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
79+
80+
* File: go.mod
81+
• Vulnerability ID: CVE-2026-39832
82+
• Pkg: golang.org/x/crypto v0.45.0
83+
• Severity: HIGH
84+
• Title: golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
85+
86+
* File: go.mod
87+
• Vulnerability ID: CVE-2026-39835
88+
• Pkg: golang.org/x/crypto v0.45.0
89+
• Severity: HIGH
90+
• Title: golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
91+
92+
* File: go.mod
93+
• Vulnerability ID: CVE-2026-42508
94+
• Pkg: golang.org/x/crypto v0.45.0
95+
• Severity: HIGH
96+
• Title: golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
97+
98+
* File: go.mod
99+
• Vulnerability ID: CVE-2026-46595
100+
• Pkg: golang.org/x/crypto v0.45.0
101+
• Severity: HIGH
102+
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
103+
104+
* File: go.mod
105+
• Vulnerability ID: CVE-2026-46597
106+
• Pkg: golang.org/x/crypto v0.45.0
107+
• Severity: HIGH
108+
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
109+
110+
* File: go.mod
111+
• Vulnerability ID: CVE-2023-45288
112+
• Pkg: golang.org/x/net v0.17.0
113+
• Severity: HIGH
114+
• Title: golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
115+
116+
* File: go.mod
117+
• Vulnerability ID: CVE-2024-45338
118+
• Pkg: golang.org/x/net v0.17.0
119+
• Severity: HIGH
120+
• Title: golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
121+
122+
* File: go.mod
123+
• Vulnerability ID: CVE-2026-25681
124+
• Pkg: golang.org/x/net v0.17.0
125+
• Severity: HIGH
126+
• Title: golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
127+
128+
* File: go.mod
129+
• Vulnerability ID: CVE-2026-27136
130+
• Pkg: golang.org/x/net v0.17.0
131+
• Severity: HIGH
132+
• Title: golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
133+
134+
* File: go.mod
135+
• Vulnerability ID: CVE-2026-33814
136+
• Pkg: golang.org/x/net v0.17.0
137+
• Severity: HIGH
138+
• Title: net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
139+
140+
* File: go.mod
141+
• Vulnerability ID: CVE-2026-39821
142+
• Pkg: golang.org/x/net v0.17.0
143+
• Severity: HIGH
144+
• Title: golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
145+

0 commit comments

Comments
 (0)