Skip to content

Trivy Vulnerability Report for branch pf9-oidc#19

Open
github-actions[bot] wants to merge 1 commit intopf9-oidcfrom
auto/trivy-scan/pf9-oidc
Open

Trivy Vulnerability Report for branch pf9-oidc#19
github-actions[bot] wants to merge 1 commit intopf9-oidcfrom
auto/trivy-scan/pf9-oidc

Conversation

@github-actions
Copy link
Copy Markdown

@github-actions github-actions bot commented Aug 29, 2025

🛡️ Trivy Scan Report for branch pf9-oidc

  • File: go.mod
    • Vulnerability ID: CVE-2026-24051
    • Pkg: go.opentelemetry.io/otel/sdk v1.28.0
    • Severity: HIGH
    • Title: OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

  • File: go.mod
    • Vulnerability ID: CVE-2026-39883
    • Pkg: go.opentelemetry.io/otel/sdk v1.28.0
    • Severity: HIGH
    • Title: opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

  • File: go.mod
    • Vulnerability ID: CVE-2025-22868
    • Pkg: golang.org/x/oauth2 v0.21.0
    • Severity: HIGH
    • Title: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws

  • File: go.mod
    • Vulnerability ID: CVE-2026-33186
    • Pkg: google.golang.org/grpc v1.65.0
    • Severity: CRITICAL
    • Title: google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

@github-actions github-actions bot force-pushed the auto/trivy-scan/pf9-oidc branch from 62ddff3 to 7802dd3 Compare April 13, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant