Trivy Vulnerability Report for branch main - #8
Open
github-actions[bot] wants to merge 1 commit into
Open
Conversation
github-actions
Bot
force-pushed
the
auto/trivy-scan/main
branch
4 times, most recently
from
July 15, 2026 02:16
5cf0153 to
d935f82
Compare
github-actions
Bot
force-pushed
the
auto/trivy-scan/main
branch
13 times, most recently
from
July 19, 2026 21:41
854cc58 to
2f87738
Compare
github-actions
Bot
force-pushed
the
auto/trivy-scan/main
branch
from
July 19, 2026 22:15
2f87738 to
2c68c33
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🛡️ Trivy Scan Report for branch
mainFile: cmd/go.mod
• Vulnerability ID: CVE-2026-25681
• Pkg: golang.org/x/net v0.38.0
• Severity: HIGH
• Title: golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
File: cmd/go.mod
• Vulnerability ID: CVE-2026-27136
• Pkg: golang.org/x/net v0.38.0
• Severity: HIGH
• Title: golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
File: cmd/go.mod
• Vulnerability ID: CVE-2026-33814
• Pkg: golang.org/x/net v0.38.0
• Severity: HIGH
• Title: net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
File: cmd/go.mod
• Vulnerability ID: CVE-2026-39821
• Pkg: golang.org/x/net v0.38.0
• Severity: HIGH
• Title: golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
File: go.mod
• Vulnerability ID: CVE-2024-25621
• Pkg: github.com/containerd/containerd v1.6.18
• Severity: HIGH
• Title: github.com/containerd/containerd: containerd local privilege escalation
File: go.mod
• Vulnerability ID: CVE-2025-15558
• Pkg: github.com/docker/cli v24.0.7+incompatible
• Severity: HIGH
• Title: docker/cli: Docker CLI for Windows: Privilege escalation via malicious plugin binaries
File: go.mod
• Vulnerability ID: CVE-2024-41110
• Pkg: github.com/docker/docker v24.0.7+incompatible
• Severity: CRITICAL
• Title: moby: Authz zero length regression
File: go.mod
• Vulnerability ID: CVE-2026-34040
• Pkg: github.com/docker/docker v24.0.7+incompatible
• Severity: HIGH
• Title: Moby: Moby: Authorization bypass vulnerability
File: go.mod
• Vulnerability ID: CVE-2026-41567
• Pkg: github.com/docker/docker v24.0.7+incompatible
• Severity: HIGH
• Title: docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload
File: go.mod
• Vulnerability ID: CVE-2026-42306
• Pkg: github.com/docker/docker v24.0.7+incompatible
• Severity: HIGH
• Title: Moby is an open source container framework. In Docker Engine prior to ...
File: go.mod
• Vulnerability ID: CVE-2025-31133
• Pkg: github.com/opencontainers/runc v1.2.0
• Severity: HIGH
• Title: runc: container escape via 'masked path' abuse due to mount race conditions
File: go.mod
• Vulnerability ID: CVE-2025-52565
• Pkg: github.com/opencontainers/runc v1.2.0
• Severity: HIGH
• Title: runc: container escape with malicious config due to /dev/console mount and related races
File: go.mod
• Vulnerability ID: CVE-2025-52881
• Pkg: github.com/opencontainers/runc v1.2.0
• Severity: HIGH
• Title: runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
File: go.mod
• Vulnerability ID: CVE-2024-45337
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
File: go.mod
• Vulnerability ID: CVE-2025-22869
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh
File: go.mod
• Vulnerability ID: CVE-2025-47913
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS
File: go.mod
• Vulnerability ID: CVE-2026-39828
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
File: go.mod
• Vulnerability ID: CVE-2026-39829
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
File: go.mod
• Vulnerability ID: CVE-2026-39830
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
File: go.mod
• Vulnerability ID: CVE-2026-39831
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
File: go.mod
• Vulnerability ID: CVE-2026-39832
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
File: go.mod
• Vulnerability ID: CVE-2026-39835
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
File: go.mod
• Vulnerability ID: CVE-2026-42508
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
File: go.mod
• Vulnerability ID: CVE-2026-46595
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
File: go.mod
• Vulnerability ID: CVE-2026-46597
• Pkg: golang.org/x/crypto v0.17.0
• Severity: HIGH
• Title: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
File: go.mod
• Vulnerability ID: CVE-2023-45288
• Pkg: golang.org/x/net v0.17.0
• Severity: HIGH
• Title: golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
File: go.mod
• Vulnerability ID: CVE-2024-45338
• Pkg: golang.org/x/net v0.17.0
• Severity: HIGH
• Title: golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
File: go.mod
• Vulnerability ID: CVE-2026-25681
• Pkg: golang.org/x/net v0.17.0
• Severity: HIGH
• Title: golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
File: go.mod
• Vulnerability ID: CVE-2026-27136
• Pkg: golang.org/x/net v0.17.0
• Severity: HIGH
• Title: golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
File: go.mod
• Vulnerability ID: CVE-2026-33814
• Pkg: golang.org/x/net v0.17.0
• Severity: HIGH
• Title: net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
File: go.mod
• Vulnerability ID: CVE-2026-39821
• Pkg: golang.org/x/net v0.17.0
• Severity: HIGH
• Title: golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
File: go.mod
• Vulnerability ID: CVE-2025-22868
• Pkg: golang.org/x/oauth2 v0.6.0
• Severity: HIGH
• Title: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws