CVE-2025-53770
CVEs:CVE-2025-53770
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 19 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVEs:CVE-2025-53770
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully test...
CVEs:CVE-2025-53770
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| sharepoint_server | affected | microsoft | — | — |
chromedriver-138.0.7204.96-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-mj9c-f5v6-7665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
chromedriver-138.0.7204.157-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
GHSA-5w32-633g-38jh
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-6558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| ipados | affected | apple | — | — |
| iphone_os | affected | apple | — | — |
| macos | affected | apple | — | — |
| safari | affected | apple | — | — |
| visionos | affected | apple | — | — |
| watchos | affected | apple | — | — |
| webkitgtk | affected | webkitgtk | — | — |
| wpe_webkit | affected | wpewebkit | — | — |
CVEs:CVE-2025-6558
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-6558
DEBIAN-CVE-2025-6558
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| webkit2gtk | affected | Debian:11 | webkit2gtk | — |
| webkit2gtk | affected | Debian:12 | webkit2gtk | — |
| webkit2gtk | affected | Debian:13 | webkit2gtk | — |
| webkit2gtk | affected | Debian:14 | webkit2gtk | — |
| wpewebkit | affected | Debian:11 | wpewebkit | — |
| wpewebkit | affected | Debian:12 | wpewebkit | — |
| wpewebkit | affected | Debian:13 | wpewebkit | — |
| wpewebkit | affected | Debian:14 | wpewebkit | — |
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-6558
CVEs:CVE-2025-38352
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
CVEs:CVE-2025-38352
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_...
CVEs:CVE-2025-38352
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| Linux | affected | Linux | — | — |
| linux_kernel | affected | Linux | — | — |
| linux_kernel | affected | linux | — | — |
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
CVEs:CVE-2025-38352
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact in www.velocidex.com/golang/velociraptor
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang/velociraptor | affected | www.velocidex.com | www.velocidex.com/golang/velociraptor | — |
Ollama vulnerable to Cross-Domain Token Exposure in github.com/ollama/ollama
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| mods | affected | chainguard | mods | — |
| mods | affected | wolfi | mods | — |
| ollama | affected | chainguard | ollama | — |
| ollama | affected | wolfi | ollama | — |
| ollama-fips | affected | chainguard | ollama-fips | — |
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
Ollama vulnerable to Cross-Domain Token Exposure
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| mods | affected | chainguard | mods | — |
| mods | affected | wolfi | mods | — |
| ollama | affected | chainguard | ollama | — |
| ollama | affected | wolfi | ollama | — |
| ollama-fips | affected | chainguard | ollama-fips | — |
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
| ollama/ollama | affected | github.com | — | — |
Ollama vulnerable to Cross-Domain Token Exposure
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
MCP Server Kubernetes vulnerable to command injection in several tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mcp-server-kubernetes | affected | npm | mcp-server-kubernetes | — |
MCP Server Kubernetes vulnerable to command injection in several tools
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mcp-server-kubernetes | affected | npm | mcp-server-kubernetes | — |
angular.js - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular.js | affected | Debian:11 | angular.js | — |
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVEs:CVE-2025-49741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
CVEs:CVE-2025-49741
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters with...
CVEs:CVE-2025-53355
MCP Server Kubernetes vulnerable to command injection in several tools
CVEs:CVE-2025-53355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mcp-server-kubernetes | affected | npm | mcp-server-kubernetes | — |
MCP Server Kubernetes vulnerable to command injection in several tools
CVEs:CVE-2025-53355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mcp-server-kubernetes | affected | npm | mcp-server-kubernetes | — |
MINI-cx94-p8gq-hj6h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.33 | affected | MinimOS | kube-apiserver-1.33 | — |
| kube-apiserver-1.33-compat | affected | MinimOS | kube-apiserver-1.33-compat | — |
| kube-controller-manager-1.33 | affected | MinimOS | kube-controller-manager-1.33 | — |
| kube-controller-manager-1.33-compat | affected | MinimOS | kube-controller-manager-1.33-compat | — |
| kubectl-1.33 | affected | MinimOS | kubectl-1.33 | — |
| kubectl-1.33-advanced-compat | affected | MinimOS | kubectl-1.33-advanced-compat | — |
| kubectl-1.33-compat | affected | MinimOS | kubectl-1.33-compat | — |
| kube-proxy-1.33 | affected | MinimOS | kube-proxy-1.33 | — |
| kube-proxy-1.33-compat | affected | MinimOS | kube-proxy-1.33-compat | — |
| kubernetes-1.33 | affected | MinimOS | kubernetes-1.33 | — |
| kube-scheduler-1.33 | affected | MinimOS | kube-scheduler-1.33 | — |
| kube-scheduler-1.33-compat | affected | MinimOS | kube-scheduler-1.33-compat | — |
CVEs:CVE-2025-49713
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVEs:CVE-2025-49713
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2025-53605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rust-protobuf | affected | Debian:12 | rust-protobuf | — |
| rust-protobuf | affected | Debian:14 | rust-protobuf | — |
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| executorch | affected | PyPI | executorch | — |
| executorch | affected | SwiftURL | executorch | — |
| executorch | affected | PyPI | executorch | — |
| executorch | affected | SwiftURL | executorch | — |
| org.pytorch:executorch-android | affected | Maven | org.pytorch:executorch-android | — |
| pytorch/executorch | affected | github.com | github.com/pytorch/executorch | — |
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| executorch | affected | SwiftURL | executorch | — |
| executorch | affected | PyPI | executorch | — |
| org.pytorch:executorch-android | affected | Maven | org.pytorch:executorch-android | — |
| pytorch/executorch | affected | github.com | github.com/pytorch/executorch | — |
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVEs:CVE-2025-30402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| executorch | affected | SwiftURL | executorch | — |
| executorch | affected | PyPI | executorch | — |
| org.pytorch:executorch-android | affected | Maven | org.pytorch:executorch-android | — |
A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c495...
CVEs:CVE-2025-30402
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVEs:CVE-2025-30402
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| executorch | affected | PyPI | executorch | — |
| executorch | affected | SwiftURL | executorch | — |
| org.pytorch:executorch-android | affected | Maven | org.pytorch:executorch-android | — |
Pillow vulnerability can cause write buffer overflow on BCn encoding
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| pillow | affected | PyPI | pillow | — |
Pillow vulnerability can cause write buffer overflow on BCn encoding
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines-visualization-server | affected | chainguard | kubeflow-pipelines-visualization-server | — |
| kubeflow-pipelines-visualization-server | affected | wolfi | kubeflow-pipelines-visualization-server | — |
| pgadmin4 | affected | chainguard | pgadmin4 | — |
| pillow | affected | PyPI | pillow | — |
| pillow | affected | PyPI | pillow | — |
| py3.10-torchvision-cuda-12.3 | affected | chainguard | py3.10-torchvision-cuda-12.3 | — |
| py3.10-vllm-cuda-11.8 | affected | chainguard | py3.10-vllm-cuda-11.8 | — |
| py3.11-torchvision-cuda-12.3 | affected | chainguard | py3.11-torchvision-cuda-12.3 | — |
| py3.9-torchvision-cuda-11.8 | affected | chainguard | py3.9-torchvision-cuda-11.8 | — |
| py3-vllm-cuda-12.4 | affected | chainguard | py3-vllm-cuda-12.4 | — |
| superset | affected | chainguard | superset | — |
| superset | affected | wolfi | superset | — |
| tensorflow-cpu-jupyter | affected | wolfi | tensorflow-cpu-jupyter | — |
| tensorflow-cpu-jupyter | affected | chainguard | tensorflow-cpu-jupyter | — |
| tensorflow-gpu-jupyter | affected | chainguard | tensorflow-gpu-jupyter | — |
| tritonserver-backend-vllm-24.04 | affected | chainguard | tritonserver-backend-vllm-24.04 | — |
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09752821; Issue I...
CVEs:CVE-2025-20694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
| software_development_kit | affected | mediatek | — | — |
CVEs:CVE-2025-20694
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue I...
CVEs:CVE-2025-20695
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
| software_development_kit | affected | mediatek | — | — |
CVEs:CVE-2025-20695
php-jwt contains weak encryption
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
php-jwt contains weak encryption
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
| zabbix-7.0 | affected | chainguard | zabbix-7.0 | — |
| zabbix-7.4 | affected | chainguard | zabbix-7.4 | — |
| zabbix-fips-7.0 | affected | chainguard | zabbix-fips-7.0 | — |
| zabbix-fips-7.4 | affected | chainguard | zabbix-fips-7.4 | — |
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, ...
CVEs:CVE-2025-45769
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firebase_php-jwt | affected | — | — |
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
CVEs:CVE-2025-45769
php-jwt contains weak encryption
CVEs:CVE-2025-45769
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php-jwt | affected | firebase | firebase/php-jwt | — |
In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2025-20693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| openwrt | affected | openwrt | — | — |
| software_development_kit | affected | mediatek | — | — |
| yocto | affected | linuxfoundation | — | — |
CVEs:CVE-2025-20693
CVEs:CVE-2025-6017
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. ...
CVEs:CVE-2025-6017
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| advanced_cluster_management_for_kubernetes | affected | redhat | — | — |
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the devic...
CVEs:CVE-2025-6044
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome_os | affected | — | — |
CVEs:CVE-2025-6044
SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| jellyfin | affected | wolfi | jellyfin | — |
| SQLitePCLRaw.lib.e_sqlite3 | affected | NuGet | SQLitePCLRaw.lib.e_sqlite3 | — |
| SQLitePCLRaw.lib.e_sqlite3.android | affected | NuGet | SQLitePCLRaw.lib.e_sqlite3.android | — |
| SQLitePCLRaw.lib.e_sqlite3.ios | affected | NuGet | SQLitePCLRaw.lib.e_sqlite3.ios | — |
SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| SQLitePCLRaw.lib.e_sqlite3 | affected | NuGet | SQLitePCLRaw.lib.e_sqlite3 | — |
| SQLitePCLRaw.lib.e_sqlite3.android | affected | NuGet | SQLitePCLRaw.lib.e_sqlite3.android | — |
| SQLitePCLRaw.lib.e_sqlite3.ios | affected | NuGet | SQLitePCLRaw.lib.e_sqlite3.ios | — |
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nvidia-container-toolkit | affected | chainguard | nvidia-container-toolkit | — |
| nvidia-container-toolkit | affected | wolfi | nvidia-container-toolkit | — |
| NVIDIA/gpu-operator | affected | github.com | github.com/NVIDIA/gpu-operator | — |
| NVIDIA/k8s-device-plugin | affected | github.com | github.com/NVIDIA/k8s-device-plugin | — |
| NVIDIA/mig-parted | affected | github.com | github.com/NVIDIA/mig-parted | — |
| NVIDIA/nvidia-container-toolkit | affected | github.com | github.com/NVIDIA/nvidia-container-toolkit | — |
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| NVIDIA/gpu-operator | affected | github.com | github.com/NVIDIA/gpu-operator | — |
| NVIDIA/k8s-device-plugin | affected | github.com | github.com/NVIDIA/k8s-device-plugin | — |
| NVIDIA/mig-parted | affected | github.com | github.com/NVIDIA/mig-parted | — |
| NVIDIA/nvidia-container-toolkit | affected | github.com | github.com/NVIDIA/nvidia-container-toolkit | — |
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escal...
CVEs:CVE-2025-23266
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
CVEs:CVE-2025-23266
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| NVIDIA/gpu-operator | affected | github.com | github.com/NVIDIA/gpu-operator | — |
| NVIDIA/k8s-device-plugin | affected | github.com | github.com/NVIDIA/k8s-device-plugin | — |
| NVIDIA/mig-parted | affected | github.com | github.com/NVIDIA/mig-parted | — |
| NVIDIA/nvidia-container-toolkit | affected | github.com | github.com/NVIDIA/nvidia-container-toolkit | — |
Important: javapackages-tools:201801 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ant | affected | Rocky Linux:8 | ant | — |
| ant-contrib | affected | Rocky Linux:8 | ant-contrib | — |
| antlr | affected | Rocky Linux:8 | antlr | — |
| aopalliance | affected | Rocky Linux:8 | aopalliance | — |
| apache-commons-beanutils | affected | Rocky Linux:8 | apache-commons-beanutils | — |
| apache-commons-cli | affected | Rocky Linux:8 | apache-commons-cli | — |
| apache-commons-codec | affected | Rocky Linux:8 | apache-commons-codec | — |
| apache-commons-collections | affected | Rocky Linux:8 | apache-commons-collections | — |
| apache-commons-compress | affected | Rocky Linux:8 | apache-commons-compress | — |
| apache-commons-exec | affected | Rocky Linux:8 | apache-commons-exec | — |
| apache-commons-io | affected | Rocky Linux:8 | apache-commons-io | — |
| apache-commons-jxpath | affected | Rocky Linux:8 | apache-commons-jxpath | — |
| apache-commons-lang | affected | Rocky Linux:8 | apache-commons-lang | — |
| apache-commons-lang3 | affected | Rocky Linux:8 | apache-commons-lang3 | — |
| apache-commons-logging | affected | Rocky Linux:8 | apache-commons-logging | — |
| apache-commons-net | affected | Rocky Linux:8 | apache-commons-net | — |
| apache-commons-parent | affected | Rocky Linux:8 | apache-commons-parent | — |
| apache-ivy | affected | Rocky Linux:8 | apache-ivy | — |
| apache-parent | affected | Rocky Linux:8 | apache-parent | — |
| apache-resource-bundles | affected | Rocky Linux:8 | apache-resource-bundles | — |
| aqute-bnd | affected | Rocky Linux:8 | aqute-bnd | — |
| assertj-core | affected | Rocky Linux:8 | assertj-core | — |
| atinject | affected | Rocky Linux:8 | atinject | — |
| bcel | affected | Rocky Linux:8 | bcel | — |
| beust-jcommander | affected | Rocky Linux:8 | beust-jcommander | — |
| bsf | affected | Rocky Linux:8 | bsf | — |
| bsh | affected | Rocky Linux:8 | bsh | — |
| byaccj | affected | Rocky Linux:8 | byaccj | — |
| cal10n | affected | Rocky Linux:8 | cal10n | — |
| cdi-api | affected | Rocky Linux:8 | cdi-api | — |
| cglib | affected | Rocky Linux:8 | cglib | — |
| easymock | affected | Rocky Linux:8 | easymock | — |
| exec-maven-plugin | affected | Rocky Linux:8 | exec-maven-plugin | — |
| felix-osgi-compendium | affected | Rocky Linux:8 | felix-osgi-compendium | — |
| felix-osgi-core | affected | Rocky Linux:8 | felix-osgi-core | — |
| felix-osgi-foundation | affected | Rocky Linux:8 | felix-osgi-foundation | — |
| felix-parent | affected | Rocky Linux:8 | felix-parent | — |
| felix-utils | affected | Rocky Linux:8 | felix-utils | — |
| forge-parent | affected | Rocky Linux:8 | forge-parent | — |
| fusesource-pom | affected | Rocky Linux:8 | fusesource-pom | — |
| geronimo-annotation | affected | Rocky Linux:8 | geronimo-annotation | — |
| geronimo-jms | affected | Rocky Linux:8 | geronimo-jms | — |
| geronimo-jpa | affected | Rocky Linux:8 | geronimo-jpa | — |
| geronimo-parent-poms | affected | Rocky Linux:8 | geronimo-parent-poms | — |
| glassfish-annotation-api | affected | Rocky Linux:8 | glassfish-annotation-api | — |
| glassfish-el | affected | Rocky Linux:8 | glassfish-el | — |
| glassfish-jsp-api | affected | Rocky Linux:8 | glassfish-jsp-api | — |
| glassfish-legal | affected | Rocky Linux:8 | glassfish-legal | — |
| glassfish-master-pom | affected | Rocky Linux:8 | glassfish-master-pom | — |
| glassfish-servlet-api | affected | Rocky Linux:8 | glassfish-servlet-api | — |
| google-guice | affected | Rocky Linux:8 | google-guice | — |
| guava20 | affected | Rocky Linux:8 | guava20 | — |
| hamcrest | affected | Rocky Linux:8 | hamcrest | — |
| hawtjni | affected | Rocky Linux:8 | hawtjni | — |
| httpcomponents-client | affected | Rocky Linux:8 | httpcomponents-client | — |
| httpcomponents-core | affected | Rocky Linux:8 | httpcomponents-core | — |
| httpcomponents-project | affected | Rocky Linux:8 | httpcomponents-project | — |
| isorelax | affected | Rocky Linux:8 | isorelax | — |
| jakarta-commons-httpclient | affected | Rocky Linux:8 | jakarta-commons-httpclient | — |
| jakarta-oro | affected | Rocky Linux:8 | jakarta-oro | — |
| jansi | affected | Rocky Linux:8 | jansi | — |
| jansi-native | affected | Rocky Linux:8 | jansi-native | — |
| javacc | affected | Rocky Linux:8 | javacc | — |
| javacc-maven-plugin | affected | Rocky Linux:8 | javacc-maven-plugin | — |
| java_cup | affected | Rocky Linux:8 | java_cup | — |
| javamail | affected | Rocky Linux:8 | javamail | — |
| javapackages-tools | affected | Rocky Linux:8 | javapackages-tools | — |
| javassist | affected | Rocky Linux:8 | javassist | — |
| jaxen | affected | Rocky Linux:8 | jaxen | — |
| jboss-interceptors-1.2-api | affected | Rocky Linux:8 | jboss-interceptors-1.2-api | — |
| jboss-parent | affected | Rocky Linux:8 | jboss-parent | — |
| jdepend | affected | Rocky Linux:8 | jdepend | — |
| jdependency | affected | Rocky Linux:8 | jdependency | — |
| jdom | affected | Rocky Linux:8 | jdom | — |
| jdom2 | affected | Rocky Linux:8 | jdom2 | — |
| jflex | affected | Rocky Linux:8 | jflex | — |
| jline | affected | Rocky Linux:8 | jline | — |
| jsch | affected | Rocky Linux:8 | jsch | — |
| jsoup | affected | Rocky Linux:8 | jsoup | — |
| jsr-305 | affected | Rocky Linux:8 | jsr-305 | — |
| jtidy | affected | Rocky Linux:8 | jtidy | — |
| junit | affected | Rocky Linux:8 | junit | — |
| jvnet-parent | affected | Rocky Linux:8 | jvnet-parent | — |
| jzlib | affected | Rocky Linux:8 | jzlib | — |
| log4j12 | affected | Rocky Linux:8 | log4j12 | — |
| maven | affected | Rocky Linux:8 | maven | — |
| maven2 | affected | Rocky Linux:8 | maven2 | — |
| maven-antrun-plugin | affected | Rocky Linux:8 | maven-antrun-plugin | — |
| maven-archiver | affected | Rocky Linux:8 | maven-archiver | — |
| maven-artifact-resolver | affected | Rocky Linux:8 | maven-artifact-resolver | — |
| maven-artifact-transfer | affected | Rocky Linux:8 | maven-artifact-transfer | — |
| maven-assembly-plugin | affected | Rocky Linux:8 | maven-assembly-plugin | — |
| maven-clean-plugin | affected | Rocky Linux:8 | maven-clean-plugin | — |
| maven-common-artifact-filters | affected | Rocky Linux:8 | maven-common-artifact-filters | — |
| maven-compiler-plugin | affected | Rocky Linux:8 | maven-compiler-plugin | — |
| maven-dependency-analyzer | affected | Rocky Linux:8 | maven-dependency-analyzer | — |
| maven-dependency-plugin | affected | Rocky Linux:8 | maven-dependency-plugin | — |
| maven-dependency-tree | affected | Rocky Linux:8 | maven-dependency-tree | — |
| maven-doxia | affected | Rocky Linux:8 | maven-doxia | — |
| maven-doxia-sitetools | affected | Rocky Linux:8 | maven-doxia-sitetools | — |
| maven-enforcer | affected | Rocky Linux:8 | maven-enforcer | — |
| maven-file-management | affected | Rocky Linux:8 | maven-file-management | — |
| maven-filtering | affected | Rocky Linux:8 | maven-filtering | — |
| maven-install-plugin | affected | Rocky Linux:8 | maven-install-plugin | — |
| maven-invoker | affected | Rocky Linux:8 | maven-invoker | — |
| maven-invoker-plugin | affected | Rocky Linux:8 | maven-invoker-plugin | — |
| maven-jar-plugin | affected | Rocky Linux:8 | maven-jar-plugin | — |
| maven-parent | affected | Rocky Linux:8 | maven-parent | — |
| maven-plugin-build-helper | affected | Rocky Linux:8 | maven-plugin-build-helper | — |
| maven-plugin-bundle | affected | Rocky Linux:8 | maven-plugin-bundle | — |
| maven-plugins-pom | affected | Rocky Linux:8 | maven-plugins-pom | — |
| maven-plugin-testing | affected | Rocky Linux:8 | maven-plugin-testing | — |
| maven-plugin-tools | affected | Rocky Linux:8 | maven-plugin-tools | — |
| maven-remote-resources-plugin | affected | Rocky Linux:8 | maven-remote-resources-plugin | — |
| maven-reporting-api | affected | Rocky Linux:8 | maven-reporting-api | — |
| maven-reporting-impl | affected | Rocky Linux:8 | maven-reporting-impl | — |
| maven-resolver | affected | Rocky Linux:8 | maven-resolver | — |
| maven-resources-plugin | affected | Rocky Linux:8 | maven-resources-plugin | — |
| maven-script-interpreter | affected | Rocky Linux:8 | maven-script-interpreter | — |
| maven-shade-plugin | affected | Rocky Linux:8 | maven-shade-plugin | — |
| maven-shared | affected | Rocky Linux:8 | maven-shared | — |
| maven-shared-incremental | affected | Rocky Linux:8 | maven-shared-incremental | — |
| maven-shared-io | affected | Rocky Linux:8 | maven-shared-io | — |
| maven-shared-utils | affected | Rocky Linux:8 | maven-shared-utils | — |
| maven-source-plugin | affected | Rocky Linux:8 | maven-source-plugin | — |
| maven-surefire | affected | Rocky Linux:8 | maven-surefire | — |
| maven-verifier | affected | Rocky Linux:8 | maven-verifier | — |
| maven-wagon | affected | Rocky Linux:8 | maven-wagon | — |
| mockito | affected | Rocky Linux:8 | mockito | — |
| modello | affected | Rocky Linux:8 | modello | — |
| mojo-parent | affected | Rocky Linux:8 | mojo-parent | — |
| munge-maven-plugin | affected | Rocky Linux:8 | munge-maven-plugin | — |
| objectweb-asm | affected | Rocky Linux:8 | objectweb-asm | — |
| objectweb-pom | affected | Rocky Linux:8 | objectweb-pom | — |
| objenesis | affected | Rocky Linux:8 | objenesis | — |
| osgi-annotation | affected | Rocky Linux:8 | osgi-annotation | — |
| osgi-compendium | affected | Rocky Linux:8 | osgi-compendium | — |
| osgi-core | affected | Rocky Linux:8 | osgi-core | — |
| os-maven-plugin | affected | Rocky Linux:8 | os-maven-plugin | — |
| plexus-ant-factory | affected | Rocky Linux:8 | plexus-ant-factory | — |
| plexus-archiver | affected | Rocky Linux:8 | plexus-archiver | — |
| plexus-bsh-factory | affected | Rocky Linux:8 | plexus-bsh-factory | — |
| plexus-build-api | affected | Rocky Linux:8 | plexus-build-api | — |
| plexus-cipher | affected | Rocky Linux:8 | plexus-cipher | — |
| plexus-classworlds | affected | Rocky Linux:8 | plexus-classworlds | — |
| plexus-cli | affected | Rocky Linux:8 | plexus-cli | — |
| plexus-compiler | affected | Rocky Linux:8 | plexus-compiler | — |
| plexus-component-api | affected | Rocky Linux:8 | plexus-component-api | — |
| plexus-component-factories-pom | affected | Rocky Linux:8 | plexus-component-factories-pom | — |
| plexus-components-pom | affected | Rocky Linux:8 | plexus-components-pom | — |
| plexus-containers | affected | Rocky Linux:8 | plexus-containers | — |
| plexus-i18n | affected | Rocky Linux:8 | plexus-i18n | — |
| plexus-interactivity | affected | Rocky Linux:8 | plexus-interactivity | — |
| plexus-interpolation | affected | Rocky Linux:8 | plexus-interpolation | — |
| plexus-io | affected | Rocky Linux:8 | plexus-io | — |
| plexus-languages | affected | Rocky Linux:8 | plexus-languages | — |
| plexus-pom | affected | Rocky Linux:8 | plexus-pom | — |
| plexus-resources | affected | Rocky Linux:8 | plexus-resources | — |
| plexus-sec-dispatcher | affected | Rocky Linux:8 | plexus-sec-dispatcher | — |
| plexus-utils | affected | Rocky Linux:8 | plexus-utils | — |
| plexus-velocity | affected | Rocky Linux:8 | plexus-velocity | — |
| powermock | affected | Rocky Linux:8 | powermock | — |
| qdox | affected | Rocky Linux:8 | qdox | — |
| regexp | affected | Rocky Linux:8 | regexp | — |
| sisu | affected | Rocky Linux:8 | sisu | — |
| sisu-mojos | affected | Rocky Linux:8 | sisu-mojos | — |
| slf4j | affected | Rocky Linux:8 | slf4j | — |
| sonatype-oss-parent | affected | Rocky Linux:8 | sonatype-oss-parent | — |
| sonatype-plugins-parent | affected | Rocky Linux:8 | sonatype-plugins-parent | — |
| spec-version-maven-plugin | affected | Rocky Linux:8 | spec-version-maven-plugin | — |
| spice-parent | affected | Rocky Linux:8 | spice-parent | — |
| testng | affected | Rocky Linux:8 | testng | — |
| velocity | affected | Rocky Linux:8 | velocity | — |
| weld-parent | affected | Rocky Linux:8 | weld-parent | — |
| xalan-j2 | affected | Rocky Linux:8 | xalan-j2 | — |
| xbean | affected | Rocky Linux:8 | xbean | — |
| xerces-j2 | affected | Rocky Linux:8 | xerces-j2 | — |
| xml-commons-apis | affected | Rocky Linux:8 | xml-commons-apis | — |
| xml-commons-resolver | affected | Rocky Linux:8 | xml-commons-resolver | — |
| xmlunit | affected | Rocky Linux:8 | xmlunit | — |
| xmvn | affected | Rocky Linux:8 | xmvn | — |
| xz-java | affected | Rocky Linux:8 | xz-java | — |
MINI-g8m7-36c2-4rx4
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-qv5v-ggc5-9gj9
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.33 | affected | MinimOS | kube-apiserver-1.33 | — |
| kube-apiserver-1.33-compat | affected | MinimOS | kube-apiserver-1.33-compat | — |
| kube-controller-manager-1.33 | affected | MinimOS | kube-controller-manager-1.33 | — |
| kube-controller-manager-1.33-compat | affected | MinimOS | kube-controller-manager-1.33-compat | — |
| kubectl-1.33 | affected | MinimOS | kubectl-1.33 | — |
| kubectl-1.33-advanced-compat | affected | MinimOS | kubectl-1.33-advanced-compat | — |
| kubectl-1.33-compat | affected | MinimOS | kubectl-1.33-compat | — |
| kube-proxy-1.33 | affected | MinimOS | kube-proxy-1.33 | — |
| kube-proxy-1.33-compat | affected | MinimOS | kube-proxy-1.33-compat | — |
| kubernetes-1.33 | affected | MinimOS | kubernetes-1.33 | — |
| kube-scheduler-1.33 | affected | MinimOS | kube-scheduler-1.33 | — |
| kube-scheduler-1.33-compat | affected | MinimOS | kube-scheduler-1.33-compat | — |
Important: delve and golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:9 | delve | — |
| golang | affected | Rocky Linux:9 | golang | — |
Important: gvisor-tap-vsock security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gvisor-tap-vsock | affected | Rocky Linux:9 | gvisor-tap-vsock | — |
Important: gvisor-tap-vsock security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gvisor-tap-vsock | affected | Rocky Linux:9 | gvisor-tap-vsock | — |
MINI-qg9w-36pv-gppf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-m2xg-84qw-pj7w
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-498w-39vm-cvh3
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-3c2f-25v7-jpph
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| actions-runner-controller | affected | wolfi | actions-runner-controller | — |
| actions-runner-controller | affected | chainguard | actions-runner-controller | — |
| actions-runner-controller-fips | affected | chainguard | actions-runner-controller-fips | — |
| addon-resizer | affected | chainguard | addon-resizer | — |
| addon-resizer | affected | wolfi | addon-resizer | — |
| addon-resizer-fips | affected | chainguard | addon-resizer-fips | — |
| agentbeat-fips | affected | chainguard | agentbeat-fips | — |
| amazon-cloudwatch-agent | affected | chainguard | amazon-cloudwatch-agent | — |
| amazon-cloudwatch-agent | affected | wolfi | amazon-cloudwatch-agent | — |
| amazon-cloudwatch-agent-fips | affected | chainguard | amazon-cloudwatch-agent-fips | — |
| amazon-cloudwatch-agent-operator | affected | chainguard | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator | affected | wolfi | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator-fips | affected | chainguard | amazon-cloudwatch-agent-operator-fips | — |
| amazon-k8s-cni | affected | chainguard | amazon-k8s-cni | — |
| amazon-k8s-cni | affected | wolfi | amazon-k8s-cni | — |
| amazon-ssm-agent | affected | chainguard | amazon-ssm-agent | — |
| ansible-operator | affected | wolfi | ansible-operator | — |
| ansible-operator | affected | chainguard | ansible-operator | — |
| apko | affected | chainguard | apko | — |
| apko | affected | wolfi | apko | — |
| argo-cd-2.10 | affected | wolfi | argo-cd-2.10 | — |
| argo-cd-2.10 | affected | chainguard | argo-cd-2.10 | — |
| argo-cd-2.11 | affected | chainguard | argo-cd-2.11 | — |
| argo-cd-2.11 | affected | wolfi | argo-cd-2.11 | — |
| argo-cd-2.12 | affected | chainguard | argo-cd-2.12 | — |
| argo-cd-2.12 | affected | wolfi | argo-cd-2.12 | — |
| argo-cd-2.13 | affected | wolfi | argo-cd-2.13 | — |
| argo-cd-2.13 | affected | chainguard | argo-cd-2.13 | — |
| argo-cd-2.14 | affected | chainguard | argo-cd-2.14 | — |
| argo-cd-2.14 | affected | wolfi | argo-cd-2.14 | — |
| argo-cd-fips-2.10 | affected | chainguard | argo-cd-fips-2.10 | — |
| argo-cd-fips-2.11 | affected | chainguard | argo-cd-fips-2.11 | — |
| argo-cd-fips-2.12 | affected | chainguard | argo-cd-fips-2.12 | — |
| argo-cd-fips-2.13 | affected | chainguard | argo-cd-fips-2.13 | — |
| argo-cd-fips-2.14 | affected | chainguard | argo-cd-fips-2.14 | — |
| argocd-image-updater | affected | wolfi | argocd-image-updater | — |
| argocd-image-updater | affected | chainguard | argocd-image-updater | — |
| argocd-image-updater-fips | affected | chainguard | argocd-image-updater-fips | — |
| argo-events | affected | chainguard | argo-events | — |
| argo-events | affected | wolfi | argo-events | — |
| argo-events-fips | affected | chainguard | argo-events-fips | — |
| argo-rollouts | affected | wolfi | argo-rollouts | — |
| argo-rollouts | affected | chainguard | argo-rollouts | — |
| argo-rollouts-fips | affected | chainguard | argo-rollouts-fips | — |
| argo-workflows | affected | wolfi | argo-workflows | — |
| argo-workflows | affected | chainguard | argo-workflows | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| authservice | affected | wolfi | authservice | — |
| authservice | affected | chainguard | authservice | — |
| authservice-fips | affected | chainguard | authservice-fips | — |
| aws-application-networking-k8s | affected | wolfi | aws-application-networking-k8s | — |
| aws-application-networking-k8s | affected | chainguard | aws-application-networking-k8s | — |
| aws-ebs-csi-driver | affected | chainguard | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver | affected | wolfi | aws-ebs-csi-driver | — |
| aws-ebs-csi-driver-fips | affected | chainguard | aws-ebs-csi-driver-fips | — |
| aws-efs-csi-driver | affected | wolfi | aws-efs-csi-driver | — |
| aws-efs-csi-driver | affected | chainguard | aws-efs-csi-driver | — |
| aws-efs-csi-driver-fips | affected | chainguard | aws-efs-csi-driver-fips | — |
| aws-load-balancer-controller | affected | chainguard | aws-load-balancer-controller | — |
| aws-load-balancer-controller | affected | wolfi | aws-load-balancer-controller | — |
| aws-network-policy-agent | affected | chainguard | aws-network-policy-agent | — |
| aws-network-policy-agent | affected | wolfi | aws-network-policy-agent | — |
| aws-network-policy-agent-fips | affected | chainguard | aws-network-policy-agent-fips | — |
| aws-privateca-issuer | affected | chainguard | aws-privateca-issuer | — |
| aws-privateca-issuer | affected | wolfi | aws-privateca-issuer | — |
| aws-privateca-issuer-fips | affected | chainguard | aws-privateca-issuer-fips | — |
| aws-s3-controller | affected | chainguard | aws-s3-controller | — |
| aws-s3-controller | affected | wolfi | aws-s3-controller | — |
| azcopy | affected | chainguard | azcopy | — |
| azcopy | affected | wolfi | azcopy | — |
| azcopy-fips | affected | chainguard | azcopy-fips | — |
| azure-aad-pod-identity-mic | affected | chainguard | azure-aad-pod-identity-mic | — |
| azuredisk-csi-1.28 | affected | chainguard | azuredisk-csi-1.28 | — |
| azuredisk-csi-1.29 | affected | chainguard | azuredisk-csi-1.29 | — |
| azuredisk-csi-1.30 | affected | chainguard | azuredisk-csi-1.30 | — |
| azuredisk-csi-1.31 | affected | wolfi | azuredisk-csi-1.31 | — |
| azuredisk-csi-1.31 | affected | chainguard | azuredisk-csi-1.31 | — |
| azuredisk-csi-fips-1.28 | affected | chainguard | azuredisk-csi-fips-1.28 | — |
| azuredisk-csi-fips-1.29 | affected | chainguard | azuredisk-csi-fips-1.29 | — |
| azuredisk-csi-fips-1.30 | affected | chainguard | azuredisk-csi-fips-1.30 | — |
| azuredisk-csi-fips-1.31 | affected | chainguard | azuredisk-csi-fips-1.31 | — |
| azurefile-csi-1.32 | affected | wolfi | azurefile-csi-1.32 | — |
| azurefile-csi-1.32 | affected | chainguard | azurefile-csi-1.32 | — |
| azure-workload-identity-webhook | affected | wolfi | azure-workload-identity-webhook | — |
| azure-workload-identity-webhook | affected | chainguard | azure-workload-identity-webhook | — |
| bank-vaults | affected | chainguard | bank-vaults | — |
| bank-vaults | affected | wolfi | bank-vaults | — |
| bank-vaults-fips | affected | chainguard | bank-vaults-fips | — |
| beats-7 | affected | chainguard | beats-7 | — |
| beats-8 | affected | chainguard | beats-8 | — |
| beats-fips-7 | affected | chainguard | beats-fips-7 | — |
| beats-fips-8 | affected | chainguard | beats-fips-8 | — |
| beats-fips-9 | affected | chainguard | beats-fips-9 | — |
| blob-csi-1.23 | affected | chainguard | blob-csi-1.23 | — |
| blob-csi-1.25 | affected | chainguard | blob-csi-1.25 | — |
| blob-csi-1.26 | affected | chainguard | blob-csi-1.26 | — |
| blob-csi-1.26 | affected | wolfi | blob-csi-1.26 | — |
| blob-csi-fips-1.23 | affected | chainguard | blob-csi-fips-1.23 | — |
| blob-csi-fips-1.24 | affected | chainguard | blob-csi-fips-1.24 | — |
| blob-csi-fips-1.25 | affected | chainguard | blob-csi-fips-1.25 | — |
| blob-csi-fips-1.26 | affected | chainguard | blob-csi-fips-1.26 | — |
| cadvisor | affected | chainguard | cadvisor | — |
| cadvisor | affected | wolfi | cadvisor | — |
| cadvisor-fips | affected | chainguard | cadvisor-fips | — |
| calico-3.27 | affected | chainguard | calico-3.27 | — |
| calico-3.28 | affected | wolfi | calico-3.28 | — |
| calico-3.28 | affected | chainguard | calico-3.28 | — |
| calico-3.29 | affected | wolfi | calico-3.29 | — |
| calico-3.29 | affected | chainguard | calico-3.29 | — |
| calico-fips-3.27 | affected | chainguard | calico-fips-3.27 | — |
| calico-fips-3.28 | affected | chainguard | calico-fips-3.28 | — |
| calico-fips-3.29 | affected | chainguard | calico-fips-3.29 | — |
| cass-operator | affected | chainguard | cass-operator | — |
| cass-operator | affected | wolfi | cass-operator | — |
| cass-operator-fips | affected | chainguard | cass-operator-fips | — |
| cass-operator-fips-no-pvc-delete | affected | chainguard | cass-operator-fips-no-pvc-delete | — |
| cert-exporter | affected | chainguard | cert-exporter | — |
| cert-exporter | affected | wolfi | cert-exporter | — |
| cert-exporter-fips | affected | chainguard | cert-exporter-fips | — |
| certificate-transparency | affected | chainguard | certificate-transparency | — |
| certificate-transparency | affected | wolfi | certificate-transparency | — |
| certificate-transparency-fips | affected | chainguard | certificate-transparency-fips | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-1.15 | affected | chainguard | cert-manager-1.15 | — |
| cert-manager-1.16 | affected | chainguard | cert-manager-1.16 | — |
| cert-manager-1.16 | affected | wolfi | cert-manager-1.16 | — |
| cert-manager-1.17 | affected | wolfi | cert-manager-1.17 | — |
| cert-manager-1.17 | affected | chainguard | cert-manager-1.17 | — |
| cert-manager-cmctl | affected | chainguard | cert-manager-cmctl | — |
| cert-manager-cmctl | affected | wolfi | cert-manager-cmctl | — |
| cert-manager-cmctl-fips | affected | chainguard | cert-manager-cmctl-fips | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| cert-manager-fips-1.15 | affected | chainguard | cert-manager-fips-1.15 | — |
| cert-manager-fips-1.16 | affected | chainguard | cert-manager-fips-1.16 | — |
| cert-manager-fips-1.17 | affected | chainguard | cert-manager-fips-1.17 | — |
| cert-manager-istio-csr | affected | wolfi | cert-manager-istio-csr | — |
| cert-manager-istio-csr | affected | chainguard | cert-manager-istio-csr | — |
| cert-manager-webhook-pdns | affected | wolfi | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns | affected | chainguard | cert-manager-webhook-pdns | — |
| cert-manager-webhook-pdns-fips | affected | chainguard | cert-manager-webhook-pdns-fips | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| chartmuseum-fips | affected | chainguard | chartmuseum-fips | — |
| chezmoi | affected | chainguard | chezmoi | — |
| chezmoi | affected | wolfi | chezmoi | — |
| cilium-1.14 | affected | wolfi | cilium-1.14 | — |
| cilium-1.14 | affected | chainguard | cilium-1.14 | — |
| cilium-1.15 | affected | wolfi | cilium-1.15 | — |
| cilium-1.15 | affected | chainguard | cilium-1.15 | — |
| cilium-1.16 | affected | chainguard | cilium-1.16 | — |
| cilium-1.16 | affected | wolfi | cilium-1.16 | — |
| cilium-1.17 | affected | wolfi | cilium-1.17 | — |
| cilium-1.17 | affected | chainguard | cilium-1.17 | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-fips-1.14 | affected | chainguard | cilium-fips-1.14 | — |
| cilium-fips-1.15 | affected | chainguard | cilium-fips-1.15 | — |
| cilium-fips-1.16 | affected | chainguard | cilium-fips-1.16 | — |
| cilium-fips-1.17 | affected | chainguard | cilium-fips-1.17 | — |
| cinder-csi-plugin-fips | affected | chainguard | cinder-csi-plugin-fips | — |
| cloudbeat-fips | affected | chainguard | cloudbeat-fips | — |
| cloudflared | affected | wolfi | cloudflared | — |
| cloudflared | affected | chainguard | cloudflared | — |
| cloudprober | affected | wolfi | cloudprober | — |
| cloudprober | affected | chainguard | cloudprober | — |
| cloudprober-fips | affected | chainguard | cloudprober-fips | — |
| cloud-provider-aws-1.28 | affected | chainguard | cloud-provider-aws-1.28 | — |
| cloud-provider-aws-1.29 | affected | chainguard | cloud-provider-aws-1.29 | — |
| cloud-provider-aws-1.30 | affected | chainguard | cloud-provider-aws-1.30 | — |
| cloud-provider-aws-1.31 | affected | wolfi | cloud-provider-aws-1.31 | — |
| cloud-provider-aws-1.31 | affected | chainguard | cloud-provider-aws-1.31 | — |
| cloud-provider-aws-1.32 | affected | chainguard | cloud-provider-aws-1.32 | — |
| cloud-provider-aws-1.32 | affected | wolfi | cloud-provider-aws-1.32 | — |
| cloud-provider-aws-fips-1.28 | affected | chainguard | cloud-provider-aws-fips-1.28 | — |
| cloud-provider-aws-fips-1.29 | affected | chainguard | cloud-provider-aws-fips-1.29 | — |
| cloud-provider-aws-fips-1.30 | affected | chainguard | cloud-provider-aws-fips-1.30 | — |
| cloud-provider-aws-fips-1.31 | affected | chainguard | cloud-provider-aws-fips-1.31 | — |
| cloud-provider-aws-fips-1.32 | affected | chainguard | cloud-provider-aws-fips-1.32 | — |
| cloud-provider-azure-1.27 | affected | chainguard | cloud-provider-azure-1.27 | — |
| cloud-provider-azure-1.28 | affected | chainguard | cloud-provider-azure-1.28 | — |
| cloud-provider-azure-1.29 | affected | chainguard | cloud-provider-azure-1.29 | — |
| cloud-provider-azure-1.30 | affected | chainguard | cloud-provider-azure-1.30 | — |
| cloud-provider-azure-1.31 | affected | wolfi | cloud-provider-azure-1.31 | — |
| cloud-provider-azure-1.31 | affected | chainguard | cloud-provider-azure-1.31 | — |
| cloud-provider-azure-1.32 | affected | chainguard | cloud-provider-azure-1.32 | — |
| cloud-provider-azure-1.32 | affected | wolfi | cloud-provider-azure-1.32 | — |
| cloud-provider-azure-fips-1.27 | affected | chainguard | cloud-provider-azure-fips-1.27 | — |
| cloud-provider-azure-fips-1.28 | affected | chainguard | cloud-provider-azure-fips-1.28 | — |
| cloud-provider-azure-fips-1.29 | affected | chainguard | cloud-provider-azure-fips-1.29 | — |
| cloud-provider-azure-fips-1.30 | affected | chainguard | cloud-provider-azure-fips-1.30 | — |
| cloud-provider-azure-fips-1.31 | affected | chainguard | cloud-provider-azure-fips-1.31 | — |
| cloud-provider-azure-fips-1.32 | affected | chainguard | cloud-provider-azure-fips-1.32 | — |
| cloud-sql-proxy | affected | chainguard | cloud-sql-proxy | — |
| cloud-sql-proxy | affected | wolfi | cloud-sql-proxy | — |
| cloud-sql-proxy-fips | affected | chainguard | cloud-sql-proxy-fips | — |
| cluster-api-aws-controller | affected | wolfi | cluster-api-aws-controller | — |
| cluster-api-aws-controller | affected | chainguard | cluster-api-aws-controller | — |
| cluster-api-aws-controller-fips | affected | chainguard | cluster-api-aws-controller-fips | — |
| cluster-api-controller | affected | wolfi | cluster-api-controller | — |
| cluster-api-controller | affected | chainguard | cluster-api-controller | — |
| cluster-api-helm-controller | affected | wolfi | cluster-api-helm-controller | — |
| cluster-api-helm-controller | affected | chainguard | cluster-api-helm-controller | — |
| cluster-api-helm-controller-fips | affected | chainguard | cluster-api-helm-controller-fips | — |
| cluster-autoscaler-1.28 | affected | wolfi | cluster-autoscaler-1.28 | — |
| cluster-autoscaler-1.28 | affected | chainguard | cluster-autoscaler-1.28 | — |
| cluster-autoscaler-1.29 | affected | chainguard | cluster-autoscaler-1.29 | — |
| cluster-autoscaler-1.29 | affected | wolfi | cluster-autoscaler-1.29 | — |
| cluster-autoscaler-1.30 | affected | wolfi | cluster-autoscaler-1.30 | — |
| cluster-autoscaler-1.30 | affected | chainguard | cluster-autoscaler-1.30 | — |
| cluster-autoscaler-1.31 | affected | chainguard | cluster-autoscaler-1.31 | — |
| cluster-autoscaler-1.31 | affected | wolfi | cluster-autoscaler-1.31 | — |
| cluster-autoscaler-1.32 | affected | wolfi | cluster-autoscaler-1.32 | — |
| cluster-autoscaler-1.32 | affected | chainguard | cluster-autoscaler-1.32 | — |
| cluster-autoscaler-fips-1.28 | affected | chainguard | cluster-autoscaler-fips-1.28 | — |
| cluster-autoscaler-fips-1.29 | affected | chainguard | cluster-autoscaler-fips-1.29 | — |
| cluster-autoscaler-fips-1.30 | affected | chainguard | cluster-autoscaler-fips-1.30 | — |
| cluster-autoscaler-fips-1.31 | affected | chainguard | cluster-autoscaler-fips-1.31 | — |
| cluster-autoscaler-fips-1.32 | affected | chainguard | cluster-autoscaler-fips-1.32 | — |
| clusterctl | affected | wolfi | clusterctl | — |
| clusterctl | affected | chainguard | clusterctl | — |
| cluster-proportional-autoscaler | affected | wolfi | cluster-proportional-autoscaler | — |
| cluster-proportional-autoscaler | affected | chainguard | cluster-proportional-autoscaler | — |
| cluster-proportional-autoscaler-fips | affected | chainguard | cluster-proportional-autoscaler-fips | — |
| conftest | affected | chainguard | conftest | — |
| conftest | affected | wolfi | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| consul-1.17 | affected | chainguard | consul-1.17 | — |
| consul-1.18 | affected | chainguard | consul-1.18 | — |
| consul-1.19 | affected | chainguard | consul-1.19 | — |
| consul-1.20 | affected | chainguard | consul-1.20 | — |
| consul-fips-1.18 | affected | chainguard | consul-fips-1.18 | — |
| consul-fips-1.19 | affected | chainguard | consul-fips-1.19 | — |
| consul-fips-1.20 | affected | chainguard | consul-fips-1.20 | — |
| consul-k8s-1.1 | affected | chainguard | consul-k8s-1.1 | — |
| consul-k8s-1.3 | affected | chainguard | consul-k8s-1.3 | — |
| consul-k8s-1.4 | affected | chainguard | consul-k8s-1.4 | — |
| consul-k8s-1.5 | affected | wolfi | consul-k8s-1.5 | — |
| consul-k8s-1.5 | affected | chainguard | consul-k8s-1.5 | — |
| consul-k8s-1.6 | affected | chainguard | consul-k8s-1.6 | — |
| consul-k8s-1.6 | affected | wolfi | consul-k8s-1.6 | — |
| consul-k8s-fips-1.1 | affected | chainguard | consul-k8s-fips-1.1 | — |
| consul-k8s-fips-1.3 | affected | chainguard | consul-k8s-fips-1.3 | — |
| consul-k8s-fips-1.4 | affected | chainguard | consul-k8s-fips-1.4 | — |
| consul-k8s-fips-1.5 | affected | chainguard | consul-k8s-fips-1.5 | — |
| consul-k8s-fips-1.6 | affected | chainguard | consul-k8s-fips-1.6 | — |
| containerd-1 | affected | wolfi | containerd-1 | — |
| containerd-1 | affected | chainguard | containerd-1 | — |
| containerd-2 | affected | chainguard | containerd-2 | — |
| containerd-2 | affected | wolfi | containerd-2 | — |
| containerd-fips | affected | chainguard | containerd-fips | — |
| contour-1.28 | affected | wolfi | contour-1.28 | — |
| contour-1.28 | affected | chainguard | contour-1.28 | — |
| contour-1.29 | affected | chainguard | contour-1.29 | — |
| contour-1.29 | affected | wolfi | contour-1.29 | — |
| contour-1.30 | affected | wolfi | contour-1.30 | — |
| contour-1.30 | affected | chainguard | contour-1.30 | — |
| contour-fips-1.28 | affected | chainguard | contour-fips-1.28 | — |
| contour-fips-1.29 | affected | chainguard | contour-fips-1.29 | — |
| contour-fips-1.30 | affected | chainguard | contour-fips-1.30 | — |
| coredns | affected | chainguard | coredns | — |
| coredns | affected | wolfi | coredns | — |
| coredns-fips | affected | chainguard | coredns-fips | — |
| cortex | affected | chainguard | cortex | — |
| cortex | affected | wolfi | cortex | — |
| cortex-fips | affected | chainguard | cortex-fips | — |
| cosign | affected | wolfi | cosign | — |
| cosign | affected | chainguard | cosign | — |
| cosign-fips | affected | wolfi | cosign-fips | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| cri-tools | affected | chainguard | cri-tools | — |
| cri-tools | affected | wolfi | cri-tools | — |
| crossplane | affected | wolfi | crossplane | — |
| crossplane | affected | chainguard | crossplane | — |
| crossplane-fips | affected | chainguard | crossplane-fips | — |
| crossplane-function-auto-ready | affected | chainguard | crossplane-function-auto-ready | — |
| crossplane-function-auto-ready-fips | affected | chainguard | crossplane-function-auto-ready-fips | — |
| crossplane-function-environment-configs | affected | chainguard | crossplane-function-environment-configs | — |
| crossplane-function-environment-configs-fips | affected | chainguard | crossplane-function-environment-configs-fips | — |
| crossplane-provider-aws | affected | chainguard | crossplane-provider-aws | — |
| crossplane-provider-aws | affected | wolfi | crossplane-provider-aws | — |
| crossplane-provider-aws-cloudformation | affected | wolfi | crossplane-provider-aws-cloudformation | — |
| crossplane-provider-aws-cloudformation | affected | chainguard | crossplane-provider-aws-cloudformation | — |
| crossplane-provider-aws-cloudfront | affected | chainguard | crossplane-provider-aws-cloudfront | — |
| crossplane-provider-aws-cloudfront | affected | wolfi | crossplane-provider-aws-cloudfront | — |
| crossplane-provider-aws-cloudwatchlogs | affected | chainguard | crossplane-provider-aws-cloudwatchlogs | — |
| crossplane-provider-aws-cloudwatchlogs | affected | wolfi | crossplane-provider-aws-cloudwatchlogs | — |
| crossplane-provider-aws-dynamodb | affected | wolfi | crossplane-provider-aws-dynamodb | — |
| crossplane-provider-aws-dynamodb | affected | chainguard | crossplane-provider-aws-dynamodb | — |
| crossplane-provider-aws-ec2 | affected | wolfi | crossplane-provider-aws-ec2 | — |
| crossplane-provider-aws-ec2 | affected | chainguard | crossplane-provider-aws-ec2 | — |
| crossplane-provider-aws-eks | affected | wolfi | crossplane-provider-aws-eks | — |
| crossplane-provider-aws-eks | affected | chainguard | crossplane-provider-aws-eks | — |
| crossplane-provider-aws-elasticache | affected | wolfi | crossplane-provider-aws-elasticache | — |
| crossplane-provider-aws-elasticache | affected | chainguard | crossplane-provider-aws-elasticache | — |
| crossplane-provider-aws-firehose | affected | wolfi | crossplane-provider-aws-firehose | — |
| crossplane-provider-aws-firehose | affected | chainguard | crossplane-provider-aws-firehose | — |
| crossplane-provider-aws-iam | affected | wolfi | crossplane-provider-aws-iam | — |
| crossplane-provider-aws-iam | affected | chainguard | crossplane-provider-aws-iam | — |
| crossplane-provider-aws-kinesis | affected | chainguard | crossplane-provider-aws-kinesis | — |
| crossplane-provider-aws-kinesis | affected | wolfi | crossplane-provider-aws-kinesis | — |
| crossplane-provider-aws-kms | affected | wolfi | crossplane-provider-aws-kms | — |
| crossplane-provider-aws-kms | affected | chainguard | crossplane-provider-aws-kms | — |
| crossplane-provider-aws-lambda | affected | wolfi | crossplane-provider-aws-lambda | — |
| crossplane-provider-aws-lambda | affected | chainguard | crossplane-provider-aws-lambda | — |
| crossplane-provider-aws-memorydb | affected | chainguard | crossplane-provider-aws-memorydb | — |
| crossplane-provider-aws-memorydb | affected | wolfi | crossplane-provider-aws-memorydb | — |
| crossplane-provider-aws-rds | affected | wolfi | crossplane-provider-aws-rds | — |
| crossplane-provider-aws-rds | affected | chainguard | crossplane-provider-aws-rds | — |
| crossplane-provider-aws-route53 | affected | wolfi | crossplane-provider-aws-route53 | — |
| crossplane-provider-aws-route53 | affected | chainguard | crossplane-provider-aws-route53 | — |
| crossplane-provider-aws-s3 | affected | wolfi | crossplane-provider-aws-s3 | — |
| crossplane-provider-aws-s3 | affected | chainguard | crossplane-provider-aws-s3 | — |
| crossplane-provider-aws-sns | affected | wolfi | crossplane-provider-aws-sns | — |
| crossplane-provider-aws-sns | affected | chainguard | crossplane-provider-aws-sns | — |
| crossplane-provider-aws-sqs | affected | wolfi | crossplane-provider-aws-sqs | — |
| crossplane-provider-aws-sqs | affected | chainguard | crossplane-provider-aws-sqs | — |
| crossplane-provider-azure | affected | wolfi | crossplane-provider-azure | — |
| crossplane-provider-azure | affected | chainguard | crossplane-provider-azure | — |
| crossplane-provider-azure-authorization | affected | wolfi | crossplane-provider-azure-authorization | — |
| crossplane-provider-azure-authorization | affected | chainguard | crossplane-provider-azure-authorization | — |
| crossplane-provider-azure-managedidentity | affected | chainguard | crossplane-provider-azure-managedidentity | — |
| crossplane-provider-azure-managedidentity | affected | wolfi | crossplane-provider-azure-managedidentity | — |
| crossplane-provider-azure-sql | affected | chainguard | crossplane-provider-azure-sql | — |
| crossplane-provider-azure-sql | affected | wolfi | crossplane-provider-azure-sql | — |
| crossplane-provider-azure-storage | affected | wolfi | crossplane-provider-azure-storage | — |
| crossplane-provider-azure-storage | affected | chainguard | crossplane-provider-azure-storage | — |
| crossplane-provider-family-aws | affected | wolfi | crossplane-provider-family-aws | — |
| crossplane-provider-family-aws | affected | chainguard | crossplane-provider-family-aws | — |
| crossplane-provider-family-azure | affected | chainguard | crossplane-provider-family-azure | — |
| crossplane-provider-family-azure | affected | wolfi | crossplane-provider-family-azure | — |
| crossplane-provider-gcp | affected | wolfi | crossplane-provider-gcp | — |
| crossplane-provider-gcp | affected | chainguard | crossplane-provider-gcp | — |
| crossplane-provider-keycloak | affected | chainguard | crossplane-provider-keycloak | — |
| crossplane-provider-keycloak | affected | wolfi | crossplane-provider-keycloak | — |
| crossplane-provider-keycloak-fips | affected | chainguard | crossplane-provider-keycloak-fips | — |
| crossplane-provider-sql | affected | chainguard | crossplane-provider-sql | — |
| crossplane-provider-sql | affected | wolfi | crossplane-provider-sql | — |
| crossplane-provider-sql-fips | affected | chainguard | crossplane-provider-sql-fips | — |
| cue | affected | wolfi | cue | — |
| cue | affected | chainguard | cue | — |
| cue-fips | affected | chainguard | cue-fips | — |
| dagdotdev | affected | chainguard | dagdotdev | — |
| dagdotdev | affected | wolfi | dagdotdev | — |
| dagger | affected | wolfi | dagger | — |
| dagger | affected | chainguard | dagger | — |
| datadog-agent | affected | chainguard | datadog-agent | — |
| datadog-agent | affected | wolfi | datadog-agent | — |
| datadog-agent-fips | affected | chainguard | datadog-agent-fips | — |
| dbmate | affected | wolfi | dbmate | — |
| dbmate | affected | chainguard | dbmate | — |
| dcgm-exporter | affected | chainguard | dcgm-exporter | — |
| dcgm-exporter-fips | affected | chainguard | dcgm-exporter-fips | — |
| descheduler | affected | chainguard | descheduler | — |
| descheduler | affected | wolfi | descheduler | — |
| descheduler-fips | affected | chainguard | descheduler-fips | — |
| dex | affected | chainguard | dex | — |
| dex | affected | wolfi | dex | — |
| dex-fips | affected | chainguard | dex-fips | — |
| dex-k8s-authenticator | affected | chainguard | dex-k8s-authenticator | — |
| distribution | affected | chainguard | distribution | — |
| distribution | affected | wolfi | distribution | — |
| distribution-fips | affected | chainguard | distribution-fips | — |
| docker | affected | wolfi | docker | — |
| docker | affected | chainguard | docker | — |
| docker-cli-buildx | affected | wolfi | docker-cli-buildx | — |
| docker-cli-buildx | affected | chainguard | docker-cli-buildx | — |
| docker-cli-buildx-fips | affected | chainguard | docker-cli-buildx-fips | — |
| docker-compose | affected | wolfi | docker-compose | — |
| docker-compose | affected | chainguard | docker-compose | — |
| docker-compose-fips | affected | chainguard | docker-compose-fips | — |
| docker-credential-gcr | affected | chainguard | docker-credential-gcr | — |
| docker-credential-gcr | affected | wolfi | docker-credential-gcr | — |
| docker-credential-gcr-fips | affected | chainguard | docker-credential-gcr-fips | — |
| docker-fips | affected | chainguard | docker-fips | — |
| doppler-kubernetes-operator | affected | chainguard | doppler-kubernetes-operator | — |
| doppler-kubernetes-operator | affected | wolfi | doppler-kubernetes-operator | — |
| dynamic-localpv-provisioner | affected | wolfi | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner | affected | chainguard | dynamic-localpv-provisioner | — |
| dynamic-localpv-provisioner-fips | affected | chainguard | dynamic-localpv-provisioner-fips | — |
| eck-operator | affected | chainguard | eck-operator | — |
| eck-operator-fips | affected | chainguard | eck-operator-fips | — |
| eksctl | affected | chainguard | eksctl | — |
| eksctl | affected | wolfi | eksctl | — |
| eks-distro-1.27 | affected | chainguard | eks-distro-1.27 | — |
| eks-distro-1.28 | affected | chainguard | eks-distro-1.28 | — |
| eks-distro-1.29 | affected | chainguard | eks-distro-1.29 | — |
| eks-distro-1.30 | affected | chainguard | eks-distro-1.30 | — |
| eks-distro-1.31 | affected | chainguard | eks-distro-1.31 | — |
| eks-distro-1.32 | affected | chainguard | eks-distro-1.32 | — |
| eks-distro-fips-1.27 | affected | chainguard | eks-distro-fips-1.27 | — |
| eks-distro-fips-1.28 | affected | chainguard | eks-distro-fips-1.28 | — |
| eks-distro-fips-1.29 | affected | chainguard | eks-distro-fips-1.29 | — |
| eks-distro-fips-1.30 | affected | chainguard | eks-distro-fips-1.30 | — |
| eks-distro-fips-1.31 | affected | chainguard | eks-distro-fips-1.31 | — |
| eks-distro-fips-1.32 | affected | chainguard | eks-distro-fips-1.32 | — |
| elastic-agent-fips | affected | chainguard | elastic-agent-fips | — |
| emissary | affected | chainguard | emissary | — |
| emissary | affected | wolfi | emissary | — |
| emissary-fips | affected | chainguard | emissary-fips | — |
| external-dns | affected | wolfi | external-dns | — |
| external-dns | affected | chainguard | external-dns | — |
| external-dns-fips | affected | chainguard | external-dns-fips | — |
| external-secrets-fips | affected | chainguard | external-secrets-fips | — |
| external-secrets-operator | affected | wolfi | external-secrets-operator | — |
| external-secrets-operator | affected | chainguard | external-secrets-operator | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| falcosidekick | affected | chainguard | falcosidekick | — |
| falcosidekick | affected | wolfi | falcosidekick | — |
| falcosidekick-fips | affected | chainguard | falcosidekick-fips | — |
| flannel | affected | chainguard | flannel | — |
| flannel | affected | wolfi | flannel | — |
| fluent-bit-plugin-loki | affected | wolfi | fluent-bit-plugin-loki | — |
| fluent-bit-plugin-loki | affected | chainguard | fluent-bit-plugin-loki | — |
| fluent-operator | affected | chainguard | fluent-operator | — |
| fluent-operator | affected | wolfi | fluent-operator | — |
| fluent-operator-fips | affected | chainguard | fluent-operator-fips | — |
| flux | affected | wolfi | flux | — |
| flux | affected | chainguard | flux | — |
| flux-2.4 | affected | wolfi | flux-2.4 | — |
| flux-2.4 | affected | chainguard | flux-2.4 | — |
| flux-2.5 | affected | chainguard | flux-2.5 | — |
| flux-2.5 | affected | wolfi | flux-2.5 | — |
| flux-fips | affected | chainguard | flux-fips | — |
| flux-fips-2.4 | affected | chainguard | flux-fips-2.4 | — |
| flux-fips-2.5 | affected | chainguard | flux-fips-2.5 | — |
| flux-helm-controller | affected | wolfi | flux-helm-controller | — |
| flux-helm-controller | affected | chainguard | flux-helm-controller | — |
| flux-helm-controller-0.37 | affected | chainguard | flux-helm-controller-0.37 | — |
| flux-helm-controller-fips | affected | chainguard | flux-helm-controller-fips | — |
| flux-image-automation-controller | affected | wolfi | flux-image-automation-controller | — |
| flux-image-automation-controller | affected | chainguard | flux-image-automation-controller | — |
| flux-image-automation-controller-fips | affected | chainguard | flux-image-automation-controller-fips | — |
| flux-image-reflector-controller | affected | chainguard | flux-image-reflector-controller | — |
| flux-image-reflector-controller | affected | wolfi | flux-image-reflector-controller | — |
| flux-image-reflector-controller-fips | affected | chainguard | flux-image-reflector-controller-fips | — |
| flux-notification-controller | affected | wolfi | flux-notification-controller | — |
| flux-notification-controller | affected | chainguard | flux-notification-controller | — |
| flux-notification-controller-fips | affected | chainguard | flux-notification-controller-fips | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller-fips | affected | chainguard | flux-source-controller-fips | — |
| flyte | affected | chainguard | flyte | — |
| flyte | affected | wolfi | flyte | — |
| frp | affected | wolfi | frp | — |
| frp | affected | chainguard | frp | — |
| fulcio | affected | wolfi | fulcio | — |
| fulcio | affected | chainguard | fulcio | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| function-environment-configs | affected | chainguard | function-environment-configs | — |
| function-environment-configs-fips | affected | chainguard | function-environment-configs-fips | — |
| function-go-templating | affected | chainguard | function-go-templating | — |
| function-go-templating-fips | affected | chainguard | function-go-templating-fips | — |
| gatekeeper-3.16 | affected | chainguard | gatekeeper-3.16 | — |
| gatekeeper-3.16 | affected | wolfi | gatekeeper-3.16 | — |
| gatekeeper-3.17 | affected | chainguard | gatekeeper-3.17 | — |
| gatekeeper-3.17 | affected | wolfi | gatekeeper-3.17 | — |
| gatekeeper-3.18 | affected | wolfi | gatekeeper-3.18 | — |
| gatekeeper-3.18 | affected | chainguard | gatekeeper-3.18 | — |
| gatekeeper-fips-3.16 | affected | chainguard | gatekeeper-fips-3.16 | — |
| gatekeeper-fips-3.17 | affected | chainguard | gatekeeper-fips-3.17 | — |
| gatekeeper-fips-3.18 | affected | chainguard | gatekeeper-fips-3.18 | — |
| gatekeeper-fips-3.19 | affected | chainguard | gatekeeper-fips-3.19 | — |
| gatus | affected | wolfi | gatus | — |
| gatus | affected | chainguard | gatus | — |
| gcp-compute-persistent-disk-csi-driver-1.12 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-1.12 | — |
| gcp-compute-persistent-disk-csi-driver-1.13 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-1.13 | — |
| gcp-compute-persistent-disk-csi-driver-1.14 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-1.14 | — |
| gcp-compute-persistent-disk-csi-driver-1.15 | affected | wolfi | gcp-compute-persistent-disk-csi-driver-1.15 | — |
| gcp-compute-persistent-disk-csi-driver-1.15 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-1.15 | — |
| gcp-compute-persistent-disk-csi-driver-1.16 | affected | wolfi | gcp-compute-persistent-disk-csi-driver-1.16 | — |
| gcp-compute-persistent-disk-csi-driver-1.16 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-1.16 | — |
| gcp-compute-persistent-disk-csi-driver-1.17 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-1.17 | — |
| gcp-compute-persistent-disk-csi-driver-1.17 | affected | wolfi | gcp-compute-persistent-disk-csi-driver-1.17 | — |
| gcp-compute-persistent-disk-csi-driver-fips-1.12 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.12 | — |
| gcp-compute-persistent-disk-csi-driver-fips-1.13 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.13 | — |
| gcp-compute-persistent-disk-csi-driver-fips-1.14 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.14 | — |
| gcp-compute-persistent-disk-csi-driver-fips-1.15 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.15 | — |
| gcp-compute-persistent-disk-csi-driver-fips-1.16 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.16 | — |
| gcp-compute-persistent-disk-csi-driver-fips-1.17 | affected | chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.17 | — |
| gcsfuse | affected | wolfi | gcsfuse | — |
| gcsfuse | affected | chainguard | gcsfuse | — |
| ghaudit | affected | wolfi | ghaudit | — |
| ghaudit | affected | chainguard | ghaudit | — |
| gitaly-17.10 | affected | wolfi | gitaly-17.10 | — |
| gitaly-17.10 | affected | chainguard | gitaly-17.10 | — |
| gitaly-17.8 | affected | chainguard | gitaly-17.8 | — |
| gitaly-17.8 | affected | wolfi | gitaly-17.8 | — |
| gitaly-17.9 | affected | wolfi | gitaly-17.9 | — |
| gitaly-17.9 | affected | chainguard | gitaly-17.9 | — |
| gitaly-18.0 | affected | wolfi | gitaly-18.0 | — |
| gitaly-18.0 | affected | chainguard | gitaly-18.0 | — |
| gitaly-fips-17.10 | affected | chainguard | gitaly-fips-17.10 | — |
| gitaly-fips-17.8 | affected | chainguard | gitaly-fips-17.8 | — |
| gitaly-fips-17.9 | affected | chainguard | gitaly-fips-17.9 | — |
| git-credential-oauth | affected | chainguard | git-credential-oauth | — |
| git-credential-oauth | affected | wolfi | git-credential-oauth | — |
| gitlab-cng-17.8 | affected | wolfi | gitlab-cng-17.8 | — |
| gitlab-cng-17.8 | affected | chainguard | gitlab-cng-17.8 | — |
| gitlab-cng-17.9 | affected | wolfi | gitlab-cng-17.9 | — |
| gitlab-cng-17.9 | affected | chainguard | gitlab-cng-17.9 | — |
| gitlab-cng-fips-17.7 | affected | chainguard | gitlab-cng-fips-17.7 | — |
| gitlab-cng-fips-17.8 | affected | chainguard | gitlab-cng-fips-17.8 | — |
| gitlab-cng-fips-17.9 | affected | chainguard | gitlab-cng-fips-17.9 | — |
| gitlab-ee-17.10 | affected | chainguard | gitlab-ee-17.10 | — |
| gitlab-ee-17.7 | affected | chainguard | gitlab-ee-17.7 | — |
| gitlab-ee-17.9 | affected | chainguard | gitlab-ee-17.9 | — |
| gitlab-ee-fips-17.10 | affected | chainguard | gitlab-ee-fips-17.10 | — |
| gitlab-ee-fips-17.7 | affected | chainguard | gitlab-ee-fips-17.7 | — |
| gitlab-ee-fips-17.8 | affected | chainguard | gitlab-ee-fips-17.8 | — |
| gitlab-ee-fips-17.9 | affected | chainguard | gitlab-ee-fips-17.9 | — |
| gitlab-kas-17.7 | affected | wolfi | gitlab-kas-17.7 | — |
| gitlab-kas-17.7 | affected | chainguard | gitlab-kas-17.7 | — |
| gitlab-kas-17.8 | affected | chainguard | gitlab-kas-17.8 | — |
| gitlab-kas-17.8 | affected | wolfi | gitlab-kas-17.8 | — |
| gitlab-kas-17.9 | affected | wolfi | gitlab-kas-17.9 | — |
| gitlab-kas-17.9 | affected | chainguard | gitlab-kas-17.9 | — |
| gitlab-kas-fips-17.7 | affected | chainguard | gitlab-kas-fips-17.7 | — |
| gitlab-kas-fips-17.8 | affected | chainguard | gitlab-kas-fips-17.8 | — |
| gitlab-kas-fips-17.9 | affected | chainguard | gitlab-kas-fips-17.9 | — |
| gitlab-pages-17.10 | affected | wolfi | gitlab-pages-17.10 | — |
| gitlab-pages-17.10 | affected | chainguard | gitlab-pages-17.10 | — |
| gitlab-pages-17.7 | affected | chainguard | gitlab-pages-17.7 | — |
| gitlab-pages-17.7 | affected | wolfi | gitlab-pages-17.7 | — |
| gitlab-pages-17.8 | affected | wolfi | gitlab-pages-17.8 | — |
| gitlab-pages-17.8 | affected | chainguard | gitlab-pages-17.8 | — |
| gitlab-pages-17.9 | affected | chainguard | gitlab-pages-17.9 | — |
| gitlab-pages-17.9 | affected | wolfi | gitlab-pages-17.9 | — |
| gitlab-pages-fips-17.10 | affected | chainguard | gitlab-pages-fips-17.10 | — |
| gitlab-pages-fips-17.7 | affected | chainguard | gitlab-pages-fips-17.7 | — |
| gitlab-pages-fips-17.8 | affected | chainguard | gitlab-pages-fips-17.8 | — |
| gitlab-pages-fips-17.9 | affected | chainguard | gitlab-pages-fips-17.9 | — |
| gitlab-pages-fips-18.1 | affected | chainguard | gitlab-pages-fips-18.1 | — |
| gitlab-rails-ee-17.7 | affected | chainguard | gitlab-rails-ee-17.7 | — |
| gitlab-rails-ee-17.8 | affected | chainguard | gitlab-rails-ee-17.8 | — |
| gitlab-rails-ee-17.9 | affected | chainguard | gitlab-rails-ee-17.9 | — |
| gitlab-rails-ee-fips-17.7 | affected | chainguard | gitlab-rails-ee-fips-17.7 | — |
| gitlab-rails-ee-fips-17.8 | affected | chainguard | gitlab-rails-ee-fips-17.8 | — |
| gitlab-rails-ee-fips-17.9 | affected | chainguard | gitlab-rails-ee-fips-17.9 | — |
| gitlab-runner-17.10 | affected | wolfi | gitlab-runner-17.10 | — |
| gitlab-runner-17.10 | affected | chainguard | gitlab-runner-17.10 | — |
| gitlab-runner-17.9 | affected | wolfi | gitlab-runner-17.9 | — |
| gitlab-runner-17.9 | affected | chainguard | gitlab-runner-17.9 | — |
| gitlab-runner-fips-17.10 | affected | chainguard | gitlab-runner-fips-17.10 | — |
| gitlab-runner-fips-17.7 | affected | chainguard | gitlab-runner-fips-17.7 | — |
| gitlab-runner-fips-17.8 | affected | chainguard | gitlab-runner-fips-17.8 | — |
| gitlab-runner-fips-17.9 | affected | chainguard | gitlab-runner-fips-17.9 | — |
| gitness | affected | chainguard | gitness | — |
| gitness | affected | wolfi | gitness | — |
| gitsign | affected | chainguard | gitsign | — |
| gitsign | affected | wolfi | gitsign | — |
| gke-gcloud-auth-plugin | affected | chainguard | gke-gcloud-auth-plugin | — |
| gke-gcloud-auth-plugin | affected | wolfi | gke-gcloud-auth-plugin | — |
| glab | affected | wolfi | glab | — |
| glab | affected | chainguard | glab | — |
| go-discover | affected | wolfi | go-discover | — |
| go-discover | affected | chainguard | go-discover | — |
| go-discover-fips | affected | chainguard | go-discover-fips | — |
| go-ipfs-fips | affected | chainguard | go-ipfs-fips | — |
| gomplate | affected | wolfi | gomplate | — |
| gomplate | affected | chainguard | gomplate | — |
| google-guest-agent | affected | chainguard | google-guest-agent | — |
| google-guest-agent-manager | affected | chainguard | google-guest-agent-manager | — |
| google-osconfig-agent | affected | chainguard | google-osconfig-agent | — |
| goreleaser | affected | wolfi | goreleaser | — |
| goreleaser | affected | chainguard | goreleaser | — |
| gostatsd | affected | chainguard | gostatsd | — |
| gostatsd | affected | wolfi | gostatsd | — |
| gpu-feature-discovery | affected | chainguard | gpu-feature-discovery | — |
| gpu-operator | affected | chainguard | gpu-operator | — |
| grafana-10.4 | affected | chainguard | grafana-10.4 | — |
| grafana-10.4 | affected | wolfi | grafana-10.4 | — |
| grafana-11.0 | affected | wolfi | grafana-11.0 | — |
| grafana-11.0 | affected | chainguard | grafana-11.0 | — |
| grafana-11.1 | affected | wolfi | grafana-11.1 | — |
| grafana-11.1 | affected | chainguard | grafana-11.1 | — |
| grafana-11.2 | affected | chainguard | grafana-11.2 | — |
| grafana-11.2 | affected | wolfi | grafana-11.2 | — |
| grafana-11.3 | affected | chainguard | grafana-11.3 | — |
| grafana-11.3 | affected | wolfi | grafana-11.3 | — |
| grafana-11.4 | affected | chainguard | grafana-11.4 | — |
| grafana-11.4 | affected | wolfi | grafana-11.4 | — |
| grafana-11.5 | affected | chainguard | grafana-11.5 | — |
| grafana-11.5 | affected | wolfi | grafana-11.5 | — |
| grafana-agent-operator | affected | wolfi | grafana-agent-operator | — |
| grafana-agent-operator | affected | chainguard | grafana-agent-operator | — |
| grafana-alloy | affected | chainguard | grafana-alloy | — |
| grafana-alloy | affected | wolfi | grafana-alloy | — |
| grafana-alloy-fips | affected | chainguard | grafana-alloy-fips | — |
| grafana-fips-10.4 | affected | chainguard | grafana-fips-10.4 | — |
| grafana-fips-11.0 | affected | chainguard | grafana-fips-11.0 | — |
| grafana-fips-11.1 | affected | chainguard | grafana-fips-11.1 | — |
| grafana-fips-11.2 | affected | chainguard | grafana-fips-11.2 | — |
| grafana-fips-11.3 | affected | chainguard | grafana-fips-11.3 | — |
| grafana-fips-11.4 | affected | chainguard | grafana-fips-11.4 | — |
| grafana-fips-11.5 | affected | chainguard | grafana-fips-11.5 | — |
| grafana-mimir | affected | wolfi | grafana-mimir | — |
| grafana-mimir | affected | chainguard | grafana-mimir | — |
| grafana-mimir-fips | affected | chainguard | grafana-mimir-fips | — |
| grafana-operator | affected | wolfi | grafana-operator | — |
| grafana-operator | affected | chainguard | grafana-operator | — |
| grafana-operator-fips | affected | chainguard | grafana-operator-fips | — |
| grafana-rollout-operator | affected | wolfi | grafana-rollout-operator | — |
| grafana-rollout-operator | affected | chainguard | grafana-rollout-operator | — |
| grafana-rollout-operator-fips | affected | chainguard | grafana-rollout-operator-fips | — |
| grpcurl | affected | wolfi | grpcurl | — |
| grpcurl | affected | chainguard | grpcurl | — |
| grype | affected | wolfi | grype | — |
| grype | affected | chainguard | grype | — |
| grype-db | affected | chainguard | grype-db | — |
| grype-fips | affected | chainguard | grype-fips | — |
| guac | affected | chainguard | guac | — |
| guac | affected | wolfi | guac | — |
| haproxy-ingress | affected | wolfi | haproxy-ingress | — |
| haproxy-ingress | affected | chainguard | haproxy-ingress | — |
| harbor-2.10 | affected | chainguard | harbor-2.10 | — |
| harbor-2.10 | affected | wolfi | harbor-2.10 | — |
| harbor-2.11 | affected | chainguard | harbor-2.11 | — |
| harbor-2.11 | affected | wolfi | harbor-2.11 | — |
| harbor-2.12 | affected | chainguard | harbor-2.12 | — |
| harbor-2.12 | affected | wolfi | harbor-2.12 | — |
| harbor-2.9 | affected | chainguard | harbor-2.9 | — |
| harbor-fips-2.10 | affected | chainguard | harbor-fips-2.10 | — |
| harbor-fips-2.12 | affected | chainguard | harbor-fips-2.12 | — |
| harbor-fips-2.9 | affected | chainguard | harbor-fips-2.9 | — |
| harbor-registry | affected | chainguard | harbor-registry | — |
| harbor-registry | affected | wolfi | harbor-registry | — |
| harbor-registry-fips | affected | chainguard | harbor-registry-fips | — |
| helm | affected | wolfi | helm | — |
| helm | affected | chainguard | helm | — |
| helm-3 | affected | chainguard | helm-3 | — |
| helm-3 | affected | wolfi | helm-3 | — |
| helm-4 | affected | wolfi | helm-4 | — |
| helm-4 | affected | chainguard | helm-4 | — |
| helm-fips | affected | chainguard | helm-fips | — |
| helm-fips-3 | affected | chainguard | helm-fips-3 | — |
| helm-fips-4 | affected | chainguard | helm-fips-4 | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-operator-fips-1.33 | affected | chainguard | helm-operator-fips-1.33 | — |
| helm-push | affected | chainguard | helm-push | — |
| helm-push | affected | wolfi | helm-push | — |
| hubble | affected | chainguard | hubble | — |
| hubble | affected | wolfi | hubble | — |
| hubble-ui | affected | wolfi | hubble-ui | — |
| hubble-ui | affected | chainguard | hubble-ui | — |
| hubble-ui-backend | affected | chainguard | hubble-ui-backend | — |
| hubble-ui-backend-fips | affected | chainguard | hubble-ui-backend-fips | — |
| hydra | affected | chainguard | hydra | — |
| hydra | affected | wolfi | hydra | — |
| hydra-fips | affected | chainguard | hydra-fips | — |
| influxd | affected | wolfi | influxd | — |
| influxd | affected | chainguard | influxd | — |
| ingress-nginx-controller-1.10 | affected | chainguard | ingress-nginx-controller-1.10 | — |
| ingress-nginx-controller-1.10 | affected | wolfi | ingress-nginx-controller-1.10 | — |
| ingress-nginx-controller-1.11 | affected | chainguard | ingress-nginx-controller-1.11 | — |
| ingress-nginx-controller-1.11 | affected | wolfi | ingress-nginx-controller-1.11 | — |
| ingress-nginx-controller-1.12 | affected | chainguard | ingress-nginx-controller-1.12 | — |
| ingress-nginx-controller-1.12 | affected | wolfi | ingress-nginx-controller-1.12 | — |
| ingress-nginx-controller-fips-1.10 | affected | chainguard | ingress-nginx-controller-fips-1.10 | — |
| ingress-nginx-controller-fips-1.11 | affected | chainguard | ingress-nginx-controller-fips-1.11 | — |
| ipfs | affected | wolfi | ipfs | — |
| ipfs | affected | chainguard | ipfs | — |
| istio-1.24 | affected | chainguard | istio-1.24 | — |
| istio-1.24 | affected | wolfi | istio-1.24 | — |
| istio-1.25 | affected | chainguard | istio-1.25 | — |
| istio-1.25 | affected | wolfi | istio-1.25 | — |
| istio-cni-1.22 | affected | chainguard | istio-cni-1.22 | — |
| istio-fips-1.21 | affected | chainguard | istio-fips-1.21 | — |
| istio-fips-1.22 | affected | chainguard | istio-fips-1.22 | — |
| istio-fips-1.23 | affected | chainguard | istio-fips-1.23 | — |
| istio-fips-1.24 | affected | chainguard | istio-fips-1.24 | — |
| istio-fips-1.25 | affected | chainguard | istio-fips-1.25 | — |
| istio-operator-1.21 | affected | chainguard | istio-operator-1.21 | — |
| istio-operator-1.21 | affected | wolfi | istio-operator-1.21 | — |
| istio-operator-1.22 | affected | wolfi | istio-operator-1.22 | — |
| istio-operator-1.22 | affected | chainguard | istio-operator-1.22 | — |
| istio-pilot-agent-1.21 | affected | chainguard | istio-pilot-agent-1.21 | — |
| istio-pilot-agent-1.21 | affected | wolfi | istio-pilot-agent-1.21 | — |
| istio-pilot-agent-1.22 | affected | wolfi | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22 | affected | chainguard | istio-pilot-agent-1.22 | — |
| istio-pilot-discovery-1.22 | affected | chainguard | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22 | affected | wolfi | istio-pilot-discovery-1.22 | — |
| jaeger-operator | affected | wolfi | jaeger-operator | — |
| jaeger-operator | affected | chainguard | jaeger-operator | — |
| jaeger-operator-fips | affected | chainguard | jaeger-operator-fips | — |
| jitsucom-bulker | affected | chainguard | jitsucom-bulker | — |
| jitsucom-bulker | affected | wolfi | jitsucom-bulker | — |
| k3d | affected | chainguard | k3d | — |
| k3d | affected | wolfi | k3d | — |
| k3s | affected | chainguard | k3s | — |
| k3s | affected | wolfi | k3s | — |
| k3s-1.31 | affected | chainguard | k3s-1.31 | — |
| k3s-1.32 | affected | chainguard | k3s-1.32 | — |
| k3s-1.32 | affected | wolfi | k3s-1.32 | — |
| k8s-device-plugin | affected | chainguard | k8s-device-plugin | — |
| k8s-device-plugin | affected | wolfi | k8s-device-plugin | — |
| k8s-device-plugin-fips | affected | chainguard | k8s-device-plugin-fips | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt-operator | affected | wolfi | k8sgpt-operator | — |
| k8sgpt-operator | affected | chainguard | k8sgpt-operator | — |
| k8ssandra-client | affected | wolfi | k8ssandra-client | — |
| k8ssandra-client | affected | chainguard | k8ssandra-client | — |
| k8ssandra-client-fips | affected | chainguard | k8ssandra-client-fips | — |
| k8ssandra-operator | affected | wolfi | k8ssandra-operator | — |
| k8ssandra-operator | affected | chainguard | k8ssandra-operator | — |
| k9s | affected | wolfi | k9s | — |
| k9s | affected | chainguard | k9s | — |
| kaf | affected | wolfi | kaf | — |
| kaf | affected | chainguard | kaf | — |
| kafka-proxy | affected | chainguard | kafka-proxy | — |
| kafka-proxy | affected | wolfi | kafka-proxy | — |
| kaniko | affected | wolfi | kaniko | — |
| kaniko | affected | chainguard | kaniko | — |
| kaniko-fips | affected | chainguard | kaniko-fips | — |
| kapp | affected | wolfi | kapp | — |
| kapp | affected | chainguard | kapp | — |
| kapp-controller | affected | wolfi | kapp-controller | — |
| kapp-controller | affected | chainguard | kapp-controller | — |
| kapp-controller-fips | affected | chainguard | kapp-controller-fips | — |
| kapp-fips | affected | chainguard | kapp-fips | — |
| kargo | affected | chainguard | kargo | — |
| kargo | affected | wolfi | kargo | — |
| karpenter-0.23 | affected | chainguard | karpenter-0.23 | — |
| karpenter-0.33 | affected | chainguard | karpenter-0.33 | — |
| karpenter-0.34 | affected | chainguard | karpenter-0.34 | — |
| karpenter-0.35 | affected | chainguard | karpenter-0.35 | — |
| karpenter-0.36 | affected | chainguard | karpenter-0.36 | — |
| karpenter-0.37 | affected | chainguard | karpenter-0.37 | — |
| karpenter-1.0 | affected | wolfi | karpenter-1.0 | — |
| karpenter-1.0 | affected | chainguard | karpenter-1.0 | — |
| karpenter-1.1 | affected | wolfi | karpenter-1.1 | — |
| karpenter-1.1 | affected | chainguard | karpenter-1.1 | — |
| karpenter-1.2 | affected | wolfi | karpenter-1.2 | — |
| karpenter-1.2 | affected | chainguard | karpenter-1.2 | — |
| karpenter-fips-0.33 | affected | chainguard | karpenter-fips-0.33 | — |
| karpenter-fips-0.34 | affected | chainguard | karpenter-fips-0.34 | — |
| karpenter-fips-0.35 | affected | chainguard | karpenter-fips-0.35 | — |
| karpenter-fips-0.36 | affected | chainguard | karpenter-fips-0.36 | — |
| karpenter-fips-0.37 | affected | chainguard | karpenter-fips-0.37 | — |
| karpenter-fips-1.0 | affected | chainguard | karpenter-fips-1.0 | — |
| karpenter-fips-1.1 | affected | chainguard | karpenter-fips-1.1 | — |
| karpenter-fips-1.2 | affected | chainguard | karpenter-fips-1.2 | — |
| karpenter-fips-1.3 | affected | chainguard | karpenter-fips-1.3 | — |
| keda-2.15 | affected | chainguard | keda-2.15 | — |
| keda-2.15 | affected | wolfi | keda-2.15 | — |
| keda-2.16 | affected | chainguard | keda-2.16 | — |
| keda-2.16 | affected | wolfi | keda-2.16 | — |
| keda-fips | affected | chainguard | keda-fips | — |
| kepler | affected | chainguard | kepler | — |
| kiali | affected | chainguard | kiali | — |
| kiali | affected | wolfi | kiali | — |
| kiali-fips | affected | chainguard | kiali-fips | — |
| kiam | affected | chainguard | kiam | — |
| knative-client | affected | chainguard | knative-client | — |
| knative-client | affected | wolfi | knative-client | — |
| knative-operator-1.18 | affected | chainguard | knative-operator-1.18 | — |
| knative-operator-1.18 | affected | wolfi | knative-operator-1.18 | — |
| knative-serving-1.15 | affected | chainguard | knative-serving-1.15 | — |
| knative-serving-1.16 | affected | wolfi | knative-serving-1.16 | — |
| knative-serving-1.16 | affected | chainguard | knative-serving-1.16 | — |
| knative-serving-1.17 | affected | chainguard | knative-serving-1.17 | — |
| knative-serving-1.17 | affected | wolfi | knative-serving-1.17 | — |
| knative-serving-1.18 | affected | wolfi | knative-serving-1.18 | — |
| knative-serving-1.18 | affected | chainguard | knative-serving-1.18 | — |
| ko | affected | wolfi | ko | — |
| ko | affected | chainguard | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| ko-fips | affected | wolfi | ko-fips | — |
| kor | affected | wolfi | kor | — |
| kor | affected | chainguard | kor | — |
| kots | affected | chainguard | kots | — |
| kots | affected | wolfi | kots | — |
| kots-compat | affected | chainguard | kots-compat | — |
| kpt | affected | chainguard | kpt | — |
| kpt | affected | wolfi | kpt | — |
| kserve | affected | chainguard | kserve | — |
| kserve | affected | wolfi | kserve | — |
| kserve-modelmesh-serving | affected | wolfi | kserve-modelmesh-serving | — |
| kserve-modelmesh-serving | affected | chainguard | kserve-modelmesh-serving | — |
| ksops | affected | chainguard | ksops | — |
| ksops | affected | wolfi | ksops | — |
| kubeadm-bootstrap-controller | affected | chainguard | kubeadm-bootstrap-controller | — |
| kubeadm-bootstrap-controller | affected | wolfi | kubeadm-bootstrap-controller | — |
| kubeadm-controlplane-controller | affected | chainguard | kubeadm-controlplane-controller | — |
| kubeadm-controlplane-controller | affected | wolfi | kubeadm-controlplane-controller | — |
| kube-bench | affected | wolfi | kube-bench | — |
| kube-bench | affected | chainguard | kube-bench | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubeflow | affected | chainguard | kubeflow | — |
| kubeflow | affected | wolfi | kubeflow | — |
| kubeflow-fips | affected | chainguard | kubeflow-fips | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kube-fluentd-operator | affected | chainguard | kube-fluentd-operator | — |
| kube-fluentd-operator | affected | wolfi | kube-fluentd-operator | — |
| kube-logging-logging-operator-3.17 | affected | chainguard | kube-logging-logging-operator-3.17 | — |
| kube-logging-logging-operator-4.1 | affected | chainguard | kube-logging-logging-operator-4.1 | — |
| kube-logging-operator | affected | wolfi | kube-logging-operator | — |
| kube-logging-operator | affected | chainguard | kube-logging-operator | — |
| kube-oidc-proxy | affected | chainguard | kube-oidc-proxy | — |
| kuberay-operator | affected | wolfi | kuberay-operator | — |
| kuberay-operator | affected | chainguard | kuberay-operator | — |
| kuberay-operator-fips | affected | chainguard | kuberay-operator-fips | — |
| kube-rbac-proxy | affected | wolfi | kube-rbac-proxy | — |
| kube-rbac-proxy | affected | chainguard | kube-rbac-proxy | — |
| kube-rbac-proxy-fips | affected | chainguard | kube-rbac-proxy-fips | — |
| kuberlr | affected | chainguard | kuberlr | — |
| kuberlr | affected | wolfi | kuberlr | — |
| kubernetes-1.26 | affected | chainguard | kubernetes-1.26 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-1.30 | affected | wolfi | kubernetes-1.30 | — |
| kubernetes-1.30 | affected | chainguard | kubernetes-1.30 | — |
| kubernetes-1.31 | affected | chainguard | kubernetes-1.31 | — |
| kubernetes-1.31 | affected | wolfi | kubernetes-1.31 | — |
| kubernetes-1.32 | affected | chainguard | kubernetes-1.32 | — |
| kubernetes-1.32 | affected | wolfi | kubernetes-1.32 | — |
| kubernetes-csi-driver-nfs | affected | chainguard | kubernetes-csi-driver-nfs | — |
| kubernetes-csi-driver-nfs | affected | wolfi | kubernetes-csi-driver-nfs | — |
| kubernetes-csi-driver-nfs-fips | affected | chainguard | kubernetes-csi-driver-nfs-fips | — |
| kubernetes-csi-external-attacher | affected | wolfi | kubernetes-csi-external-attacher | — |
| kubernetes-csi-external-attacher | affected | chainguard | kubernetes-csi-external-attacher | — |
| kubernetes-csi-external-attacher-fips | affected | chainguard | kubernetes-csi-external-attacher-fips | — |
| kubernetes-csi-external-provisioner | affected | chainguard | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner | affected | wolfi | kubernetes-csi-external-provisioner | — |
| kubernetes-csi-external-provisioner-fips | affected | chainguard | kubernetes-csi-external-provisioner-fips | — |
| kubernetes-csi-external-resizer | affected | wolfi | kubernetes-csi-external-resizer | — |
| kubernetes-csi-external-resizer | affected | chainguard | kubernetes-csi-external-resizer | — |
| kubernetes-csi-external-resizer-fips | affected | chainguard | kubernetes-csi-external-resizer-fips | — |
| kubernetes-csi-external-snapshotter-6.3 | affected | chainguard | kubernetes-csi-external-snapshotter-6.3 | — |
| kubernetes-csi-external-snapshotter-7.0 | affected | chainguard | kubernetes-csi-external-snapshotter-7.0 | — |
| kubernetes-csi-external-snapshotter-8.2 | affected | wolfi | kubernetes-csi-external-snapshotter-8.2 | — |
| kubernetes-csi-external-snapshotter-8.2 | affected | chainguard | kubernetes-csi-external-snapshotter-8.2 | — |
| kubernetes-csi-external-snapshotter-fips-6.3 | affected | chainguard | kubernetes-csi-external-snapshotter-fips-6.3 | — |
| kubernetes-csi-external-snapshotter-fips-7.0 | affected | chainguard | kubernetes-csi-external-snapshotter-fips-7.0 | — |
| kubernetes-csi-external-snapshotter-fips-8.0 | affected | chainguard | kubernetes-csi-external-snapshotter-fips-8.0 | — |
| kubernetes-csi-external-snapshotter-fips-8.1 | affected | chainguard | kubernetes-csi-external-snapshotter-fips-8.1 | — |
| kubernetes-csi-external-snapshotter-fips-8.2 | affected | chainguard | kubernetes-csi-external-snapshotter-fips-8.2 | — |
| kubernetes-dashboard | affected | wolfi | kubernetes-dashboard | — |
| kubernetes-dashboard | affected | chainguard | kubernetes-dashboard | — |
| kubernetes-dashboard-api | affected | wolfi | kubernetes-dashboard-api | — |
| kubernetes-dashboard-api | affected | chainguard | kubernetes-dashboard-api | — |
| kubernetes-dashboard-api-fips | affected | chainguard | kubernetes-dashboard-api-fips | — |
| kubernetes-dashboard-auth | affected | wolfi | kubernetes-dashboard-auth | — |
| kubernetes-dashboard-auth | affected | chainguard | kubernetes-dashboard-auth | — |
| kubernetes-dashboard-auth-fips | affected | chainguard | kubernetes-dashboard-auth-fips | — |
| kubernetes-dashboard-fips | affected | chainguard | kubernetes-dashboard-fips | — |
| kubernetes-dashboard-metrics-scraper | affected | wolfi | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper | affected | chainguard | kubernetes-dashboard-metrics-scraper | — |
| kubernetes-dashboard-metrics-scraper-fips | affected | chainguard | kubernetes-dashboard-metrics-scraper-fips | — |
| kubernetes-dashboard-web | affected | chainguard | kubernetes-dashboard-web | — |
| kubernetes-dashboard-web | affected | wolfi | kubernetes-dashboard-web | — |
| kubernetes-dashboard-web-fips | affected | chainguard | kubernetes-dashboard-web-fips | — |
| kubernetes-dns-node-cache | affected | chainguard | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache | affected | wolfi | kubernetes-dns-node-cache | — |
| kubernetes-dns-node-cache-fips | affected | chainguard | kubernetes-dns-node-cache-fips | — |
| kubernetes-event-exporter | affected | wolfi | kubernetes-event-exporter | — |
| kubernetes-event-exporter | affected | chainguard | kubernetes-event-exporter | — |
| kubernetes-event-exporter-fips | affected | chainguard | kubernetes-event-exporter-fips | — |
| kubernetes-fips-1.28 | affected | chainguard | kubernetes-fips-1.28 | — |
| kubernetes-fips-1.29 | affected | chainguard | kubernetes-fips-1.29 | — |
| kubernetes-fips-1.30 | affected | chainguard | kubernetes-fips-1.30 | — |
| kubernetes-fips-1.31 | affected | chainguard | kubernetes-fips-1.31 | — |
| kubernetes-fips-1.32 | affected | chainguard | kubernetes-fips-1.32 | — |
| kubernetes-replicator | affected | chainguard | kubernetes-replicator | — |
| kubernetes-replicator | affected | wolfi | kubernetes-replicator | — |
| kubernetes-replicator-fips | affected | chainguard | kubernetes-replicator-fips | — |
| kubescape | affected | chainguard | kubescape | — |
| kubescape | affected | wolfi | kubescape | — |
| kube-state-metrics | affected | wolfi | kube-state-metrics | — |
| kube-state-metrics | affected | chainguard | kube-state-metrics | — |
| kube-state-metrics-2.6 | affected | chainguard | kube-state-metrics-2.6 | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kubevela | affected | wolfi | kubevela | — |
| kubevela | affected | chainguard | kubevela | — |
| kube-vip | affected | chainguard | kube-vip | — |
| kube-vip | affected | wolfi | kube-vip | — |
| kube-vip-fips | affected | chainguard | kube-vip-fips | — |
| kubewatch | affected | wolfi | kubewatch | — |
| kubewatch | affected | chainguard | kubewatch | — |
| kuma-2.5 | affected | chainguard | kuma-2.5 | — |
| kuma-2.6 | affected | chainguard | kuma-2.6 | — |
| kwok | affected | chainguard | kwok | — |
| kwok | affected | wolfi | kwok | — |
| kyverno-1.11 | affected | chainguard | kyverno-1.11 | — |
| kyverno-1.12 | affected | chainguard | kyverno-1.12 | — |
| kyverno-1.12 | affected | wolfi | kyverno-1.12 | — |
| kyverno-1.13 | affected | wolfi | kyverno-1.13 | — |
| kyverno-1.13 | affected | chainguard | kyverno-1.13 | — |
| kyverno-fips-1.11 | affected | chainguard | kyverno-fips-1.11 | — |
| kyverno-fips-1.12 | affected | chainguard | kyverno-fips-1.12 | — |
| kyverno-fips-1.13 | affected | chainguard | kyverno-fips-1.13 | — |
| kyverno-notation-aws | affected | chainguard | kyverno-notation-aws | — |
| kyverno-notation-aws | affected | wolfi | kyverno-notation-aws | — |
| kyverno-policy-reporter-kyverno-plugin | affected | chainguard | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-kyverno-plugin | affected | wolfi | kyverno-policy-reporter-kyverno-plugin | — |
| kyverno-policy-reporter-kyverno-plugin-fips | affected | chainguard | kyverno-policy-reporter-kyverno-plugin-fips | — |
| kyverno-policy-reporter-ui-fips | affected | chainguard | kyverno-policy-reporter-ui-fips | — |
| linkerd2 | affected | chainguard | linkerd2 | — |
| linkerd2 | affected | wolfi | linkerd2 | — |
| litestream | affected | chainguard | litestream | — |
| litestream | affected | wolfi | litestream | — |
| local-path-provisioner | affected | chainguard | local-path-provisioner | — |
| local-path-provisioner | affected | wolfi | local-path-provisioner | — |
| local-path-provisioner-fips | affected | chainguard | local-path-provisioner-fips | — |
| local-static-provisioner | affected | wolfi | local-static-provisioner | — |
| local-static-provisioner | affected | chainguard | local-static-provisioner | — |
| local-static-provisioner-fips | affected | chainguard | local-static-provisioner-fips | — |
| loki-3.2 | affected | chainguard | loki-3.2 | — |
| loki-3.2 | affected | wolfi | loki-3.2 | — |
| loki-3.3 | affected | wolfi | loki-3.3 | — |
| loki-3.3 | affected | chainguard | loki-3.3 | — |
| loki-3.4 | affected | chainguard | loki-3.4 | — |
| loki-3.4 | affected | wolfi | loki-3.4 | — |
| loki-fips-3.2 | affected | chainguard | loki-fips-3.2 | — |
| loki-fips-3.3 | affected | chainguard | loki-fips-3.3 | — |
| loki-fips-3.4 | affected | chainguard | loki-fips-3.4 | — |
| longhorn-instance-manager-1.8 | affected | chainguard | longhorn-instance-manager-1.8 | — |
| longhorn-share-manager-1.8 | affected | chainguard | longhorn-share-manager-1.8 | — |
| longhorn-share-manager-fips-1.8 | affected | chainguard | longhorn-share-manager-fips-1.8 | — |
| lvm-driver | affected | wolfi | lvm-driver | — |
| lvm-driver | affected | chainguard | lvm-driver | — |
| memcached-exporter | affected | wolfi | memcached-exporter | — |
| memcached-exporter | affected | chainguard | memcached-exporter | — |
| memcached-exporter-fips | affected | chainguard | memcached-exporter-fips | — |
| metacontroller | affected | wolfi | metacontroller | — |
| metacontroller | affected | chainguard | metacontroller | — |
| metallb | affected | chainguard | metallb | — |
| metallb | affected | wolfi | metallb | — |
| metallb-fips | affected | chainguard | metallb-fips | — |
| metrics-server | affected | chainguard | metrics-server | — |
| metrics-server | affected | wolfi | metrics-server | — |
| metrics-server-fips | affected | chainguard | metrics-server-fips | — |
| minio | affected | chainguard | minio | — |
| minio | affected | wolfi | minio | — |
| minio-fips | affected | chainguard | minio-fips | — |
| minio-operator | affected | wolfi | minio-operator | — |
| minio-operator | affected | chainguard | minio-operator | — |
| minio-operator-fips | affected | chainguard | minio-operator-fips | — |
| modelmesh-runtime-adapter | affected | chainguard | modelmesh-runtime-adapter | — |
| modelmesh-runtime-adapter | affected | wolfi | modelmesh-runtime-adapter | — |
| mountpoint-s3-csi-driver | affected | chainguard | mountpoint-s3-csi-driver | — |
| mountpoint-s3-csi-driver | affected | wolfi | mountpoint-s3-csi-driver | — |
| mountpoint-s3-csi-driver-1.15 | affected | chainguard | mountpoint-s3-csi-driver-1.15 | — |
| multus-cni | affected | wolfi | multus-cni | — |
| multus-cni | affected | chainguard | multus-cni | — |
| multus-cni-4.0.2 | affected | chainguard | multus-cni-4.0.2 | — |
| multus-cni-fips | affected | chainguard | multus-cni-fips | — |
| multus-cni-fips-4.0.2 | affected | chainguard | multus-cni-fips-4.0.2 | — |
| nemo | affected | chainguard | nemo | — |
| net-kourier-fips-1.16 | affected | chainguard | net-kourier-fips-1.16 | — |
| neuvector | affected | wolfi | neuvector | — |
| neuvector | affected | chainguard | neuvector | — |
| neuvector-fips | affected | chainguard | neuvector-fips | — |
| neuvector-sigstore-interface | affected | wolfi | neuvector-sigstore-interface | — |
| neuvector-sigstore-interface | affected | chainguard | neuvector-sigstore-interface | — |
| neuvector-sigstore-interface-fips | affected | chainguard | neuvector-sigstore-interface-fips | — |
| newrelic-infra-operator | affected | wolfi | newrelic-infra-operator | — |
| newrelic-infra-operator | affected | chainguard | newrelic-infra-operator | — |
| newrelic-infrastructure-agent | affected | wolfi | newrelic-infrastructure-agent | — |
| newrelic-infrastructure-agent | affected | chainguard | newrelic-infrastructure-agent | — |
| newrelic-infrastructure-agent-1.43 | affected | chainguard | newrelic-infrastructure-agent-1.43 | — |
| newrelic-nri-kube-events | affected | wolfi | newrelic-nri-kube-events | — |
| newrelic-nri-kube-events | affected | chainguard | newrelic-nri-kube-events | — |
| newrelic-nri-kube-events-1.9 | affected | chainguard | newrelic-nri-kube-events-1.9 | — |
| newrelic-nri-statsd | affected | chainguard | newrelic-nri-statsd | — |
| newrelic-nri-statsd | affected | wolfi | newrelic-nri-statsd | — |
| nfs-subdir-external-provisioner | affected | chainguard | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner | affected | wolfi | nfs-subdir-external-provisioner | — |
| nfs-subdir-external-provisioner-fips | affected | chainguard | nfs-subdir-external-provisioner-fips | — |
| nginx-prometheus-exporter | affected | chainguard | nginx-prometheus-exporter | — |
| nginx-prometheus-exporter | affected | wolfi | nginx-prometheus-exporter | — |
| nginx-prometheus-exporter-fips | affected | chainguard | nginx-prometheus-exporter-fips | — |
| node-feature-discovery-0.15 | affected | wolfi | node-feature-discovery-0.15 | — |
| node-feature-discovery-0.15 | affected | chainguard | node-feature-discovery-0.15 | — |
| node-feature-discovery-0.16 | affected | wolfi | node-feature-discovery-0.16 | — |
| node-feature-discovery-0.16 | affected | chainguard | node-feature-discovery-0.16 | — |
| node-feature-discovery-0.17 | affected | chainguard | node-feature-discovery-0.17 | — |
| node-feature-discovery-0.17 | affected | wolfi | node-feature-discovery-0.17 | — |
| node-feature-discovery-fips-0.16 | affected | chainguard | node-feature-discovery-fips-0.16 | — |
| node-feature-discovery-fips-0.17 | affected | chainguard | node-feature-discovery-fips-0.17 | — |
| node-problem-detector-0.8 | affected | wolfi | node-problem-detector-0.8 | — |
| node-problem-detector-0.8 | affected | chainguard | node-problem-detector-0.8 | — |
| node-problem-detector-fips-0.8 | affected | chainguard | node-problem-detector-fips-0.8 | — |
| nodetaint | affected | wolfi | nodetaint | — |
| nodetaint | affected | chainguard | nodetaint | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nri-kubernetes | affected | chainguard | nri-kubernetes | — |
| nri-kubernetes | affected | wolfi | nri-kubernetes | — |
| nri-kubernetes-2.13 | affected | chainguard | nri-kubernetes-2.13 | — |
| nri-prometheus | affected | chainguard | nri-prometheus | — |
| nri-prometheus | affected | wolfi | nri-prometheus | — |
| nuclei | affected | chainguard | nuclei | — |
| nuclei | affected | wolfi | nuclei | — |
| nvidia-gpu-operator-validator-24.3 | affected | chainguard | nvidia-gpu-operator-validator-24.3 | — |
| oauth2-proxy | affected | chainguard | oauth2-proxy | — |
| oauth2-proxy | affected | wolfi | oauth2-proxy | — |
| octo-sts | affected | wolfi | octo-sts | — |
| octo-sts | affected | chainguard | octo-sts | — |
| openbao | affected | wolfi | openbao | — |
| openbao | affected | chainguard | openbao | — |
| openbao-fips | affected | chainguard | openbao-fips | — |
| openbao-k8s | affected | wolfi | openbao-k8s | — |
| openbao-k8s | affected | chainguard | openbao-k8s | — |
| openbao-k8s-fips | affected | chainguard | openbao-k8s-fips | — |
| opencost | affected | wolfi | opencost | — |
| opencost | affected | chainguard | opencost | — |
| opencost-fips | affected | chainguard | opencost-fips | — |
| openfga | affected | wolfi | openfga | — |
| openfga | affected | chainguard | openfga | — |
| opensearch-k8s-operator | affected | chainguard | opensearch-k8s-operator | — |
| opensearch-k8s-operator | affected | wolfi | opensearch-k8s-operator | — |
| opentelemetry-collector | affected | chainguard | opentelemetry-collector | — |
| opentelemetry-collector | affected | wolfi | opentelemetry-collector | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| opentelemetry-operator | affected | wolfi | opentelemetry-operator | — |
| opentelemetry-operator | affected | chainguard | opentelemetry-operator | — |
| opentelemetry-operator-fips | affected | chainguard | opentelemetry-operator-fips | — |
| opentofu-1.6 | affected | chainguard | opentofu-1.6 | — |
| opentofu-1.7 | affected | wolfi | opentofu-1.7 | — |
| opentofu-1.7 | affected | chainguard | opentofu-1.7 | — |
| opentofu-1.8 | affected | wolfi | opentofu-1.8 | — |
| opentofu-1.8 | affected | chainguard | opentofu-1.8 | — |
| opentofu-1.9 | affected | chainguard | opentofu-1.9 | — |
| opentofu-1.9 | affected | wolfi | opentofu-1.9 | — |
| opentofu-fips-1.6 | affected | chainguard | opentofu-fips-1.6 | — |
| opentofu-fips-1.7 | affected | chainguard | opentofu-fips-1.7 | — |
| opentofu-fips-1.8 | affected | chainguard | opentofu-fips-1.8 | — |
| opentofu-fips-1.9 | affected | chainguard | opentofu-fips-1.9 | — |
| packer | affected | chainguard | packer | — |
| packer-fips | affected | chainguard | packer-fips | — |
| pluto | affected | wolfi | pluto | — |
| pluto | affected | chainguard | pluto | — |
| podman | affected | wolfi | podman | — |
| podman | affected | chainguard | podman | — |
| podman-fips | affected | chainguard | podman-fips | — |
| policy-controller | affected | wolfi | policy-controller | — |
| policy-controller | affected | chainguard | policy-controller | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| portieris | affected | wolfi | portieris | — |
| portieris | affected | chainguard | portieris | — |
| portieris-fips | affected | chainguard | portieris-fips | — |
| postgres-operator | affected | chainguard | postgres-operator | — |
| postgres-operator | affected | wolfi | postgres-operator | — |
| postgres-operator-fips | affected | chainguard | postgres-operator-fips | — |
| prometheus-2.51 | affected | chainguard | prometheus-2.51 | — |
| prometheus-2.53 | affected | chainguard | prometheus-2.53 | — |
| prometheus-2.53 | affected | wolfi | prometheus-2.53 | — |
| prometheus-2.55 | affected | chainguard | prometheus-2.55 | — |
| prometheus-2.55 | affected | wolfi | prometheus-2.55 | — |
| prometheus-3.1 | affected | wolfi | prometheus-3.1 | — |
| prometheus-3.1 | affected | chainguard | prometheus-3.1 | — |
| prometheus-3.2 | affected | wolfi | prometheus-3.2 | — |
| prometheus-3.2 | affected | chainguard | prometheus-3.2 | — |
| prometheus-adapter | affected | chainguard | prometheus-adapter | — |
| prometheus-adapter | affected | wolfi | prometheus-adapter | — |
| prometheus-adapter-0.10 | affected | chainguard | prometheus-adapter-0.10 | — |
| prometheus-adapter-fips | affected | chainguard | prometheus-adapter-fips | — |
| prometheus-adapter-fips-0.10 | affected | chainguard | prometheus-adapter-fips-0.10 | — |
| prometheus-alertmanager | affected | chainguard | prometheus-alertmanager | — |
| prometheus-alertmanager | affected | wolfi | prometheus-alertmanager | — |
| prometheus-alertmanager-fips | affected | chainguard | prometheus-alertmanager-fips | — |
| prometheus-bind-exporter | affected | chainguard | prometheus-bind-exporter | — |
| prometheus-bind-exporter | affected | wolfi | prometheus-bind-exporter | — |
| prometheus-blackbox-exporter | affected | wolfi | prometheus-blackbox-exporter | — |
| prometheus-blackbox-exporter | affected | chainguard | prometheus-blackbox-exporter | — |
| prometheus-blackbox-exporter-fips | affected | chainguard | prometheus-blackbox-exporter-fips | — |
| prometheus-elasticsearch-exporter | affected | chainguard | prometheus-elasticsearch-exporter | — |
| prometheus-elasticsearch-exporter | affected | wolfi | prometheus-elasticsearch-exporter | — |
| prometheus-elasticsearch-exporter-fips | affected | chainguard | prometheus-elasticsearch-exporter-fips | — |
| prometheus-fips-2.53 | affected | chainguard | prometheus-fips-2.53 | — |
| prometheus-fips-2.54 | affected | chainguard | prometheus-fips-2.54 | — |
| prometheus-fips-2.55 | affected | chainguard | prometheus-fips-2.55 | — |
| prometheus-fips-3.0 | affected | chainguard | prometheus-fips-3.0 | — |
| prometheus-fips-3.1 | affected | chainguard | prometheus-fips-3.1 | — |
| prometheus-fips-3.2 | affected | chainguard | prometheus-fips-3.2 | — |
| prometheus-mongodb-exporter | affected | wolfi | prometheus-mongodb-exporter | — |
| prometheus-mongodb-exporter | affected | chainguard | prometheus-mongodb-exporter | — |
| prometheus-mongodb-exporter-0.37 | affected | chainguard | prometheus-mongodb-exporter-0.37 | — |
| prometheus-mongodb-exporter-fips | affected | chainguard | prometheus-mongodb-exporter-fips | — |
| prometheus-mongodb-exporter-fips-0.37 | affected | chainguard | prometheus-mongodb-exporter-fips-0.37 | — |
| prometheus-mysqld-exporter | affected | wolfi | prometheus-mysqld-exporter | — |
| prometheus-mysqld-exporter | affected | chainguard | prometheus-mysqld-exporter | — |
| prometheus-mysqld-exporter-fips | affected | chainguard | prometheus-mysqld-exporter-fips | — |
| prometheus-node-exporter | affected | wolfi | prometheus-node-exporter | — |
| prometheus-node-exporter | affected | chainguard | prometheus-node-exporter | — |
| prometheus-node-exporter-1.4 | affected | chainguard | prometheus-node-exporter-1.4 | — |
| prometheus-node-exporter-1.5 | affected | chainguard | prometheus-node-exporter-1.5 | — |
| prometheus-node-exporter-fips | affected | chainguard | prometheus-node-exporter-fips | — |
| prometheus-operator | affected | chainguard | prometheus-operator | — |
| prometheus-operator | affected | wolfi | prometheus-operator | — |
| prometheus-operator-fips | affected | chainguard | prometheus-operator-fips | — |
| prometheus-podman-exporter | affected | wolfi | prometheus-podman-exporter | — |
| prometheus-podman-exporter | affected | chainguard | prometheus-podman-exporter | — |
| prometheus-postgres-exporter | affected | wolfi | prometheus-postgres-exporter | — |
| prometheus-postgres-exporter | affected | chainguard | prometheus-postgres-exporter | — |
| prometheus-postgres-exporter-0.10 | affected | chainguard | prometheus-postgres-exporter-0.10 | — |
| prometheus-postgres-exporter-fips | affected | chainguard | prometheus-postgres-exporter-fips | — |
| prometheus-pushgateway | affected | chainguard | prometheus-pushgateway | — |
| prometheus-pushgateway | affected | wolfi | prometheus-pushgateway | — |
| prometheus-pushgateway-1.4 | affected | chainguard | prometheus-pushgateway-1.4 | — |
| prometheus-pushgateway-fips | affected | chainguard | prometheus-pushgateway-fips | — |
| prometheus-pushgateway-fips-1.4 | affected | chainguard | prometheus-pushgateway-fips-1.4 | — |
| prometheus-stackdriver-exporter | affected | chainguard | prometheus-stackdriver-exporter | — |
| prometheus-stackdriver-exporter | affected | wolfi | prometheus-stackdriver-exporter | — |
| prometheus-statsd-exporter | affected | chainguard | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter | affected | wolfi | prometheus-statsd-exporter | — |
| prometheus-statsd-exporter-fips | affected | chainguard | prometheus-statsd-exporter-fips | — |
| promxy | affected | chainguard | promxy | — |
| promxy | affected | wolfi | promxy | — |
| promxy-fips | affected | chainguard | promxy-fips | — |
| pulumi | affected | wolfi | pulumi | — |
| pulumi | affected | chainguard | pulumi | — |
| pulumi-kubernetes-operator | affected | chainguard | pulumi-kubernetes-operator | — |
| pulumi-kubernetes-operator | affected | wolfi | pulumi-kubernetes-operator | — |
| rabbitmq-cluster-operator | affected | wolfi | rabbitmq-cluster-operator | — |
| rabbitmq-cluster-operator | affected | chainguard | rabbitmq-cluster-operator | — |
| rabbitmq-cluster-operator-fips | affected | chainguard | rabbitmq-cluster-operator-fips | — |
| rabbitmq-messaging-topology-operator | affected | wolfi | rabbitmq-messaging-topology-operator | — |
| rabbitmq-messaging-topology-operator | affected | chainguard | rabbitmq-messaging-topology-operator | — |
| rabbitmq-messaging-topology-operator-fips | affected | chainguard | rabbitmq-messaging-topology-operator-fips | — |
| rancher-2.8 | affected | chainguard | rancher-2.8 | — |
| rancher-2.8 | affected | wolfi | rancher-2.8 | — |
| rancher-agent-2.10 | affected | wolfi | rancher-agent-2.10 | — |
| rancher-agent-2.10 | affected | chainguard | rancher-agent-2.10 | — |
| rancher-agent-2.8 | affected | chainguard | rancher-agent-2.8 | — |
| rancher-agent-2.9 | affected | wolfi | rancher-agent-2.9 | — |
| rancher-agent-2.9 | affected | chainguard | rancher-agent-2.9 | — |
| rancher-fleet | affected | wolfi | rancher-fleet | — |
| rancher-fleet | affected | chainguard | rancher-fleet | — |
| rancher-webhook-0.4 | affected | chainguard | rancher-webhook-0.4 | — |
| rancher-webhook-0.5 | affected | wolfi | rancher-webhook-0.5 | — |
| rancher-webhook-0.5 | affected | chainguard | rancher-webhook-0.5 | — |
| rancher-webhook-0.6 | affected | chainguard | rancher-webhook-0.6 | — |
| rancher-webhook-0.6 | affected | wolfi | rancher-webhook-0.6 | — |
| rancher-webhook-fips-0.4 | affected | chainguard | rancher-webhook-fips-0.4 | — |
| rclone | affected | wolfi | rclone | — |
| rclone | affected | chainguard | rclone | — |
| rclone-fips | affected | chainguard | rclone-fips | — |
| redis-operator | affected | wolfi | redis-operator | — |
| redis-operator | affected | chainguard | redis-operator | — |
| redis-operator-fips | affected | chainguard | redis-operator-fips | — |
| rekor | affected | chainguard | rekor | — |
| rekor | affected | wolfi | rekor | — |
| rekor-fips | affected | chainguard | rekor-fips | — |
| request-1279 | affected | chainguard | request-1279 | — |
| request-1279-1-14 | affected | chainguard | request-1279-1-14 | — |
| restic | affected | wolfi | restic | — |
| restic | affected | chainguard | restic | — |
| restic-fips | affected | chainguard | restic-fips | — |
| rook | affected | wolfi | rook | — |
| rook | affected | chainguard | rook | — |
| sbomqs | affected | wolfi | sbomqs | — |
| sbomqs | affected | chainguard | sbomqs | — |
| scorecard | affected | chainguard | scorecard | — |
| scorecard | affected | wolfi | scorecard | — |
| seaweedfs | affected | chainguard | seaweedfs | — |
| seaweedfs | affected | wolfi | seaweedfs | — |
| secrets-store-csi-driver | affected | wolfi | secrets-store-csi-driver | — |
| secrets-store-csi-driver | affected | chainguard | secrets-store-csi-driver | — |
| secrets-store-csi-driver-fips | affected | chainguard | secrets-store-csi-driver-fips | — |
| secrets-store-csi-driver-provider-aws | affected | chainguard | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws | affected | wolfi | secrets-store-csi-driver-provider-aws | — |
| secrets-store-csi-driver-provider-aws-fips | affected | chainguard | secrets-store-csi-driver-provider-aws-fips | — |
| secrets-store-csi-driver-provider-gcp | affected | chainguard | secrets-store-csi-driver-provider-gcp | — |
| secrets-store-csi-driver-provider-gcp | affected | wolfi | secrets-store-csi-driver-provider-gcp | — |
| secrets-store-csi-driver-provider-gcp-fips | affected | chainguard | secrets-store-csi-driver-provider-gcp-fips | — |
| sigstore-scaffolding | affected | wolfi | sigstore-scaffolding | — |
| sigstore-scaffolding | affected | chainguard | sigstore-scaffolding | — |
| sigstore-scaffolding-fips | affected | chainguard | sigstore-scaffolding-fips | — |
| skaffold | affected | wolfi | skaffold | — |
| skaffold | affected | chainguard | skaffold | — |
| skopeo | affected | chainguard | skopeo | — |
| skopeo | affected | wolfi | skopeo | — |
| skopeo-fips | affected | chainguard | skopeo-fips | — |
| snyk-cli | affected | chainguard | snyk-cli | — |
| snyk-cli | affected | wolfi | snyk-cli | — |
| sonobuoy | affected | chainguard | sonobuoy | — |
| sonobuoy | affected | wolfi | sonobuoy | — |
| sops | affected | chainguard | sops | — |
| sops | affected | wolfi | sops | — |
| sops-fips | affected | chainguard | sops-fips | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spark-operator-fips | affected | chainguard | spark-operator-fips | — |
| spegel | affected | wolfi | spegel | — |
| spegel | affected | chainguard | spegel | — |
| spire-controller-manager | affected | chainguard | spire-controller-manager | — |
| spire-controller-manager | affected | wolfi | spire-controller-manager | — |
| spire-controller-manager-fips | affected | chainguard | spire-controller-manager-fips | — |
| spire-server | affected | wolfi | spire-server | — |
| spire-server | affected | chainguard | spire-server | — |
| spire-server-fips | affected | chainguard | spire-server-fips | — |
| splunk-otel-collector | affected | chainguard | splunk-otel-collector | — |
| splunk-otel-collector | affected | wolfi | splunk-otel-collector | — |
| splunk-otel-collector-fips | affected | chainguard | splunk-otel-collector-fips | — |
| sql_exporter | affected | chainguard | sql_exporter | — |
| sql_exporter | affected | wolfi | sql_exporter | — |
| src | affected | chainguard | src | — |
| src | affected | wolfi | src | — |
| src-fingerprint | affected | wolfi | src-fingerprint | — |
| src-fingerprint | affected | chainguard | src-fingerprint | — |
| src-fingerprint-fips | affected | chainguard | src-fingerprint-fips | — |
| sriov-network-device-plugin | affected | chainguard | sriov-network-device-plugin | — |
| sriov-network-device-plugin | affected | wolfi | sriov-network-device-plugin | — |
| sriov-network-device-plugin-fips | affected | chainguard | sriov-network-device-plugin-fips | — |
| stakater-reloader | affected | chainguard | stakater-reloader | — |
| stakater-reloader | affected | wolfi | stakater-reloader | — |
| stakater-reloader-0.0.119 | affected | chainguard | stakater-reloader-0.0.119 | — |
| stakater-reloader-0.0.128 | affected | chainguard | stakater-reloader-0.0.128 | — |
| stakater-reloader-fips | affected | chainguard | stakater-reloader-fips | — |
| step | affected | chainguard | step | — |
| step | affected | wolfi | step | — |
| step-ca | affected | chainguard | step-ca | — |
| step-ca | affected | wolfi | step-ca | — |
| step-ca-fips | affected | chainguard | step-ca-fips | — |
| step-fips | affected | chainguard | step-fips | — |
| step-issuer | affected | wolfi | step-issuer | — |
| step-issuer | affected | chainguard | step-issuer | — |
| step-issuer-fips | affected | chainguard | step-issuer-fips | — |
| step-kms-plugin | affected | wolfi | step-kms-plugin | — |
| step-kms-plugin | affected | chainguard | step-kms-plugin | — |
| step-kms-plugin-fips | affected | chainguard | step-kms-plugin-fips | — |
| stern | affected | chainguard | stern | — |
| stern | affected | wolfi | stern | — |
| tailscale | affected | chainguard | tailscale | — |
| tailscale | affected | wolfi | tailscale | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| tekton-pipelines | affected | wolfi | tekton-pipelines | — |
| tekton-pipelines | affected | chainguard | tekton-pipelines | — |
| tekton-pipelines-fips | affected | chainguard | tekton-pipelines-fips | — |
| telegraf-1.31 | affected | chainguard | telegraf-1.31 | — |
| telegraf-1.31 | affected | wolfi | telegraf-1.31 | — |
| telegraf-1.32 | affected | chainguard | telegraf-1.32 | — |
| telegraf-1.32 | affected | wolfi | telegraf-1.32 | — |
| telegraf-1.33 | affected | wolfi | telegraf-1.33 | — |
| telegraf-1.33 | affected | chainguard | telegraf-1.33 | — |
| telegraf-1.34 | affected | wolfi | telegraf-1.34 | — |
| telegraf-1.34 | affected | chainguard | telegraf-1.34 | — |
| tempo | affected | chainguard | tempo | — |
| tempo | affected | wolfi | tempo | — |
| tempo-fips | affected | chainguard | tempo-fips | — |
| temporal | affected | chainguard | temporal | — |
| temporal | affected | wolfi | temporal | — |
| temporal-fips | affected | chainguard | temporal-fips | — |
| temporal-server | affected | wolfi | temporal-server | — |
| temporal-server | affected | chainguard | temporal-server | — |
| temporal-server-fips | affected | chainguard | temporal-server-fips | — |
| temporal-ui-server | affected | wolfi | temporal-ui-server | — |
| temporal-ui-server | affected | chainguard | temporal-ui-server | — |
| temporal-ui-server-fips | affected | chainguard | temporal-ui-server-fips | — |
| terraform | affected | chainguard | terraform | — |
| terraform | affected | wolfi | terraform | — |
| terraform-1.10 | affected | chainguard | terraform-1.10 | — |
| terraform-1.8 | affected | chainguard | terraform-1.8 | — |
| terraform-1.9 | affected | chainguard | terraform-1.9 | — |
| terraform-fips-1.10 | affected | chainguard | terraform-fips-1.10 | — |
| terraform-fips-1.9 | affected | chainguard | terraform-fips-1.9 | — |
| terraform-provider-acme | affected | wolfi | terraform-provider-acme | — |
| terraform-provider-acme | affected | chainguard | terraform-provider-acme | — |
| terraform-provider-acme-fips | affected | chainguard | terraform-provider-acme-fips | — |
| terraform-provider-azuread | affected | chainguard | terraform-provider-azuread | — |
| terraform-provider-azuread | affected | wolfi | terraform-provider-azuread | — |
| terraform-provider-azuread-fips | affected | chainguard | terraform-provider-azuread-fips | — |
| terraform-provider-azurerm | affected | chainguard | terraform-provider-azurerm | — |
| terraform-provider-azurerm | affected | wolfi | terraform-provider-azurerm | — |
| terraform-provider-azurerm-fips | affected | chainguard | terraform-provider-azurerm-fips | — |
| terraform-provider-google | affected | wolfi | terraform-provider-google | — |
| terraform-provider-google | affected | chainguard | terraform-provider-google | — |
| terraform-provider-kubernetes | affected | wolfi | terraform-provider-kubernetes | — |
| terraform-provider-kubernetes | affected | chainguard | terraform-provider-kubernetes | — |
| terraform-provider-kubernetes-fips | affected | chainguard | terraform-provider-kubernetes-fips | — |
| terraform-provider-pagerduty | affected | wolfi | terraform-provider-pagerduty | — |
| terraform-provider-pagerduty | affected | chainguard | terraform-provider-pagerduty | — |
| terraform-provider-pagerduty-fips | affected | chainguard | terraform-provider-pagerduty-fips | — |
| terragrunt | affected | chainguard | terragrunt | — |
| terragrunt | affected | wolfi | terragrunt | — |
| tflint | affected | wolfi | tflint | — |
| tflint | affected | chainguard | tflint | — |
| tfsec | affected | chainguard | tfsec | — |
| tfsec | affected | wolfi | tfsec | — |
| thanos | affected | chainguard | thanos | — |
| thanos | affected | wolfi | thanos | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| thanos-operator | affected | chainguard | thanos-operator | — |
| thanos-operator | affected | wolfi | thanos-operator | — |
| thanos-operator-fips | affected | chainguard | thanos-operator-fips | — |
| tigera-operator-1.28 | affected | chainguard | tigera-operator-1.28 | — |
| tigera-operator-1.29 | affected | chainguard | tigera-operator-1.29 | — |
| tigera-operator-1.30 | affected | wolfi | tigera-operator-1.30 | — |
| tigera-operator-1.30 | affected | chainguard | tigera-operator-1.30 | — |
| tigera-operator-1.31 | affected | wolfi | tigera-operator-1.31 | — |
| tigera-operator-1.31 | affected | chainguard | tigera-operator-1.31 | — |
| tigera-operator-1.32 | affected | chainguard | tigera-operator-1.32 | — |
| tigera-operator-1.32 | affected | wolfi | tigera-operator-1.32 | — |
| tigera-operator-1.33 | affected | wolfi | tigera-operator-1.33 | — |
| tigera-operator-1.33 | affected | chainguard | tigera-operator-1.33 | — |
| tigera-operator-1.34 | affected | wolfi | tigera-operator-1.34 | — |
| tigera-operator-1.34 | affected | chainguard | tigera-operator-1.34 | — |
| tigera-operator-1.35 | affected | wolfi | tigera-operator-1.35 | — |
| tigera-operator-1.35 | affected | chainguard | tigera-operator-1.35 | — |
| tigera-operator-1.36 | affected | chainguard | tigera-operator-1.36 | — |
| tigera-operator-1.36 | affected | wolfi | tigera-operator-1.36 | — |
| tigera-operator-1.37 | affected | chainguard | tigera-operator-1.37 | — |
| tigera-operator-1.37 | affected | wolfi | tigera-operator-1.37 | — |
| tigera-operator-fips-1.29 | affected | chainguard | tigera-operator-fips-1.29 | — |
| tigera-operator-fips-1.30 | affected | chainguard | tigera-operator-fips-1.30 | — |
| tigera-operator-fips-1.31 | affected | chainguard | tigera-operator-fips-1.31 | — |
| tigera-operator-fips-1.32 | affected | chainguard | tigera-operator-fips-1.32 | — |
| tigera-operator-fips-1.33 | affected | chainguard | tigera-operator-fips-1.33 | — |
| tigera-operator-fips-1.34 | affected | chainguard | tigera-operator-fips-1.34 | — |
| tigera-operator-fips-1.35 | affected | chainguard | tigera-operator-fips-1.35 | — |
| tigera-operator-fips-1.36 | affected | chainguard | tigera-operator-fips-1.36 | — |
| tigera-operator-fips-1.37 | affected | chainguard | tigera-operator-fips-1.37 | — |
| timestamp-authority | affected | wolfi | timestamp-authority | — |
| timestamp-authority | affected | chainguard | timestamp-authority | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| timoni | affected | chainguard | timoni | — |
| timoni | affected | wolfi | timoni | — |
| tkn | affected | chainguard | tkn | — |
| tkn | affected | wolfi | tkn | — |
| tkn-fips | affected | chainguard | tkn-fips | — |
| traefik-2.11 | affected | chainguard | traefik-2.11 | — |
| traefik-3.1 | affected | chainguard | traefik-3.1 | — |
| traefik-3.1 | affected | wolfi | traefik-3.1 | — |
| traefik-3.2 | affected | chainguard | traefik-3.2 | — |
| traefik-3.2 | affected | wolfi | traefik-3.2 | — |
| traefik-3.3 | affected | chainguard | traefik-3.3 | — |
| traefik-3.3 | affected | wolfi | traefik-3.3 | — |
| traefik-fips-2.11 | affected | chainguard | traefik-fips-2.11 | — |
| traefik-fips-3.1 | affected | chainguard | traefik-fips-3.1 | — |
| traefik-fips-3.2 | affected | chainguard | traefik-fips-3.2 | — |
| traefik-fips-3.3 | affected | chainguard | traefik-fips-3.3 | — |
| trillian | affected | chainguard | trillian | — |
| trillian | affected | wolfi | trillian | — |
| trillian-fips | affected | chainguard | trillian-fips | — |
| trivy | affected | wolfi | trivy | — |
| trivy | affected | chainguard | trivy | — |
| trivy-fips | affected | chainguard | trivy-fips | — |
| trufflehog | affected | chainguard | trufflehog | — |
| trufflehog | affected | wolfi | trufflehog | — |
| trufflehog-fips | affected | chainguard | trufflehog-fips | — |
| trust-manager | affected | chainguard | trust-manager | — |
| trust-manager | affected | wolfi | trust-manager | — |
| trust-manager-fips | affected | chainguard | trust-manager-fips | — |
| tw | affected | chainguard | tw | — |
| tw | affected | wolfi | tw | — |
| vault-1.16 | affected | chainguard | vault-1.16 | — |
| vault-1.17 | affected | chainguard | vault-1.17 | — |
| vault-1.18 | affected | chainguard | vault-1.18 | — |
| vault-benchmark | affected | wolfi | vault-benchmark | — |
| vault-benchmark | affected | chainguard | vault-benchmark | — |
| vault-csi-provider | affected | wolfi | vault-csi-provider | — |
| vault-csi-provider | affected | chainguard | vault-csi-provider | — |
| vault-fips-1.17 | affected | chainguard | vault-fips-1.17 | — |
| vault-fips-1.18 | affected | chainguard | vault-fips-1.18 | — |
| vault-k8s-fips | affected | chainguard | vault-k8s-fips | — |
| vcluster | affected | wolfi | vcluster | — |
| vcluster | affected | chainguard | vcluster | — |
| velero | affected | wolfi | velero | — |
| velero | affected | chainguard | velero | — |
| velero-fips | affected | chainguard | velero-fips | — |
| velero-plugin-for-aws | affected | wolfi | velero-plugin-for-aws | — |
| velero-plugin-for-aws | affected | chainguard | velero-plugin-for-aws | — |
| velero-plugin-for-aws-fips | affected | chainguard | velero-plugin-for-aws-fips | — |
| velero-plugin-for-csi | affected | wolfi | velero-plugin-for-csi | — |
| velero-plugin-for-csi | affected | chainguard | velero-plugin-for-csi | — |
| velero-plugin-for-csi-fips | affected | chainguard | velero-plugin-for-csi-fips | — |
| velero-plugin-for-microsoft-azure | affected | chainguard | velero-plugin-for-microsoft-azure | — |
| velero-plugin-for-microsoft-azure | affected | wolfi | velero-plugin-for-microsoft-azure | — |
| velero-plugin-for-microsoft-azure-fips | affected | chainguard | velero-plugin-for-microsoft-azure-fips | — |
| vendir | affected | wolfi | vendir | — |
| vendir | affected | chainguard | vendir | — |
| vendir-fips | affected | chainguard | vendir-fips | — |
| vertical-pod-autoscaler | affected | wolfi | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler | affected | chainguard | vertical-pod-autoscaler | — |
| vertical-pod-autoscaler-fips | affected | chainguard | vertical-pod-autoscaler-fips | — |
| vexctl | affected | chainguard | vexctl | — |
| vexctl | affected | wolfi | vexctl | — |
| victoriametrics | affected | wolfi | victoriametrics | — |
| victoriametrics | affected | chainguard | victoriametrics | — |
| victoriametrics-cluster | affected | chainguard | victoriametrics-cluster | — |
| victoriametrics-cluster | affected | wolfi | victoriametrics-cluster | — |
| victoriametrics-cluster-fips | affected | chainguard | victoriametrics-cluster-fips | — |
| victoriametrics-fips | affected | chainguard | victoriametrics-fips | — |
| victoriametrics-operator | affected | wolfi | victoriametrics-operator | — |
| victoriametrics-operator | affected | chainguard | victoriametrics-operator | — |
| victoriametrics-operator-fips | affected | chainguard | victoriametrics-operator-fips | — |
| vitess-18 | affected | chainguard | vitess-18 | — |
| vitess-18.0 | affected | chainguard | vitess-18.0 | — |
| vitess-19 | affected | chainguard | vitess-19 | — |
| vitess-19.0 | affected | chainguard | vitess-19.0 | — |
| vitess-21.0 | affected | chainguard | vitess-21.0 | — |
| vitess-21.0 | affected | wolfi | vitess-21.0 | — |
| volume-modifier-for-k8s | affected | wolfi | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s | affected | chainguard | volume-modifier-for-k8s | — |
| volume-modifier-for-k8s-fips | affected | chainguard | volume-modifier-for-k8s-fips | — |
| wal-g | affected | wolfi | wal-g | — |
| wal-g | affected | chainguard | wal-g | — |
| wave | affected | chainguard | wave | — |
| wave | affected | wolfi | wave | — |
| wave-fips | affected | chainguard | wave-fips | — |
| wavefront-collector-for-kubernetes-1.12 | affected | chainguard | wavefront-collector-for-kubernetes-1.12 | — |
| wavefront-collector-for-kubernetes-1.13 | affected | chainguard | wavefront-collector-for-kubernetes-1.13 | — |
| weaviate | affected | wolfi | weaviate | — |
| weaviate | affected | chainguard | weaviate | — |
| wgcf | affected | wolfi | wgcf | — |
| wgcf | affected | chainguard | wgcf | — |
| whereabouts | affected | chainguard | whereabouts | — |
| whereabouts | affected | wolfi | whereabouts | — |
| whereabouts-fips | affected | chainguard | whereabouts-fips | — |
| x509-certificate-exporter | affected | wolfi | x509-certificate-exporter | — |
| x509-certificate-exporter | affected | chainguard | x509-certificate-exporter | — |
| x509-certificate-exporter-fips | affected | chainguard | x509-certificate-exporter-fips | — |
| xeol | affected | wolfi | xeol | — |
| xeol | affected | chainguard | xeol | — |
| xeol-fips | affected | chainguard | xeol-fips | — |
| x/oauth2 | affected | golang.org | golang.org/x/oauth2 | — |
| yunikorn-k8shim | affected | wolfi | yunikorn-k8shim | — |
| yunikorn-k8shim | affected | chainguard | yunikorn-k8shim | — |
| yunikorn-k8shim-fips | affected | chainguard | yunikorn-k8shim-fips | — |
| zarf | affected | chainguard | zarf | — |
| zarf | affected | wolfi | zarf | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| x/oauth2 | affected | golang.org | golang.org/x/oauth2 | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Red Hat Security Advisory: OpenShift Container Platform 4.18.20 packages and security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-tools | affected | Red Hat:openshift:4.18::el9 | cri-tools | — |
| cri-tools | affected | Red Hat:openshift:4.18::el8 | cri-tools | — |
| cri-tools-debuginfo | affected | Red Hat:openshift:4.18::el8 | cri-tools-debuginfo | — |
| cri-tools-debuginfo | affected | Red Hat:openshift:4.18::el9 | cri-tools-debuginfo | — |
| cri-tools-debugsource | affected | Red Hat:openshift:4.18::el8 | cri-tools-debugsource | — |
| cri-tools-debugsource | affected | Red Hat:openshift:4.18::el9 | cri-tools-debugsource | — |
| openshift | affected | Red Hat:openshift:4.18::el8 | openshift | — |
| openshift | affected | Red Hat:openshift:4.18::el9 | openshift | — |
| openshift-clients | affected | Red Hat:openshift:4.18::el9 | openshift-clients | — |
| openshift-clients | affected | Red Hat:openshift:4.18::el8 | openshift-clients | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.18::el8 | openshift-clients-redistributable | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.18::el9 | openshift-clients-redistributable | — |
| openshift-hyperkube | affected | Red Hat:openshift:4.18::el8 | openshift-hyperkube | — |
| openshift-hyperkube | affected | Red Hat:openshift:4.18::el9 | openshift-hyperkube | — |
| openshift-kube-apiserver | affected | Red Hat:openshift:4.18::el9 | openshift-kube-apiserver | — |
| openshift-kube-apiserver | affected | Red Hat:openshift:4.18::el8 | openshift-kube-apiserver | — |
| openshift-kube-controller-manager | affected | Red Hat:openshift:4.18::el8 | openshift-kube-controller-manager | — |
| openshift-kube-controller-manager | affected | Red Hat:openshift:4.18::el9 | openshift-kube-controller-manager | — |
| openshift-kubelet | affected | Red Hat:openshift:4.18::el8 | openshift-kubelet | — |
| openshift-kubelet | affected | Red Hat:openshift:4.18::el9 | openshift-kubelet | — |
| openshift-kube-scheduler | affected | Red Hat:openshift:4.18::el8 | openshift-kube-scheduler | — |
| openshift-kube-scheduler | affected | Red Hat:openshift:4.18::el9 | openshift-kube-scheduler | — |
| ose-aws-ecr-image-credential-provider | affected | Red Hat:openshift:4.18::el8 | ose-aws-ecr-image-credential-provider | — |
| ose-aws-ecr-image-credential-provider | affected | Red Hat:openshift:4.18::el9 | ose-aws-ecr-image-credential-provider | — |
| ose-azure-acr-image-credential-provider | affected | Red Hat:openshift:4.18::el9 | ose-azure-acr-image-credential-provider | — |
| ose-azure-acr-image-credential-provider | affected | Red Hat:openshift:4.18::el8 | ose-azure-acr-image-credential-provider | — |
| ose-gcp-gcr-image-credential-provider | affected | Red Hat:openshift:4.18::el8 | ose-gcp-gcr-image-credential-provider | — |
| ose-gcp-gcr-image-credential-provider | affected | Red Hat:openshift:4.18::el9 | ose-gcp-gcr-image-credential-provider | — |
Red Hat Security Advisory: OpenShift Container Platform 4.16.44 packages and security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cri-o | affected | Red Hat:openshift:4.16::el8 | cri-o | — |
| cri-o | affected | Red Hat:openshift:4.16::el9 | cri-o | — |
| cri-o-debuginfo | affected | Red Hat:openshift:4.16::el9 | cri-o-debuginfo | — |
| cri-o-debuginfo | affected | Red Hat:openshift:4.16::el8 | cri-o-debuginfo | — |
| cri-o-debugsource | affected | Red Hat:openshift:4.16::el9 | cri-o-debugsource | — |
| cri-o-debugsource | affected | Red Hat:openshift:4.16::el8 | cri-o-debugsource | — |
| cri-tools | affected | Red Hat:openshift:4.16::el8 | cri-tools | — |
| cri-tools | affected | Red Hat:openshift:4.16::el9 | cri-tools | — |
| cri-tools-debuginfo | affected | Red Hat:openshift:4.16::el8 | cri-tools-debuginfo | — |
| cri-tools-debuginfo | affected | Red Hat:openshift:4.16::el9 | cri-tools-debuginfo | — |
| cri-tools-debugsource | affected | Red Hat:openshift:4.16::el9 | cri-tools-debugsource | — |
| cri-tools-debugsource | affected | Red Hat:openshift:4.16::el8 | cri-tools-debugsource | — |
| openshift | affected | Red Hat:openshift:4.16::el8 | openshift | — |
| openshift | affected | Red Hat:openshift:4.16::el9 | openshift | — |
| openshift-clients | affected | Red Hat:openshift:4.16::el8 | openshift-clients | — |
| openshift-clients | affected | Red Hat:openshift:4.16::el9 | openshift-clients | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.16::el9 | openshift-clients-redistributable | — |
| openshift-clients-redistributable | affected | Red Hat:openshift:4.16::el8 | openshift-clients-redistributable | — |
| openshift-hyperkube | affected | Red Hat:openshift:4.16::el8 | openshift-hyperkube | — |
| openshift-hyperkube | affected | Red Hat:openshift:4.16::el9 | openshift-hyperkube | — |
| openshift-kube-apiserver | affected | Red Hat:openshift:4.16::el8 | openshift-kube-apiserver | — |
| openshift-kube-apiserver | affected | Red Hat:openshift:4.16::el9 | openshift-kube-apiserver | — |
| openshift-kube-controller-manager | affected | Red Hat:openshift:4.16::el8 | openshift-kube-controller-manager | — |
| openshift-kube-controller-manager | affected | Red Hat:openshift:4.16::el9 | openshift-kube-controller-manager | — |
| openshift-kubelet | affected | Red Hat:openshift:4.16::el9 | openshift-kubelet | — |
| openshift-kubelet | affected | Red Hat:openshift:4.16::el8 | openshift-kubelet | — |
| openshift-kube-scheduler | affected | Red Hat:openshift:4.16::el8 | openshift-kube-scheduler | — |
| openshift-kube-scheduler | affected | Red Hat:openshift:4.16::el9 | openshift-kube-scheduler | — |
| ose-aws-ecr-image-credential-provider | affected | Red Hat:openshift:4.16::el9 | ose-aws-ecr-image-credential-provider | — |
| ose-aws-ecr-image-credential-provider | affected | Red Hat:openshift:4.16::el8 | ose-aws-ecr-image-credential-provider | — |
| ose-azure-acr-image-credential-provider | affected | Red Hat:openshift:4.16::el8 | ose-azure-acr-image-credential-provider | — |
| ose-azure-acr-image-credential-provider | affected | Red Hat:openshift:4.16::el9 | ose-azure-acr-image-credential-provider | — |
| ose-gcp-gcr-image-credential-provider | affected | Red Hat:openshift:4.16::el9 | ose-gcp-gcr-image-credential-provider | — |
| ose-gcp-gcr-image-credential-provider | affected | Red Hat:openshift:4.16::el8 | ose-gcp-gcr-image-credential-provider | — |
| skopeo | affected | Red Hat:openshift:4.16::el8 | skopeo | — |
| skopeo | affected | Red Hat:openshift:4.16::el9 | skopeo | — |
| skopeo-debuginfo | affected | Red Hat:openshift:4.16::el9 | skopeo-debuginfo | — |
| skopeo-debugsource | affected | Red Hat:openshift:4.16::el9 | skopeo-debugsource | — |
| skopeo-tests | affected | Red Hat:openshift:4.16::el8 | skopeo-tests | — |
| skopeo-tests | affected | Red Hat:openshift:4.16::el9 | skopeo-tests | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:24.03-LTS-SP2 | golang | — |
Red Hat Security Advisory: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:8::appstream | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:8::appstream | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:8::appstream | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:8::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:8::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:8::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:8::appstream | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:8::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:8::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:8::appstream | go-toolset | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:9::appstream | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:9::appstream | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:9::appstream | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:9::appstream | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:9::appstream | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:9::appstream | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:9::appstream | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:9::appstream | go-toolset | — |
Red Hat Security Advisory: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Red Hat:enterprise_linux:10.0 | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:10.0 | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:10.0 | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:10.0 | golang-misc | — |
| golang-race | affected | Red Hat:enterprise_linux:10.0 | golang-race | — |
| golang-src | affected | Red Hat:enterprise_linux:10.0 | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:10.0 | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:10.0 | go-toolset | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | AlmaLinux:8 | delve | — |
| golang | affected | AlmaLinux:8 | golang | — |
| golang-bin | affected | AlmaLinux:8 | golang-bin | — |
| golang-docs | affected | AlmaLinux:8 | golang-docs | — |
| golang-misc | affected | AlmaLinux:8 | golang-misc | — |
| golang-src | affected | AlmaLinux:8 | golang-src | — |
| golang-tests | affected | AlmaLinux:8 | golang-tests | — |
| go-toolset | affected | AlmaLinux:8 | go-toolset | — |
Moderate: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | AlmaLinux:9 | golang | — |
| golang-bin | affected | AlmaLinux:9 | golang-bin | — |
| golang-docs | affected | AlmaLinux:9 | golang-docs | — |
| golang-misc | affected | AlmaLinux:9 | golang-misc | — |
| golang-race | affected | AlmaLinux:9 | golang-race | — |
| golang-src | affected | AlmaLinux:9 | golang-src | — |
| golang-tests | affected | AlmaLinux:9 | golang-tests | — |
| go-toolset | affected | AlmaLinux:9 | go-toolset | — |
Moderate: golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-docs | affected | AlmaLinux:10 | golang-docs | — |
| golang-misc | affected | AlmaLinux:10 | golang-misc | — |
| golang-src | affected | AlmaLinux:10 | golang-src | — |
| golang-tests | affected | AlmaLinux:10 | golang-tests | — |
golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | openEuler:24.03-LTS | golang | — |
| golang | affected | openEuler:24.03-LTS-SP1 | golang | — |
| golang | affected | openEuler:20.03-LTS-SP4 | golang | — |
| golang | affected | openEuler:22.03-LTS-SP3 | golang | — |
| golang | affected | openEuler:22.03-LTS-SP4 | golang | — |
Starlette has possible denial-of-service vector when parsing large files in multipart forms
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| airflow-3 | affected | chainguard | airflow-3 | — |
| airflow-3 | affected | wolfi | airflow-3 | — |
| airflow-core-3 | affected | chainguard | airflow-core-3 | — |
| k8s-sidecar | affected | wolfi | k8s-sidecar | — |
| k8s-sidecar | affected | chainguard | k8s-sidecar | — |
| kserve | affected | wolfi | kserve | — |
| kserve | affected | chainguard | kserve | — |
| mlflow | affected | chainguard | mlflow | — |
| mlflow | affected | wolfi | mlflow | — |
| nemo | affected | chainguard | nemo | — |
| open-webui | affected | chainguard | open-webui | — |
| open-webui | affected | wolfi | open-webui | — |
| py3.10-vllm-cuda-11.8 | affected | chainguard | py3.10-vllm-cuda-11.8 | — |
| reflex | affected | wolfi | reflex | — |
| reflex | affected | chainguard | reflex | — |
| starlette | affected | PyPI | starlette | — |
| starlette | affected | PyPI | starlette | — |
Starlette has possible denial-of-service vector when parsing large files in multipart forms
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| starlette | affected | PyPI | starlette | — |
Security update for kubernetes1.26
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.26 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.26 | — |
| kubernetes1.26 | affected | openSUSE:Leap 15.6 | kubernetes1.26 | — |
Security update for kubernetes1.25
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.25 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.25 | — |
| kubernetes1.25 | affected | openSUSE:Leap 15.6 | kubernetes1.25 | — |
Security update for kubernetes1.27
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.27 | affected | openSUSE:Leap 15.6 | kubernetes1.27 | — |
| kubernetes1.27 | affected | SUSE:Linux Enterprise Module for Containers 15 SP6 | kubernetes1.27 | — |
MINI-fm23-m3q7-qxm8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-5ghq-3fvh-m4p8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.23 | affected | MinimOS | istio-1.23 | — |
| istio-cni-1.23 | affected | MinimOS | istio-cni-1.23 | — |
| istio-cni-1.23-compat | affected | MinimOS | istio-cni-1.23-compat | — |
| istioctl-1.23 | affected | MinimOS | istioctl-1.23 | — |
| istioctl-bash-completion-1.23 | affected | MinimOS | istioctl-bash-completion-1.23 | — |
| istioctl-zsh-completion-1.23 | affected | MinimOS | istioctl-zsh-completion-1.23 | — |
| istio-install-cni-1.23 | affected | MinimOS | istio-install-cni-1.23 | — |
| istio-install-cni-1.23-compat | affected | MinimOS | istio-install-cni-1.23-compat | — |
| istio-pilot-agent-1.23 | affected | MinimOS | istio-pilot-agent-1.23 | — |
| istio-pilot-agent-1.23-compat | affected | MinimOS | istio-pilot-agent-1.23-compat | — |
| istio-pilot-discovery-1.23 | affected | MinimOS | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23-compat | affected | MinimOS | istio-pilot-discovery-1.23-compat | — |
kubernetes1.30-apiserver-1.30.14-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.30 | affected | openSUSE:Tumbleweed | kubernetes1.30 | — |
kubernetes1.31-apiserver-1.31.10-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.31 | affected | openSUSE:Tumbleweed | kubernetes1.31 | — |
kubernetes1.32-apiserver-1.32.6-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes1.32 | affected | openSUSE:Tumbleweed | kubernetes1.32 | — |
GHSA-wc8w-c4fg-hj36
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2025-7657
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-7657
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-7657
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2025-7657
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
MINI-3c7g-qv2h-835h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cerbos | affected | chainguard | cerbos | — |
| cerbos | affected | wolfi | cerbos | — |
| cerbos-fips | affected | chainguard | cerbos-fips | — |
| cert-manager-cmctl | affected | wolfi | cert-manager-cmctl | — |
| cert-manager-cmctl | affected | chainguard | cert-manager-cmctl | — |
| cert-manager-cmctl-fips | affected | chainguard | cert-manager-cmctl-fips | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| chartmuseum-fips | affected | chainguard | chartmuseum-fips | — |
| chart-testing | affected | chainguard | chart-testing | — |
| chart-testing | affected | wolfi | chart-testing | — |
| chart-testing-fips | affected | chainguard | chart-testing-fips | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cluster-api-helm-controller | affected | chainguard | cluster-api-helm-controller | — |
| cluster-api-helm-controller | affected | wolfi | cluster-api-helm-controller | — |
| cluster-api-helm-controller-fips | affected | chainguard | cluster-api-helm-controller-fips | — |
| consul-k8s-1.1 | affected | chainguard | consul-k8s-1.1 | — |
| consul-k8s-1.3 | affected | chainguard | consul-k8s-1.3 | — |
| consul-k8s-1.4 | affected | chainguard | consul-k8s-1.4 | — |
| consul-k8s-1.5 | affected | chainguard | consul-k8s-1.5 | — |
| consul-k8s-1.6 | affected | chainguard | consul-k8s-1.6 | — |
| consul-k8s-1.7 | affected | chainguard | consul-k8s-1.7 | — |
| consul-k8s-fips-1.1 | affected | chainguard | consul-k8s-fips-1.1 | — |
| consul-k8s-fips-1.3 | affected | chainguard | consul-k8s-fips-1.3 | — |
| consul-k8s-fips-1.4 | affected | chainguard | consul-k8s-fips-1.4 | — |
| consul-k8s-fips-1.5 | affected | chainguard | consul-k8s-fips-1.5 | — |
| consul-k8s-fips-1.6 | affected | chainguard | consul-k8s-fips-1.6 | — |
| consul-k8s-fips-1.7 | affected | chainguard | consul-k8s-fips-1.7 | — |
| eksctl | affected | wolfi | eksctl | — |
| eksctl | affected | chainguard | eksctl | — |
| envoy-gateway | affected | wolfi | envoy-gateway | — |
| envoy-gateway | affected | chainguard | envoy-gateway | — |
| envoy-gateway-fips | affected | chainguard | envoy-gateway-fips | — |
| flux-2.6 | affected | chainguard | flux-2.6 | — |
| flux-fips-2.5 | affected | chainguard | flux-fips-2.5 | — |
| flux-fips-2.6 | affected | chainguard | flux-fips-2.6 | — |
| flux-helm-controller | affected | wolfi | flux-helm-controller | — |
| flux-helm-controller | affected | chainguard | flux-helm-controller | — |
| flux-helm-controller-fips | affected | chainguard | flux-helm-controller-fips | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller-fips | affected | chainguard | flux-source-controller-fips | — |
| harbor-2.11 | affected | chainguard | harbor-2.11 | — |
| harbor-2.12 | affected | chainguard | harbor-2.12 | — |
| harbor-2.13 | affected | chainguard | harbor-2.13 | — |
| harbor-fips-2.11 | affected | chainguard | harbor-fips-2.11 | — |
| harbor-fips-2.12 | affected | chainguard | harbor-fips-2.12 | — |
| harbor-fips-2.13 | affected | chainguard | harbor-fips-2.13 | — |
| helm-docs | affected | chainguard | helm-docs | — |
| helm-docs | affected | wolfi | helm-docs | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-push | affected | chainguard | helm-push | — |
| helm-push | affected | wolfi | helm-push | — |
| helm/v3 | affected | helm.sh | helm.sh/helm/v3 | — |
| istio-1.25 | affected | wolfi | istio-1.25 | — |
| istio-1.25 | affected | chainguard | istio-1.25 | — |
| istio-1.26 | affected | chainguard | istio-1.26 | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8ssandra-client | affected | wolfi | k8ssandra-client | — |
| k8ssandra-client | affected | chainguard | k8ssandra-client | — |
| k8ssandra-client-fips | affected | chainguard | k8ssandra-client-fips | — |
| k9s | affected | chainguard | k9s | — |
| k9s | affected | wolfi | k9s | — |
| kargo | affected | wolfi | kargo | — |
| kargo | affected | chainguard | kargo | — |
| kots | affected | chainguard | kots | — |
| kots | affected | wolfi | kots | — |
| kuma-2.10 | affected | chainguard | kuma-2.10 | — |
| kuma-2.11 | affected | chainguard | kuma-2.11 | — |
| kuma-2.9 | affected | chainguard | kuma-2.9 | — |
| linkerd2 | affected | wolfi | linkerd2 | — |
| linkerd2 | affected | chainguard | linkerd2 | — |
| linkerd2-fips | affected | chainguard | linkerd2-fips | — |
| pluto | affected | wolfi | pluto | — |
| pluto | affected | chainguard | pluto | — |
| rancher-fleet | affected | chainguard | rancher-fleet | — |
| rancher-fleet | affected | wolfi | rancher-fleet | — |
| rancher-fleet-fips | affected | chainguard | rancher-fleet-fips | — |
| rancher-helm-3 | affected | chainguard | rancher-helm-3 | — |
| rancher-helm-3 | affected | wolfi | rancher-helm-3 | — |
| teleport-15 | affected | chainguard | teleport-15 | — |
| teleport-16 | affected | chainguard | teleport-16 | — |
| teleport-17 | affected | chainguard | teleport-17 | — |
| trivy | affected | wolfi | trivy | — |
| trivy | affected | chainguard | trivy | — |
| trivy-fips | affected | chainguard | trivy-fips | — |
| trivy-operator-fips | affected | chainguard | trivy-operator-fips | — |
| tw | affected | wolfi | tw | — |
| tw | affected | chainguard | tw | — |
| zarf | affected | wolfi | zarf | — |
| zarf | affected | chainguard | zarf | — |
| zot | affected | chainguard | zot | — |
| zot | affected | wolfi | zot | — |
MINI-q3rc-mw86-xqg6
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-jfhc-r34g-496x
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.23 | affected | MinimOS | istio-1.23 | — |
| istio-cni-1.23 | affected | MinimOS | istio-cni-1.23 | — |
| istio-cni-1.23-compat | affected | MinimOS | istio-cni-1.23-compat | — |
| istioctl-1.23 | affected | MinimOS | istioctl-1.23 | — |
| istioctl-bash-completion-1.23 | affected | MinimOS | istioctl-bash-completion-1.23 | — |
| istioctl-zsh-completion-1.23 | affected | MinimOS | istioctl-zsh-completion-1.23 | — |
| istio-install-cni-1.23 | affected | MinimOS | istio-install-cni-1.23 | — |
| istio-install-cni-1.23-compat | affected | MinimOS | istio-install-cni-1.23-compat | — |
| istio-pilot-agent-1.23 | affected | MinimOS | istio-pilot-agent-1.23 | — |
| istio-pilot-agent-1.23-compat | affected | MinimOS | istio-pilot-agent-1.23-compat | — |
| istio-pilot-discovery-1.23 | affected | MinimOS | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23-compat | affected | MinimOS | istio-pilot-discovery-1.23-compat | — |
MINI-j3gx-66j6-28r5
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.25 | affected | MinimOS | istio-1.25 | — |
| istio-cni-1.25 | affected | MinimOS | istio-cni-1.25 | — |
| istio-cni-1.25-compat | affected | MinimOS | istio-cni-1.25-compat | — |
| istioctl-1.25 | affected | MinimOS | istioctl-1.25 | — |
| istioctl-bash-completion-1.25 | affected | MinimOS | istioctl-bash-completion-1.25 | — |
| istioctl-zsh-completion-1.25 | affected | MinimOS | istioctl-zsh-completion-1.25 | — |
| istio-install-cni-1.25 | affected | MinimOS | istio-install-cni-1.25 | — |
| istio-install-cni-1.25-compat | affected | MinimOS | istio-install-cni-1.25-compat | — |
| istio-pilot-agent-1.25 | affected | MinimOS | istio-pilot-agent-1.25 | — |
| istio-pilot-agent-1.25-compat | affected | MinimOS | istio-pilot-agent-1.25-compat | — |
| istio-pilot-discovery-1.25 | affected | MinimOS | istio-pilot-discovery-1.25 | — |
| istio-pilot-discovery-1.25-compat | affected | MinimOS | istio-pilot-discovery-1.25-compat | — |
MINI-fjh2-m992-m6fx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.24 | affected | MinimOS | istio-1.24 | — |
| istio-cni-1.24 | affected | MinimOS | istio-cni-1.24 | — |
| istio-cni-1.24-compat | affected | MinimOS | istio-cni-1.24-compat | — |
| istioctl-1.24 | affected | MinimOS | istioctl-1.24 | — |
| istioctl-bash-completion-1.24 | affected | MinimOS | istioctl-bash-completion-1.24 | — |
| istioctl-zsh-completion-1.24 | affected | MinimOS | istioctl-zsh-completion-1.24 | — |
| istio-install-cni-1.24 | affected | MinimOS | istio-install-cni-1.24 | — |
| istio-install-cni-1.24-compat | affected | MinimOS | istio-install-cni-1.24-compat | — |
| istio-pilot-agent-1.24 | affected | MinimOS | istio-pilot-agent-1.24 | — |
| istio-pilot-agent-1.24-compat | affected | MinimOS | istio-pilot-agent-1.24-compat | — |
| istio-pilot-discovery-1.24 | affected | MinimOS | istio-pilot-discovery-1.24 | — |
| istio-pilot-discovery-1.24-compat | affected | MinimOS | istio-pilot-discovery-1.24-compat | — |
MINI-jggr-2452-8ffh
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.26 | affected | MinimOS | istio-1.26 | — |
| istio-cni-1.26 | affected | MinimOS | istio-cni-1.26 | — |
| istio-cni-1.26-compat | affected | MinimOS | istio-cni-1.26-compat | — |
| istioctl-1.26 | affected | MinimOS | istioctl-1.26 | — |
| istioctl-bash-completion-1.26 | affected | MinimOS | istioctl-bash-completion-1.26 | — |
| istioctl-zsh-completion-1.26 | affected | MinimOS | istioctl-zsh-completion-1.26 | — |
| istio-install-cni-1.26 | affected | MinimOS | istio-install-cni-1.26 | — |
| istio-install-cni-1.26-compat | affected | MinimOS | istio-install-cni-1.26-compat | — |
| istio-pilot-agent-1.26 | affected | MinimOS | istio-pilot-agent-1.26 | — |
| istio-pilot-agent-1.26-compat | affected | MinimOS | istio-pilot-agent-1.26-compat | — |
| istio-pilot-discovery-1.26 | affected | MinimOS | istio-pilot-discovery-1.26 | — |
| istio-pilot-discovery-1.26-compat | affected | MinimOS | istio-pilot-discovery-1.26-compat | — |
Helm vulnerable to Code Injection through malicious chart.yaml content
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| helm/v3 | affected | helm.sh | helm.sh/helm/v3 | — |
Helm vulnerable to Code Injection through malicious chart.yaml content
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cerbos | affected | wolfi | cerbos | — |
| cerbos | affected | chainguard | cerbos | — |
| cerbos-fips | affected | chainguard | cerbos-fips | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-cmctl | affected | wolfi | cert-manager-cmctl | — |
| cert-manager-cmctl | affected | chainguard | cert-manager-cmctl | — |
| cert-manager-cmctl-fips | affected | chainguard | cert-manager-cmctl-fips | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| chartmuseum | affected | wolfi | chartmuseum | — |
| chartmuseum | affected | chainguard | chartmuseum | — |
| chartmuseum-fips | affected | chainguard | chartmuseum-fips | — |
| chart-testing | affected | chainguard | chart-testing | — |
| chart-testing | affected | wolfi | chart-testing | — |
| chart-testing-fips | affected | chainguard | chart-testing-fips | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cloudbeat | affected | chainguard | cloudbeat | — |
| cloudbeat-fips | affected | chainguard | cloudbeat-fips | — |
| cluster-api-helm-controller | affected | chainguard | cluster-api-helm-controller | — |
| cluster-api-helm-controller | affected | wolfi | cluster-api-helm-controller | — |
| cluster-api-helm-controller-fips | affected | chainguard | cluster-api-helm-controller-fips | — |
| consul-k8s-1.1 | affected | chainguard | consul-k8s-1.1 | — |
| consul-k8s-1.3 | affected | chainguard | consul-k8s-1.3 | — |
| consul-k8s-1.4 | affected | chainguard | consul-k8s-1.4 | — |
| consul-k8s-1.5 | affected | chainguard | consul-k8s-1.5 | — |
| consul-k8s-1.5 | affected | wolfi | consul-k8s-1.5 | — |
| consul-k8s-1.6 | affected | wolfi | consul-k8s-1.6 | — |
| consul-k8s-1.6 | affected | chainguard | consul-k8s-1.6 | — |
| consul-k8s-1.7 | affected | wolfi | consul-k8s-1.7 | — |
| consul-k8s-1.7 | affected | chainguard | consul-k8s-1.7 | — |
| consul-k8s-fips-1.1 | affected | chainguard | consul-k8s-fips-1.1 | — |
| consul-k8s-fips-1.3 | affected | chainguard | consul-k8s-fips-1.3 | — |
| consul-k8s-fips-1.4 | affected | chainguard | consul-k8s-fips-1.4 | — |
| consul-k8s-fips-1.5 | affected | chainguard | consul-k8s-fips-1.5 | — |
| consul-k8s-fips-1.6 | affected | chainguard | consul-k8s-fips-1.6 | — |
| consul-k8s-fips-1.7 | affected | chainguard | consul-k8s-fips-1.7 | — |
| eksctl | affected | chainguard | eksctl | — |
| eksctl | affected | wolfi | eksctl | — |
| envoy-gateway | affected | wolfi | envoy-gateway | — |
| envoy-gateway | affected | chainguard | envoy-gateway | — |
| envoy-gateway-fips | affected | chainguard | envoy-gateway-fips | — |
| flux-2.6 | affected | chainguard | flux-2.6 | — |
| flux-2.6 | affected | wolfi | flux-2.6 | — |
| flux-fips | affected | chainguard | flux-fips | — |
| flux-fips-2.5 | affected | chainguard | flux-fips-2.5 | — |
| flux-fips-2.6 | affected | chainguard | flux-fips-2.6 | — |
| flux-helm-controller | affected | wolfi | flux-helm-controller | — |
| flux-helm-controller | affected | chainguard | flux-helm-controller | — |
| flux-helm-controller-fips | affected | chainguard | flux-helm-controller-fips | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller-fips | affected | chainguard | flux-source-controller-fips | — |
| harbor-2.10 | affected | chainguard | harbor-2.10 | — |
| harbor-2.10 | affected | wolfi | harbor-2.10 | — |
| harbor-2.11 | affected | chainguard | harbor-2.11 | — |
| harbor-2.11 | affected | wolfi | harbor-2.11 | — |
| harbor-2.12 | affected | wolfi | harbor-2.12 | — |
| harbor-2.12 | affected | chainguard | harbor-2.12 | — |
| harbor-2.13 | affected | wolfi | harbor-2.13 | — |
| harbor-2.13 | affected | chainguard | harbor-2.13 | — |
| harbor-fips-2.10 | affected | chainguard | harbor-fips-2.10 | — |
| harbor-fips-2.11 | affected | chainguard | harbor-fips-2.11 | — |
| harbor-fips-2.12 | affected | chainguard | harbor-fips-2.12 | — |
| harbor-fips-2.13 | affected | chainguard | harbor-fips-2.13 | — |
| helm-docs | affected | chainguard | helm-docs | — |
| helm-docs | affected | wolfi | helm-docs | — |
| helm-operator | affected | wolfi | helm-operator | — |
| helm-operator | affected | chainguard | helm-operator | — |
| helm-operator-fips | affected | chainguard | helm-operator-fips | — |
| helm-push | affected | wolfi | helm-push | — |
| helm-push | affected | chainguard | helm-push | — |
| helm/v3 | affected | helm.sh | helm.sh/helm/v3 | — |
| istio-1.23 | affected | chainguard | istio-1.23 | — |
| istio-1.23 | affected | wolfi | istio-1.23 | — |
| istio-1.24 | affected | chainguard | istio-1.24 | — |
| istio-1.24 | affected | wolfi | istio-1.24 | — |
| istio-1.25 | affected | chainguard | istio-1.25 | — |
| istio-1.25 | affected | wolfi | istio-1.25 | — |
| istio-1.26 | affected | chainguard | istio-1.26 | — |
| istio-1.26 | affected | wolfi | istio-1.26 | — |
| istio-cni-1.23 | affected | wolfi | istio-cni-1.23 | — |
| istio-cni-1.23 | affected | chainguard | istio-cni-1.23 | — |
| istio-fips-1.23 | affected | chainguard | istio-fips-1.23 | — |
| istio-pilot-discovery-1.23 | affected | wolfi | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23 | affected | chainguard | istio-pilot-discovery-1.23 | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8ssandra-client | affected | chainguard | k8ssandra-client | — |
| k8ssandra-client | affected | wolfi | k8ssandra-client | — |
| k8ssandra-client-fips | affected | chainguard | k8ssandra-client-fips | — |
| k9s | affected | chainguard | k9s | — |
| k9s | affected | wolfi | k9s | — |
| kargo | affected | wolfi | kargo | — |
| kargo | affected | chainguard | kargo | — |
| kots | affected | chainguard | kots | — |
| kots | affected | wolfi | kots | — |
| kots-compat | affected | chainguard | kots-compat | — |
| kuma-2.10 | affected | wolfi | kuma-2.10 | — |
| kuma-2.10 | affected | chainguard | kuma-2.10 | — |
| kuma-2.11 | affected | wolfi | kuma-2.11 | — |
| kuma-2.11 | affected | chainguard | kuma-2.11 | — |
| kuma-2.9 | affected | chainguard | kuma-2.9 | — |
| kuma-2.9 | affected | wolfi | kuma-2.9 | — |
| linkerd2 | affected | wolfi | linkerd2 | — |
| linkerd2 | affected | chainguard | linkerd2 | — |
| linkerd2-fips | affected | chainguard | linkerd2-fips | — |
| pluto | affected | chainguard | pluto | — |
| pluto | affected | wolfi | pluto | — |
| rancher-fleet | affected | chainguard | rancher-fleet | — |
| rancher-fleet | affected | wolfi | rancher-fleet | — |
| rancher-fleet-fips | affected | chainguard | rancher-fleet-fips | — |
| rancher-helm-3 | affected | chainguard | rancher-helm-3 | — |
| rancher-helm-3 | affected | wolfi | rancher-helm-3 | — |
| teleport-15 | affected | chainguard | teleport-15 | — |
| teleport-16 | affected | chainguard | teleport-16 | — |
| teleport-17 | affected | chainguard | teleport-17 | — |
| teleport-17 | affected | wolfi | teleport-17 | — |
| trivy | affected | chainguard | trivy | — |
| trivy | affected | wolfi | trivy | — |
| trivy-fips | affected | chainguard | trivy-fips | — |
| trivy-operator-fips | affected | chainguard | trivy-operator-fips | — |
| tw | affected | wolfi | tw | — |
| tw | affected | chainguard | tw | — |
| zarf | affected | wolfi | zarf | — |
| zarf | affected | chainguard | zarf | — |
| zot | affected | wolfi | zot | — |
| zot | affected | chainguard | zot | — |
MINI-gpr6-8f34-f834
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
Unexpected command execution in untrusted VCS repositories in cmd/go
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Bitnami | golang | — |
CVE-2025-4674 affecting package golang for versions less than 1.18.8-10
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
CVE-2025-4674 affecting package golang for versions less than 1.22.7-5
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Azure Linux:2 | golang | — |
DEBIAN-CVE-2025-4674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-1.15 | affected | Debian:11 | golang-1.15 | — |
| golang-1.19 | affected | Debian:12 | golang-1.19 | — |
| golang-1.24 | affected | Debian:13 | golang-1.24 | — |
Updated golang packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:9 | golang | — |
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but con...
CVEs:CVE-2025-4674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
CVEs:CVE-2025-4674
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.
CVEs:CVE-2025-4674
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Micro 6.0 | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Basesystem 15 SP7 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Development Tools 15 SP7 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Package Hub 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Python 3 15 SP6 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Python 3 15 SP7 | protobuf | — |
| protobuf | affected | openSUSE:Leap 15.6 | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Enterprise Micro 5.5 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP5 | protobuf | — |
Security update for protobuf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | SUSE:Linux Enterprise Micro 5.3 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Micro 5.4 | protobuf | — |
| protobuf | affected | SUSE:Linux Enterprise Module for Public Cloud 15 SP4 | protobuf | — |
| protobuf | affected | SUSE:Manager Server Module 4.3 | protobuf | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:24.03-LTS | protobuf | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:20.03-LTS-SP4 | protobuf | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:24.03-LTS-SP2 | protobuf | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:24.03-LTS-SP1 | protobuf | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:22.03-LTS-SP4 | protobuf | — |
protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openEuler:22.03-LTS-SP3 | protobuf | — |
libprotobuf-lite31_1_0-31.1-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | openSUSE:Tumbleweed | protobuf | — |
Fix CVE(s): CVE-2025-4516
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.6 | affected | TuxCare:Ubuntu:18.04 | idle-python3.6 | — |
| libpython3.6 | affected | TuxCare:Ubuntu:18.04 | libpython3.6 | — |
| libpython3.6-dev | affected | TuxCare:Ubuntu:18.04 | libpython3.6-dev | — |
| libpython3.6-minimal | affected | TuxCare:Ubuntu:18.04 | libpython3.6-minimal | — |
| libpython3.6-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython3.6-stdlib | — |
| libpython3.6-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython3.6-testsuite | — |
| python3.6 | affected | TuxCare:Ubuntu:18.04 | python3.6 | — |
| python3.6-dev | affected | TuxCare:Ubuntu:18.04 | python3.6-dev | — |
| python3.6-doc | affected | TuxCare:Ubuntu:18.04 | python3.6-doc | — |
| python3.6-examples | affected | TuxCare:Ubuntu:18.04 | python3.6-examples | — |
| python3.6-minimal | affected | TuxCare:Ubuntu:18.04 | python3.6-minimal | — |
| python3.6-venv | affected | TuxCare:Ubuntu:18.04 | python3.6-venv | — |
GCP-2025-041 (High)
MINI-3w5v-mhm4-8g58
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
Moby firewalld reload removes bridge network isolation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aactl | affected | chainguard | aactl | — |
| aactl | affected | wolfi | aactl | — |
| amazon-cloudwatch-agent-operator | affected | chainguard | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator | affected | wolfi | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator-fips | affected | chainguard | amazon-cloudwatch-agent-operator-fips | — |
| amazon-ecs-agent | affected | chainguard | amazon-ecs-agent | — |
| amazon-ecs-agent-fips | affected | chainguard | amazon-ecs-agent-fips | — |
| beats-8.18 | affected | chainguard | beats-8.18 | — |
| beats-9.0 | affected | chainguard | beats-9.0 | — |
| beats-fips-9.0 | affected | chainguard | beats-fips-9.0 | — |
| bento | affected | chainguard | bento | — |
| bento | affected | wolfi | bento | — |
| bom | affected | chainguard | bom | — |
| bom | affected | wolfi | bom | — |
| cert-manager-1.12 | affected | chainguard | cert-manager-1.12 | — |
| cert-manager-fips-1.12 | affected | chainguard | cert-manager-fips-1.12 | — |
| cluster-api-1.8 | affected | chainguard | cluster-api-1.8 | — |
| cluster-api-1.9 | affected | chainguard | cluster-api-1.9 | — |
| cluster-api-1.9 | affected | wolfi | cluster-api-1.9 | — |
| cluster-api-fips-1.8 | affected | chainguard | cluster-api-fips-1.8 | — |
| cluster-api-fips-1.9 | affected | chainguard | cluster-api-fips-1.9 | — |
| cluster-api-helm-controller | affected | wolfi | cluster-api-helm-controller | — |
| cluster-api-helm-controller | affected | chainguard | cluster-api-helm-controller | — |
| cluster-api-helm-controller-fips | affected | chainguard | cluster-api-helm-controller-fips | — |
| consul-k8s-fips-1.4 | affected | chainguard | consul-k8s-fips-1.4 | — |
| crossplane | affected | chainguard | crossplane | — |
| crossplane | affected | wolfi | crossplane | — |
| crossplane-fips | affected | chainguard | crossplane-fips | — |
| ctop | affected | chainguard | ctop | — |
| ctop | affected | wolfi | ctop | — |
| docker-credential-gcr | affected | chainguard | docker-credential-gcr | — |
| docker-credential-gcr | affected | wolfi | docker-credential-gcr | — |
| docker-credential-gcr-fips | affected | chainguard | docker-credential-gcr-fips | — |
| docker/docker | affected | github.com | github.com/docker/docker | — |
| falco | affected | wolfi | falco | — |
| falco | affected | chainguard | falco | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| falcoctl-fips-0.4 | affected | chainguard | falcoctl-fips-0.4 | — |
| gatekeeper-3.16 | affected | chainguard | gatekeeper-3.16 | — |
| gatekeeper-3.16 | affected | wolfi | gatekeeper-3.16 | — |
| gatekeeper-3.17 | affected | chainguard | gatekeeper-3.17 | — |
| gatekeeper-3.17 | affected | wolfi | gatekeeper-3.17 | — |
| gatekeeper-3.18 | affected | chainguard | gatekeeper-3.18 | — |
| gatekeeper-3.18 | affected | wolfi | gatekeeper-3.18 | — |
| gatekeeper-3.19 | affected | wolfi | gatekeeper-3.19 | — |
| gatekeeper-3.19 | affected | chainguard | gatekeeper-3.19 | — |
| gitlab-rails-ce-18.1 | affected | chainguard | gitlab-rails-ce-18.1 | — |
| gitlab-rails-ce-18.2 | affected | chainguard | gitlab-rails-ce-18.2 | — |
| gitlab-rails-ce-18.3 | affected | chainguard | gitlab-rails-ce-18.3 | — |
| gitlab-rails-ce-fips-18.1 | affected | chainguard | gitlab-rails-ce-fips-18.1 | — |
| gitlab-rails-ce-fips-18.2 | affected | chainguard | gitlab-rails-ce-fips-18.2 | — |
| gitlab-rails-ce-fips-18.3 | affected | chainguard | gitlab-rails-ce-fips-18.3 | — |
| gitlab-rails-ce-fips-18.4 | affected | chainguard | gitlab-rails-ce-fips-18.4 | — |
| gitlab-rails-ce-fips-18.5 | affected | chainguard | gitlab-rails-ce-fips-18.5 | — |
| gitlab-rails-ce-fips-18.6 | affected | chainguard | gitlab-rails-ce-fips-18.6 | — |
| gitlab-rails-ce-fips-18.7 | affected | chainguard | gitlab-rails-ce-fips-18.7 | — |
| gitlab-rails-ce-fips-18.8 | affected | chainguard | gitlab-rails-ce-fips-18.8 | — |
| gitlab-runner-fips-18.6 | affected | chainguard | gitlab-runner-fips-18.6 | — |
| harbor-2.11 | affected | chainguard | harbor-2.11 | — |
| harbor-2.11 | affected | wolfi | harbor-2.11 | — |
| harbor-fips-2.11 | affected | chainguard | harbor-fips-2.11 | — |
| harbor-scanner-trivy | affected | wolfi | harbor-scanner-trivy | — |
| harbor-scanner-trivy | affected | chainguard | harbor-scanner-trivy | — |
| harbor-scanner-trivy-fips | affected | chainguard | harbor-scanner-trivy-fips | — |
| harvester | affected | chainguard | harvester | — |
| harvester-fips | affected | chainguard | harvester-fips | — |
| helm-mapkubeapis | affected | chainguard | helm-mapkubeapis | — |
| helm-mapkubeapis | affected | wolfi | helm-mapkubeapis | — |
| helm-set-status | affected | wolfi | helm-set-status | — |
| helm-set-status | affected | chainguard | helm-set-status | — |
| istio-1.23 | affected | wolfi | istio-1.23 | — |
| istio-1.23 | affected | chainguard | istio-1.23 | — |
| istio-cni-1.23 | affected | chainguard | istio-cni-1.23 | — |
| istio-cni-1.23 | affected | wolfi | istio-cni-1.23 | — |
| istio-fips-1.23 | affected | chainguard | istio-fips-1.23 | — |
| istio-pilot-discovery-1.23 | affected | wolfi | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23 | affected | chainguard | istio-pilot-discovery-1.23 | — |
| k3d | affected | wolfi | k3d | — |
| k3d | affected | chainguard | k3d | — |
| k3s | affected | chainguard | k3s | — |
| k3s | affected | wolfi | k3s | — |
| k3s-1.31 | affected | chainguard | k3s-1.31 | — |
| k3s-1.32 | affected | wolfi | k3s-1.32 | — |
| k3s-1.32 | affected | chainguard | k3s-1.32 | — |
| k3s-1.33 | affected | chainguard | k3s-1.33 | — |
| k3s-1.33 | affected | wolfi | k3s-1.33 | — |
| k3s-1.34 | affected | chainguard | k3s-1.34 | — |
| k3s-1.34 | affected | wolfi | k3s-1.34 | — |
| k3s-1.35 | affected | wolfi | k3s-1.35 | — |
| k3s-1.35 | affected | chainguard | k3s-1.35 | — |
| knative-serving-1.16 | affected | chainguard | knative-serving-1.16 | — |
| knative-serving-1.16 | affected | wolfi | knative-serving-1.16 | — |
| knative-serving-fips-1.16 | affected | chainguard | knative-serving-fips-1.16 | — |
| kpt | affected | chainguard | kpt | — |
| kpt | affected | wolfi | kpt | — |
| kube-arangodb | affected | wolfi | kube-arangodb | — |
| kube-arangodb | affected | chainguard | kube-arangodb | — |
| kube-arangodb-fips | affected | chainguard | kube-arangodb-fips | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| kubevirt-cdi-uploadserver-1.5 | affected | chainguard | kubevirt-cdi-uploadserver-1.5 | — |
| kyverno-1.12 | affected | wolfi | kyverno-1.12 | — |
| kyverno-1.12 | affected | chainguard | kyverno-1.12 | — |
| kyverno-fips-1.11 | affected | chainguard | kyverno-fips-1.11 | — |
| kyverno-fips-1.12 | affected | chainguard | kyverno-fips-1.12 | — |
| lazydocker | affected | chainguard | lazydocker | — |
| lazydocker | affected | wolfi | lazydocker | — |
| neuvector-scanner-fips | affected | chainguard | neuvector-scanner-fips | — |
| newrelic-infrastructure-agent | affected | wolfi | newrelic-infrastructure-agent | — |
| newrelic-infrastructure-agent | affected | chainguard | newrelic-infrastructure-agent | — |
| openbao | affected | chainguard | openbao | — |
| openbao | affected | wolfi | openbao | — |
| openbao-fips | affected | chainguard | openbao-fips | — |
| opentelemetry-operator | affected | chainguard | opentelemetry-operator | — |
| opentelemetry-operator | affected | wolfi | opentelemetry-operator | — |
| opentelemetry-operator-fips | affected | chainguard | opentelemetry-operator-fips | — |
| portieris | affected | chainguard | portieris | — |
| portieris | affected | wolfi | portieris | — |
| portieris-fips | affected | chainguard | portieris-fips | — |
| prometheus-3.2 | affected | wolfi | prometheus-3.2 | — |
| prometheus-3.2 | affected | chainguard | prometheus-3.2 | — |
| prometheus-fips-3.2 | affected | chainguard | prometheus-fips-3.2 | — |
| promxy | affected | wolfi | promxy | — |
| promxy | affected | chainguard | promxy | — |
| promxy-fips | affected | chainguard | promxy-fips | — |
| rancher-2.12 | affected | chainguard | rancher-2.12 | — |
| rancher-2.12 | affected | wolfi | rancher-2.12 | — |
| rancher-agent-2.12 | affected | chainguard | rancher-agent-2.12 | — |
| rancher-agent-2.13 | affected | chainguard | rancher-agent-2.13 | — |
| rancher-agent-2.13 | affected | wolfi | rancher-agent-2.13 | — |
| rancher-machine | affected | wolfi | rancher-machine | — |
| rancher-machine | affected | chainguard | rancher-machine | — |
| redpanda-25.1 | affected | chainguard | redpanda-25.1 | — |
| rke2-runtime-1.33 | affected | chainguard | rke2-runtime-1.33 | — |
| rke2-runtime-1.34 | affected | chainguard | rke2-runtime-1.34 | — |
| rke2-runtime-1.35 | affected | chainguard | rke2-runtime-1.35 | — |
| rke2-runtime-1.36 | affected | chainguard | rke2-runtime-1.36 | — |
| skaffold | affected | chainguard | skaffold | — |
| skaffold | affected | wolfi | skaffold | — |
| skaffold-fips | affected | chainguard | skaffold-fips | — |
| tekton-pipelines-0.59 | affected | chainguard | tekton-pipelines-0.59 | — |
| tekton-pipelines-0.62 | affected | chainguard | tekton-pipelines-0.62 | — |
| tekton-pipelines-0.65 | affected | chainguard | tekton-pipelines-0.65 | — |
| tekton-pipelines-fips-0.59 | affected | chainguard | tekton-pipelines-fips-0.59 | — |
| tekton-pipelines-fips-0.62 | affected | chainguard | tekton-pipelines-fips-0.62 | — |
| tekton-pipelines-fips-0.65 | affected | chainguard | tekton-pipelines-fips-0.65 | — |
| telegraf-1.32 | affected | chainguard | telegraf-1.32 | — |
| telegraf-1.32 | affected | wolfi | telegraf-1.32 | — |
| telegraf-1.33 | affected | wolfi | telegraf-1.33 | — |
| telegraf-1.33 | affected | chainguard | telegraf-1.33 | — |
| traefik-2.11 | affected | chainguard | traefik-2.11 | — |
| traefik-3.5 | affected | chainguard | traefik-3.5 | — |
| traefik-3.5 | affected | wolfi | traefik-3.5 | — |
| traefik-fips-2.11 | affected | chainguard | traefik-fips-2.11 | — |
| traefik-fips-3.5 | affected | chainguard | traefik-fips-3.5 | — |
| undock | affected | chainguard | undock | — |
| undock | affected | wolfi | undock | — |
| vault-1.16 | affected | chainguard | vault-1.16 | — |
| vault-1.18 | affected | chainguard | vault-1.18 | — |
| vault-1.19 | affected | chainguard | vault-1.19 | — |
| vault-fips-1.18 | affected | chainguard | vault-fips-1.18 | — |
| vault-fips-1.19 | affected | chainguard | vault-fips-1.19 | — |
| xeol | affected | wolfi | xeol | — |
| xeol | affected | chainguard | xeol | — |
| xeol-fips | affected | chainguard | xeol-fips | — |
Moby firewalld reload removes bridge network isolation
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| docker/docker | affected | github.com | github.com/docker/docker | — |
GCP-2025-039 (High)
CVEs:CVE-2025-21003
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
CVEs:CVE-2025-21003
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
GHSA-x429-qrf9-h4p7
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-7656
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-7656
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-7656
DEBIAN-CVE-2025-7656
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
chromedriver-138.0.7204.168-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
GHSA-h5wm-mmc5-5pvc
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
GHSA-rc69-9q59-4f5f
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2025-8011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2025-8010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-8010
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-8010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-8010
CVEs:CVE-2025-8011
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-8011
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-8011
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| NVIDIA/gpu-operator | affected | github.com | github.com/NVIDIA/gpu-operator | — |
| NVIDIA/k8s-device-plugin | affected | github.com | github.com/NVIDIA/k8s-device-plugin | — |
| NVIDIA/mig-parted | affected | github.com | github.com/NVIDIA/mig-parted | — |
| NVIDIA/nvidia-container-toolkit | affected | github.com | github.com/NVIDIA/nvidia-container-toolkit | — |
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| NVIDIA/gpu-operator | affected | github.com | github.com/NVIDIA/gpu-operator | — |
| NVIDIA/k8s-device-plugin | affected | github.com | github.com/NVIDIA/k8s-device-plugin | — |
| NVIDIA/mig-parted | affected | github.com | github.com/NVIDIA/mig-parted | — |
| NVIDIA/nvidia-container-toolkit | affected | github.com | github.com/NVIDIA/nvidia-container-toolkit | — |
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data t...
CVEs:CVE-2025-23267
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
CVEs:CVE-2025-23267
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| NVIDIA/gpu-operator | affected | github.com | github.com/NVIDIA/gpu-operator | — |
| NVIDIA/k8s-device-plugin | affected | github.com | github.com/NVIDIA/k8s-device-plugin | — |
| NVIDIA/mig-parted | affected | github.com | github.com/NVIDIA/mig-parted | — |
| NVIDIA/nvidia-container-toolkit | affected | github.com | github.com/NVIDIA/nvidia-container-toolkit | — |
CVEs:CVE-2025-7327
The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, t...
CVEs:CVE-2025-7327
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| widget_for_google_reviews | affected | radiustheme | — | — |
Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| argo-cd-3.0 | affected | chainguard | argo-cd-3.0 | — |
| argo-cd-3.1 | affected | chainguard | argo-cd-3.1 | — |
| argo-cd-fips-3.0 | affected | chainguard | argo-cd-fips-3.0 | — |
| argo-cd-fips-3.1 | affected | chainguard | argo-cd-fips-3.1 | — |
| azuredisk-csi-1.32 | affected | chainguard | azuredisk-csi-1.32 | — |
| azuredisk-csi-1.33 | affected | chainguard | azuredisk-csi-1.33 | — |
| azuredisk-csi-fips-1.32 | affected | chainguard | azuredisk-csi-fips-1.32 | — |
| azuredisk-csi-fips-1.33 | affected | chainguard | azuredisk-csi-fips-1.33 | — |
| azurefile-csi-1.33 | affected | chainguard | azurefile-csi-1.33 | — |
| azurefile-csi-fips-1.32 | affected | chainguard | azurefile-csi-fips-1.32 | — |
| azurefile-csi-fips-1.33 | affected | chainguard | azurefile-csi-fips-1.33 | — |
| blob-csi-1.26 | affected | chainguard | blob-csi-1.26 | — |
| blob-csi-fips-1.26 | affected | chainguard | blob-csi-fips-1.26 | — |
| calico-3.30 | affected | chainguard | calico-3.30 | — |
| calico-fips-3.30 | affected | chainguard | calico-fips-3.30 | — |
| cloud-provider-gcp-cloud-controller-manager | affected | wolfi | cloud-provider-gcp-cloud-controller-manager | — |
| cloud-provider-gcp-cloud-controller-manager | affected | chainguard | cloud-provider-gcp-cloud-controller-manager | — |
| cloud-provider-gcp-cloud-controller-manager-fips | affected | chainguard | cloud-provider-gcp-cloud-controller-manager-fips | — |
| cluster-autoscaler-1.32 | affected | chainguard | cluster-autoscaler-1.32 | — |
| cluster-autoscaler-fips-1.32 | affected | chainguard | cluster-autoscaler-fips-1.32 | — |
| docker-machine-driver-harvester | affected | chainguard | docker-machine-driver-harvester | — |
| docker-machine-driver-harvester | affected | wolfi | docker-machine-driver-harvester | — |
| emissary | affected | chainguard | emissary | — |
| emissary | affected | wolfi | emissary | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-csi-driver-hostpath | affected | chainguard | kubernetes-csi-driver-hostpath | — |
| kubernetes-csi-driver-hostpath | affected | wolfi | kubernetes-csi-driver-hostpath | — |
| longhorn-share-manager-1.8 | affected | chainguard | longhorn-share-manager-1.8 | — |
| longhorn-share-manager-fips-1.8 | affected | chainguard | longhorn-share-manager-fips-1.8 | — |
| mesosphere-vsphere-csi | affected | chainguard | mesosphere-vsphere-csi | — |
| mesosphere-vsphere-csi | affected | wolfi | mesosphere-vsphere-csi | — |
| mesosphere-vsphere-csi-fips | affected | chainguard | mesosphere-vsphere-csi-fips | — |
| node-feature-discovery-0.17 | affected | chainguard | node-feature-discovery-0.17 | — |
| node-feature-discovery-fips-0.17 | affected | chainguard | node-feature-discovery-fips-0.17 | — |
| rancher-2.11 | affected | chainguard | rancher-2.11 | — |
| rancher-2.12 | affected | chainguard | rancher-2.12 | — |
| rancher-agent-2.11 | affected | chainguard | rancher-agent-2.11 | — |
| rancher-agent-2.12 | affected | chainguard | rancher-agent-2.12 | — |
| rancher-fleet | affected | chainguard | rancher-fleet | — |
| rancher-fleet | affected | wolfi | rancher-fleet | — |
| rancher-fleet-fips | affected | chainguard | rancher-fleet-fips | — |
| rancher-system-agent | affected | wolfi | rancher-system-agent | — |
| rancher-system-agent | affected | chainguard | rancher-system-agent | — |
| vcluster | affected | chainguard | vcluster | — |
| vcluster | affected | wolfi | vcluster | — |
| yunikorn-k8shim | affected | chainguard | yunikorn-k8shim | — |
| yunikorn-k8shim | affected | wolfi | yunikorn-k8shim | — |
| yunikorn-k8shim-fips | affected | chainguard | yunikorn-k8shim-fips | — |
MINI-jjvc-wp46-7hc6
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-5prw-63rm-cv3h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.23 | affected | MinimOS | istio-1.23 | — |
| istio-cni-1.23 | affected | MinimOS | istio-cni-1.23 | — |
| istio-cni-1.23-compat | affected | MinimOS | istio-cni-1.23-compat | — |
| istioctl-1.23 | affected | MinimOS | istioctl-1.23 | — |
| istioctl-bash-completion-1.23 | affected | MinimOS | istioctl-bash-completion-1.23 | — |
| istioctl-zsh-completion-1.23 | affected | MinimOS | istioctl-zsh-completion-1.23 | — |
| istio-install-cni-1.23 | affected | MinimOS | istio-install-cni-1.23 | — |
| istio-install-cni-1.23-compat | affected | MinimOS | istio-install-cni-1.23-compat | — |
| istio-pilot-agent-1.23 | affected | MinimOS | istio-pilot-agent-1.23 | — |
| istio-pilot-agent-1.23-compat | affected | MinimOS | istio-pilot-agent-1.23-compat | — |
| istio-pilot-discovery-1.23 | affected | MinimOS | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23-compat | affected | MinimOS | istio-pilot-discovery-1.23-compat | — |
MINI-62r6-r37h-h72r
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.25 | affected | MinimOS | istio-1.25 | — |
| istio-cni-1.25 | affected | MinimOS | istio-cni-1.25 | — |
| istio-cni-1.25-compat | affected | MinimOS | istio-cni-1.25-compat | — |
| istioctl-1.25 | affected | MinimOS | istioctl-1.25 | — |
| istioctl-bash-completion-1.25 | affected | MinimOS | istioctl-bash-completion-1.25 | — |
| istioctl-zsh-completion-1.25 | affected | MinimOS | istioctl-zsh-completion-1.25 | — |
| istio-install-cni-1.25 | affected | MinimOS | istio-install-cni-1.25 | — |
| istio-install-cni-1.25-compat | affected | MinimOS | istio-install-cni-1.25-compat | — |
| istio-pilot-agent-1.25 | affected | MinimOS | istio-pilot-agent-1.25 | — |
| istio-pilot-agent-1.25-compat | affected | MinimOS | istio-pilot-agent-1.25-compat | — |
| istio-pilot-discovery-1.25 | affected | MinimOS | istio-pilot-discovery-1.25 | — |
| istio-pilot-discovery-1.25-compat | affected | MinimOS | istio-pilot-discovery-1.25-compat | — |
MINI-fc44-qc2p-c8qp
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.24 | affected | MinimOS | istio-1.24 | — |
| istio-cni-1.24 | affected | MinimOS | istio-cni-1.24 | — |
| istio-cni-1.24-compat | affected | MinimOS | istio-cni-1.24-compat | — |
| istioctl-1.24 | affected | MinimOS | istioctl-1.24 | — |
| istioctl-bash-completion-1.24 | affected | MinimOS | istioctl-bash-completion-1.24 | — |
| istioctl-zsh-completion-1.24 | affected | MinimOS | istioctl-zsh-completion-1.24 | — |
| istio-install-cni-1.24 | affected | MinimOS | istio-install-cni-1.24 | — |
| istio-install-cni-1.24-compat | affected | MinimOS | istio-install-cni-1.24-compat | — |
| istio-pilot-agent-1.24 | affected | MinimOS | istio-pilot-agent-1.24 | — |
| istio-pilot-agent-1.24-compat | affected | MinimOS | istio-pilot-agent-1.24-compat | — |
| istio-pilot-discovery-1.24 | affected | MinimOS | istio-pilot-discovery-1.24 | — |
| istio-pilot-discovery-1.24-compat | affected | MinimOS | istio-pilot-discovery-1.24-compat | — |
MINI-gjx2-53mv-jp8g
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
MINI-4r93-hvxc-m458
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.23 | affected | MinimOS | istio-1.23 | — |
| istio-cni-1.23 | affected | MinimOS | istio-cni-1.23 | — |
| istio-cni-1.23-compat | affected | MinimOS | istio-cni-1.23-compat | — |
| istioctl-1.23 | affected | MinimOS | istioctl-1.23 | — |
| istioctl-bash-completion-1.23 | affected | MinimOS | istioctl-bash-completion-1.23 | — |
| istioctl-zsh-completion-1.23 | affected | MinimOS | istioctl-zsh-completion-1.23 | — |
| istio-install-cni-1.23 | affected | MinimOS | istio-install-cni-1.23 | — |
| istio-install-cni-1.23-compat | affected | MinimOS | istio-install-cni-1.23-compat | — |
| istio-pilot-agent-1.23 | affected | MinimOS | istio-pilot-agent-1.23 | — |
| istio-pilot-agent-1.23-compat | affected | MinimOS | istio-pilot-agent-1.23-compat | — |
| istio-pilot-discovery-1.23 | affected | MinimOS | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23-compat | affected | MinimOS | istio-pilot-discovery-1.23-compat | — |
MINI-3853-5m45-fc27
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.25 | affected | MinimOS | istio-1.25 | — |
| istio-cni-1.25 | affected | MinimOS | istio-cni-1.25 | — |
| istio-cni-1.25-compat | affected | MinimOS | istio-cni-1.25-compat | — |
| istioctl-1.25 | affected | MinimOS | istioctl-1.25 | — |
| istioctl-bash-completion-1.25 | affected | MinimOS | istioctl-bash-completion-1.25 | — |
| istioctl-zsh-completion-1.25 | affected | MinimOS | istioctl-zsh-completion-1.25 | — |
| istio-install-cni-1.25 | affected | MinimOS | istio-install-cni-1.25 | — |
| istio-install-cni-1.25-compat | affected | MinimOS | istio-install-cni-1.25-compat | — |
| istio-pilot-agent-1.25 | affected | MinimOS | istio-pilot-agent-1.25 | — |
| istio-pilot-agent-1.25-compat | affected | MinimOS | istio-pilot-agent-1.25-compat | — |
| istio-pilot-discovery-1.25 | affected | MinimOS | istio-pilot-discovery-1.25 | — |
| istio-pilot-discovery-1.25-compat | affected | MinimOS | istio-pilot-discovery-1.25-compat | — |
MINI-jh3w-g4fj-7x2g
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.24 | affected | MinimOS | istio-1.24 | — |
| istio-cni-1.24 | affected | MinimOS | istio-cni-1.24 | — |
| istio-cni-1.24-compat | affected | MinimOS | istio-cni-1.24-compat | — |
| istioctl-1.24 | affected | MinimOS | istioctl-1.24 | — |
| istioctl-bash-completion-1.24 | affected | MinimOS | istioctl-bash-completion-1.24 | — |
| istioctl-zsh-completion-1.24 | affected | MinimOS | istioctl-zsh-completion-1.24 | — |
| istio-install-cni-1.24 | affected | MinimOS | istio-install-cni-1.24 | — |
| istio-install-cni-1.24-compat | affected | MinimOS | istio-install-cni-1.24-compat | — |
| istio-pilot-agent-1.24 | affected | MinimOS | istio-pilot-agent-1.24 | — |
| istio-pilot-agent-1.24-compat | affected | MinimOS | istio-pilot-agent-1.24-compat | — |
| istio-pilot-discovery-1.24 | affected | MinimOS | istio-pilot-discovery-1.24 | — |
| istio-pilot-discovery-1.24-compat | affected | MinimOS | istio-pilot-discovery-1.24-compat | — |
GHSA-m59m-7wxv-85c8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2025-8292
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-8292
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-8292
CVEs:CVE-2025-8292
MINI-xvj6-qf8r-mvm5
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.23 | affected | MinimOS | istio-1.23 | — |
| istio-cni-1.23 | affected | MinimOS | istio-cni-1.23 | — |
| istio-cni-1.23-compat | affected | MinimOS | istio-cni-1.23-compat | — |
| istioctl-1.23 | affected | MinimOS | istioctl-1.23 | — |
| istioctl-bash-completion-1.23 | affected | MinimOS | istioctl-bash-completion-1.23 | — |
| istioctl-zsh-completion-1.23 | affected | MinimOS | istioctl-zsh-completion-1.23 | — |
| istio-install-cni-1.23 | affected | MinimOS | istio-install-cni-1.23 | — |
| istio-install-cni-1.23-compat | affected | MinimOS | istio-install-cni-1.23-compat | — |
| istio-pilot-agent-1.23 | affected | MinimOS | istio-pilot-agent-1.23 | — |
| istio-pilot-agent-1.23-compat | affected | MinimOS | istio-pilot-agent-1.23-compat | — |
| istio-pilot-discovery-1.23 | affected | MinimOS | istio-pilot-discovery-1.23 | — |
| istio-pilot-discovery-1.23-compat | affected | MinimOS | istio-pilot-discovery-1.23-compat | — |
MINI-fjph-7vr4-rgx6
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| istio-1.22 | affected | MinimOS | istio-1.22 | — |
| istio-cni-1.22 | affected | MinimOS | istio-cni-1.22 | — |
| istio-cni-1.22-compat | affected | MinimOS | istio-cni-1.22-compat | — |
| istioctl-1.22 | affected | MinimOS | istioctl-1.22 | — |
| istioctl-bash-completion-1.22 | affected | MinimOS | istioctl-bash-completion-1.22 | — |
| istioctl-zsh-completion-1.22 | affected | MinimOS | istioctl-zsh-completion-1.22 | — |
| istio-install-cni-1.22 | affected | MinimOS | istio-install-cni-1.22 | — |
| istio-install-cni-1.22-compat | affected | MinimOS | istio-install-cni-1.22-compat | — |
| istio-pilot-agent-1.22 | affected | MinimOS | istio-pilot-agent-1.22 | — |
| istio-pilot-agent-1.22-compat | affected | MinimOS | istio-pilot-agent-1.22-compat | — |
| istio-pilot-discovery-1.22 | affected | MinimOS | istio-pilot-discovery-1.22 | — |
| istio-pilot-discovery-1.22-compat | affected | MinimOS | istio-pilot-discovery-1.22-compat | — |
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aiohttp | affected | PyPI | aiohttp | — |
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| aiohttp | affected | PyPI | aiohttp | — |
| airflow-3 | affected | wolfi | airflow-3 | — |
| airflow-3 | affected | chainguard | airflow-3 | — |
| airflow-core-2 | affected | chainguard | airflow-core-2 | — |
| apache-beam-python-3.11-sdk | affected | chainguard | apache-beam-python-3.11-sdk | — |
| dask-kubernetes | affected | wolfi | dask-kubernetes | — |
| dask-kubernetes | affected | chainguard | dask-kubernetes | — |
| py3.10-vllm-cuda-11.8 | affected | chainguard | py3.10-vllm-cuda-11.8 | — |
| py3.13-scanner-test-libraries-aiohttp | affected | chainguard | py3.13-scanner-test-libraries-aiohttp | — |
| py3-cassandra-medusa | affected | chainguard | py3-cassandra-medusa | — |
| py3-cassandra-medusa | affected | wolfi | py3-cassandra-medusa | — |
| py3-vllm-cuda-12.4 | affected | chainguard | py3-vllm-cuda-12.4 | — |
| request-1276 | affected | chainguard | request-1276 | — |
| text-generation-inference | affected | chainguard | text-generation-inference | — |
CVEs:CVE-2025-8362
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag Manager allows Cross-Site Scripting (XSS).This issue affects GoogleTag Manager: from 0.0.0 before 1.10.0.
CVEs:CVE-2025-8362
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| googletag_manager | affected | googletag_manager_project | — | — |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extensi...
CVEs:CVE-2025-53489
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| googledocs4mw | affected | jackphoenix | — | — |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extension: from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
CVEs:CVE-2025-53489
CVEs:CVE-2025-53489
OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal in github.com/google/osv-scalibr
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google/osv-scalibr | affected | github.com | github.com/google/osv-scalibr | — |
CVEs:CVE-2025-20999
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
CVEs:CVE-2025-20999
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. T...
CVEs:CVE-2025-5924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| wp_firebase_push_notification | affected | skywavesolutions | — | — |
CVEs:CVE-2025-5924
CVEs:CVE-2025-20982
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
CVEs:CVE-2025-20982
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20983
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
CVEs:CVE-2025-20983
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-21006
Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
CVEs:CVE-2025-21006
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-32330
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional execut...
CVEs:CVE-2025-32330
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-21007
Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
CVEs:CVE-2025-21007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-21008
Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
CVEs:CVE-2025-21008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-21009
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
CVEs:CVE-2025-21009
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.
CVEs:CVE-2025-21005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-21005
Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
CVEs:CVE-2025-21000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-21000
CVEs:CVE-2025-21001
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
CVEs:CVE-2025-21001
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-21002
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
CVEs:CVE-2025-21002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2024-49714
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-49714
CVEs:CVE-2025-32325
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2025-32325
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-32331
In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVEs:CVE-2025-32331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User i...
CVEs:CVE-2025-26454
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26454
CVEs:CVE-2025-32321
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVEs:CVE-2025-32321
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-32326
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVEs:CVE-2025-32326
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
MINI-cvpq-75g3-7344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.33 | affected | MinimOS | kube-apiserver-1.33 | — |
| kube-apiserver-1.33-compat | affected | MinimOS | kube-apiserver-1.33-compat | — |
| kube-controller-manager-1.33 | affected | MinimOS | kube-controller-manager-1.33 | — |
| kube-controller-manager-1.33-compat | affected | MinimOS | kube-controller-manager-1.33-compat | — |
| kubectl-1.33 | affected | MinimOS | kubectl-1.33 | — |
| kubectl-1.33-advanced-compat | affected | MinimOS | kubectl-1.33-advanced-compat | — |
| kubectl-1.33-compat | affected | MinimOS | kubectl-1.33-compat | — |
| kube-proxy-1.33 | affected | MinimOS | kube-proxy-1.33 | — |
| kube-proxy-1.33-compat | affected | MinimOS | kube-proxy-1.33-compat | — |
| kubernetes-1.33 | affected | MinimOS | kubernetes-1.33 | — |
| kube-scheduler-1.33 | affected | MinimOS | kube-scheduler-1.33 | — |
| kube-scheduler-1.33-compat | affected | MinimOS | kube-scheduler-1.33-compat | — |
MINI-g6cw-q257-775p
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.33 | affected | MinimOS | kube-apiserver-1.33 | — |
| kube-apiserver-1.33-compat | affected | MinimOS | kube-apiserver-1.33-compat | — |
| kube-controller-manager-1.33 | affected | MinimOS | kube-controller-manager-1.33 | — |
| kube-controller-manager-1.33-compat | affected | MinimOS | kube-controller-manager-1.33-compat | — |
| kubectl-1.33 | affected | MinimOS | kubectl-1.33 | — |
| kubectl-1.33-advanced-compat | affected | MinimOS | kubectl-1.33-advanced-compat | — |
| kubectl-1.33-compat | affected | MinimOS | kubectl-1.33-compat | — |
| kube-proxy-1.33 | affected | MinimOS | kube-proxy-1.33 | — |
| kube-proxy-1.33-compat | affected | MinimOS | kube-proxy-1.33-compat | — |
| kubernetes-1.33 | affected | MinimOS | kubernetes-1.33 | — |
| kube-scheduler-1.33 | affected | MinimOS | kube-scheduler-1.33 | — |
| kube-scheduler-1.33-compat | affected | MinimOS | kube-scheduler-1.33-compat | — |
May leak sensitive information in logs when processing malformed data in github.com/go-viper/mapstructure
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| agentbeat | affected | chainguard | agentbeat | — |
| agentbeat-fips | affected | chainguard | agentbeat-fips | — |
| amazon-cloudwatch-agent | affected | chainguard | amazon-cloudwatch-agent | — |
| amazon-cloudwatch-agent | affected | wolfi | amazon-cloudwatch-agent | — |
| amazon-cloudwatch-agent-fips | affected | chainguard | amazon-cloudwatch-agent-fips | — |
| amazon-cloudwatch-agent-operator | affected | wolfi | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator | affected | chainguard | amazon-cloudwatch-agent-operator | — |
| amazon-cloudwatch-agent-operator-fips | affected | chainguard | amazon-cloudwatch-agent-operator-fips | — |
| argo-events | affected | wolfi | argo-events | — |
| argo-events | affected | chainguard | argo-events | — |
| argo-events-fips | affected | chainguard | argo-events-fips | — |
| argo-workflows | affected | wolfi | argo-workflows | — |
| argo-workflows | affected | chainguard | argo-workflows | — |
| argo-workflows-fips | affected | chainguard | argo-workflows-fips | — |
| atlantis | affected | chainguard | atlantis | — |
| atlantis | affected | wolfi | atlantis | — |
| atlantis-fips | affected | chainguard | atlantis-fips | — |
| aws-iam-authenticator-fips | affected | chainguard | aws-iam-authenticator-fips | — |
| aws-otel-collector | affected | wolfi | aws-otel-collector | — |
| aws-otel-collector | affected | chainguard | aws-otel-collector | — |
| aws-otel-collector-fips | affected | chainguard | aws-otel-collector-fips | — |
| boring-registry | affected | wolfi | boring-registry | — |
| boring-registry | affected | chainguard | boring-registry | — |
| boring-registry-fips | affected | chainguard | boring-registry-fips | — |
| calico-3.30 | affected | chainguard | calico-3.30 | — |
| calico-fips-3.30 | affected | chainguard | calico-fips-3.30 | — |
| cg | affected | chainguard | cg | — |
| chainctl | affected | chainguard | chainctl | — |
| chart-testing | affected | wolfi | chart-testing | — |
| chart-testing | affected | chainguard | chart-testing | — |
| chart-testing-fips | affected | chainguard | chart-testing-fips | — |
| cilium-cli | affected | chainguard | cilium-cli | — |
| cilium-cli | affected | wolfi | cilium-cli | — |
| cloud-sql-proxy-2.16 | affected | chainguard | cloud-sql-proxy-2.16 | — |
| cloud-sql-proxy-2.16 | affected | wolfi | cloud-sql-proxy-2.16 | — |
| cloud-sql-proxy-2.17 | affected | chainguard | cloud-sql-proxy-2.17 | — |
| cloud-sql-proxy-fips | affected | chainguard | cloud-sql-proxy-fips | — |
| cluster-api-1.10 | affected | chainguard | cluster-api-1.10 | — |
| conftest | affected | chainguard | conftest | — |
| conftest | affected | wolfi | conftest | — |
| conftest-fips | affected | chainguard | conftest-fips | — |
| cosign | affected | chainguard | cosign | — |
| cosign | affected | wolfi | cosign | — |
| cosign-fips | affected | chainguard | cosign-fips | — |
| crossplane | affected | chainguard | crossplane | — |
| crossplane | affected | wolfi | crossplane | — |
| dagger | affected | wolfi | dagger | — |
| dagger | affected | chainguard | dagger | — |
| dataplaneapi | affected | wolfi | dataplaneapi | — |
| dataplaneapi | affected | chainguard | dataplaneapi | — |
| dataplaneapi-fips | affected | chainguard | dataplaneapi-fips | — |
| dive | affected | wolfi | dive | — |
| dive | affected | chainguard | dive | — |
| docker-cli-buildx | affected | chainguard | docker-cli-buildx | — |
| docker-cli-buildx | affected | wolfi | docker-cli-buildx | — |
| docker-cli-buildx-fips | affected | chainguard | docker-cli-buildx-fips | — |
| docker-compose | affected | wolfi | docker-compose | — |
| docker-compose | affected | chainguard | docker-compose | — |
| docker-compose-fips | affected | chainguard | docker-compose-fips | — |
| elastic-agent | affected | chainguard | elastic-agent | — |
| envoy-gateway | affected | chainguard | envoy-gateway | — |
| envoy-gateway | affected | wolfi | envoy-gateway | — |
| envoy-gateway-fips | affected | chainguard | envoy-gateway-fips | — |
| falcoctl | affected | wolfi | falcoctl | — |
| falcoctl | affected | chainguard | falcoctl | — |
| falcoctl-fips | affected | chainguard | falcoctl-fips | — |
| filebrowser | affected | wolfi | filebrowser | — |
| filebrowser | affected | chainguard | filebrowser | — |
| flux-source-controller | affected | chainguard | flux-source-controller | — |
| flux-source-controller | affected | wolfi | flux-source-controller | — |
| flux-source-controller-fips | affected | chainguard | flux-source-controller-fips | — |
| fulcio-fips | affected | chainguard | fulcio-fips | — |
| gcsfuse | affected | chainguard | gcsfuse | — |
| gcsfuse | affected | wolfi | gcsfuse | — |
| gh | affected | wolfi | gh | — |
| gh | affected | chainguard | gh | — |
| github-mcp-server | affected | wolfi | github-mcp-server | — |
| github-mcp-server | affected | chainguard | github-mcp-server | — |
| gitlab-cng-18.1 | affected | chainguard | gitlab-cng-18.1 | — |
| gitlab-cng-fips-18.1 | affected | chainguard | gitlab-cng-fips-18.1 | — |
| glab | affected | wolfi | glab | — |
| glab | affected | chainguard | glab | — |
| glow | affected | chainguard | glow | — |
| glow | affected | wolfi | glow | — |
| golangci-lint | affected | wolfi | golangci-lint | — |
| golangci-lint | affected | chainguard | golangci-lint | — |
| goreleaser | affected | wolfi | goreleaser | — |
| goreleaser | affected | chainguard | goreleaser | — |
| go-viper/mapstructure | affected | github.com | github.com/go-viper/mapstructure | — |
| go-viper/mapstructure/v2 | affected | github.com | github.com/go-viper/mapstructure/v2 | — |
| grafana-11.3 | affected | chainguard | grafana-11.3 | — |
| grafana-11.4 | affected | chainguard | grafana-11.4 | — |
| grafana-11.5 | affected | chainguard | grafana-11.5 | — |
| grafana-11.6 | affected | chainguard | grafana-11.6 | — |
| grafana-12.0 | affected | chainguard | grafana-12.0 | — |
| grafana-alloy | affected | chainguard | grafana-alloy | — |
| grafana-alloy | affected | wolfi | grafana-alloy | — |
| grafana-alloy-fips | affected | chainguard | grafana-alloy-fips | — |
| grafana-fips-11.4 | affected | chainguard | grafana-fips-11.4 | — |
| grafana-fips-11.5 | affected | chainguard | grafana-fips-11.5 | — |
| grafana-fips-11.6 | affected | chainguard | grafana-fips-11.6 | — |
| grafana-fips-12.0 | affected | chainguard | grafana-fips-12.0 | — |
| grype | affected | wolfi | grype | — |
| grype | affected | chainguard | grype | — |
| grype-db | affected | chainguard | grype-db | — |
| grype-fips | affected | chainguard | grype-fips | — |
| guac | affected | chainguard | guac | — |
| guac | affected | wolfi | guac | — |
| harbor-cli | affected | chainguard | harbor-cli | — |
| harbor-cli | affected | wolfi | harbor-cli | — |
| hcloud | affected | chainguard | hcloud | — |
| hcloud | affected | wolfi | hcloud | — |
| istio-1.27 | affected | chainguard | istio-1.27 | — |
| istio-1.27 | affected | wolfi | istio-1.27 | — |
| istio-fips-1.27 | affected | chainguard | istio-fips-1.27 | — |
| jitsucom-bulker | affected | wolfi | jitsucom-bulker | — |
| jitsucom-bulker | affected | chainguard | jitsucom-bulker | — |
| k9s | affected | chainguard | k9s | — |
| k9s | affected | wolfi | k9s | — |
| ko | affected | wolfi | ko | — |
| ko | affected | chainguard | ko | — |
| ko-fips | affected | chainguard | ko-fips | — |
| kor | affected | chainguard | kor | — |
| kor | affected | wolfi | kor | — |
| kots | affected | wolfi | kots | — |
| kots | affected | chainguard | kots | — |
| kube-bench | affected | chainguard | kube-bench | — |
| kube-bench | affected | wolfi | kube-bench | — |
| kube-bench-fips | affected | chainguard | kube-bench-fips | — |
| kubecolor | affected | chainguard | kubecolor | — |
| kubecolor | affected | wolfi | kubecolor | — |
| kube-state-metrics-fips | affected | chainguard | kube-state-metrics-fips | — |
| kyverno-1.13 | affected | chainguard | kyverno-1.13 | — |
| kyverno-1.14 | affected | chainguard | kyverno-1.14 | — |
| kyverno-fips-1.13 | affected | chainguard | kyverno-fips-1.13 | — |
| kyverno-fips-1.14 | affected | chainguard | kyverno-fips-1.14 | — |
| kyverno-notation-aws | affected | wolfi | kyverno-notation-aws | — |
| kyverno-notation-aws | affected | chainguard | kyverno-notation-aws | — |
| kyverno-notation-aws-fips | affected | chainguard | kyverno-notation-aws-fips | — |
| kyverno-policy-reporter | affected | chainguard | kyverno-policy-reporter | — |
| kyverno-policy-reporter | affected | wolfi | kyverno-policy-reporter | — |
| kyverno-policy-reporter-fips | affected | chainguard | kyverno-policy-reporter-fips | — |
| kyverno-policy-reporter-ui | affected | wolfi | kyverno-policy-reporter-ui | — |
| kyverno-policy-reporter-ui | affected | chainguard | kyverno-policy-reporter-ui | — |
| kyverno-policy-reporter-ui-fips | affected | chainguard | kyverno-policy-reporter-ui-fips | — |
| mattermost-10.11 | affected | chainguard | mattermost-10.11 | — |
| mattermost-10.12 | affected | chainguard | mattermost-10.12 | — |
| mattermost-fips-10.10 | affected | chainguard | mattermost-fips-10.10 | — |
| mattermost-fips-10.11 | affected | chainguard | mattermost-fips-10.11 | — |
| mattermost-fips-10.12 | affected | chainguard | mattermost-fips-10.12 | — |
| mockery | affected | chainguard | mockery | — |
| mockery | affected | wolfi | mockery | — |
| nerdctl | affected | wolfi | nerdctl | — |
| nerdctl | affected | chainguard | nerdctl | — |
| nerdctl-fips | affected | chainguard | nerdctl-fips | — |
| neuvector-sigstore-interface | affected | chainguard | neuvector-sigstore-interface | — |
| neuvector-sigstore-interface | affected | wolfi | neuvector-sigstore-interface | — |
| neuvector-sigstore-interface-fips | affected | chainguard | neuvector-sigstore-interface-fips | — |
| nri-discovery-kubernetes | affected | wolfi | nri-discovery-kubernetes | — |
| nri-discovery-kubernetes | affected | chainguard | nri-discovery-kubernetes | — |
| nri-kubernetes | affected | chainguard | nri-kubernetes | — |
| nri-kubernetes | affected | wolfi | nri-kubernetes | — |
| nri-postgresql | affected | chainguard | nri-postgresql | — |
| nri-postgresql | affected | wolfi | nri-postgresql | — |
| nri-prometheus | affected | wolfi | nri-prometheus | — |
| nri-prometheus | affected | chainguard | nri-prometheus | — |
| opa | affected | wolfi | opa | — |
| opa | affected | chainguard | opa | — |
| opa-envoy | affected | chainguard | opa-envoy | — |
| opa-envoy | affected | wolfi | opa-envoy | — |
| opa-fips | affected | chainguard | opa-fips | — |
| opa-fips-envoy | affected | chainguard | opa-fips-envoy | — |
| openfga | affected | chainguard | openfga | — |
| openfga | affected | wolfi | openfga | — |
| openfga-fips | affected | chainguard | openfga-fips | — |
| opentelemetry-collector | affected | wolfi | opentelemetry-collector | — |
| opentelemetry-collector | affected | chainguard | opentelemetry-collector | — |
| opentelemetry-collector-contrib | affected | chainguard | opentelemetry-collector-contrib | — |
| opentelemetry-collector-contrib | affected | wolfi | opentelemetry-collector-contrib | — |
| opentelemetry-collector-contrib-fips | affected | chainguard | opentelemetry-collector-contrib-fips | — |
| opentelemetry-collector-fips | affected | chainguard | opentelemetry-collector-fips | — |
| opentelemetry-operator | affected | chainguard | opentelemetry-operator | — |
| opentelemetry-operator | affected | wolfi | opentelemetry-operator | — |
| opentelemetry-operator-fips | affected | chainguard | opentelemetry-operator-fips | — |
| opentofu-1.8 | affected | chainguard | opentofu-1.8 | — |
| opentofu-1.9 | affected | chainguard | opentofu-1.9 | — |
| opentofu-1.9 | affected | wolfi | opentofu-1.9 | — |
| opentofu-fips-1.10 | affected | chainguard | opentofu-fips-1.10 | — |
| opentofu-fips-1.8 | affected | chainguard | opentofu-fips-1.8 | — |
| opentofu-fips-1.9 | affected | chainguard | opentofu-fips-1.9 | — |
| pg_timetable | affected | chainguard | pg_timetable | — |
| pg_timetable | affected | wolfi | pg_timetable | — |
| pg_timetable-fips | affected | chainguard | pg_timetable-fips | — |
| pluto | affected | wolfi | pluto | — |
| pluto | affected | chainguard | pluto | — |
| podinfo | affected | chainguard | podinfo | — |
| podinfo | affected | wolfi | podinfo | — |
| policy-controller | affected | chainguard | policy-controller | — |
| policy-controller | affected | wolfi | policy-controller | — |
| policy-controller-fips | affected | chainguard | policy-controller-fips | — |
| prometheus-3.5 | affected | chainguard | prometheus-3.5 | — |
| prometheus-fips-3.5 | affected | chainguard | prometheus-fips-3.5 | — |
| seaweedfs | affected | chainguard | seaweedfs | — |
| seaweedfs | affected | wolfi | seaweedfs | — |
| spark-operator | affected | wolfi | spark-operator | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator-fips | affected | chainguard | spark-operator-fips | — |
| spire-server | affected | chainguard | spire-server | — |
| spire-server | affected | wolfi | spire-server | — |
| spire-server-fips | affected | chainguard | spire-server-fips | — |
| splunk-otel-collector | affected | wolfi | splunk-otel-collector | — |
| splunk-otel-collector | affected | chainguard | splunk-otel-collector | — |
| splunk-otel-collector-fips | affected | chainguard | splunk-otel-collector-fips | — |
| steampipe | affected | chainguard | steampipe | — |
| steampipe | affected | wolfi | steampipe | — |
| swagger | affected | chainguard | swagger | — |
| swagger | affected | wolfi | swagger | — |
| syft | affected | chainguard | syft | — |
| syft | affected | wolfi | syft | — |
| syft-fips | affected | chainguard | syft-fips | — |
| tekton-chains | affected | wolfi | tekton-chains | — |
| tekton-chains | affected | chainguard | tekton-chains | — |
| tekton-chains-fips | affected | chainguard | tekton-chains-fips | — |
| tempo | affected | wolfi | tempo | — |
| tempo | affected | chainguard | tempo | — |
| terraform-mcp-server | affected | chainguard | terraform-mcp-server | — |
| terraform-mcp-server | affected | wolfi | terraform-mcp-server | — |
| terraform-provider-acme | affected | wolfi | terraform-provider-acme | — |
| terraform-provider-acme | affected | chainguard | terraform-provider-acme | — |
| tflint | affected | wolfi | tflint | — |
| tflint | affected | chainguard | tflint | — |
| tfsec | affected | wolfi | tfsec | — |
| tfsec | affected | chainguard | tfsec | — |
| thanos | affected | chainguard | thanos | — |
| thanos | affected | wolfi | thanos | — |
| thanos-fips | affected | chainguard | thanos-fips | — |
| timestamp-authority | affected | wolfi | timestamp-authority | — |
| timestamp-authority | affected | chainguard | timestamp-authority | — |
| timestamp-authority-fips | affected | chainguard | timestamp-authority-fips | — |
| tkn | affected | chainguard | tkn | — |
| tkn | affected | wolfi | tkn | — |
| tkn-fips | affected | chainguard | tkn-fips | — |
| traefik-2.11 | affected | chainguard | traefik-2.11 | — |
| traefik-3.3 | affected | chainguard | traefik-3.3 | — |
| traefik-3.3 | affected | wolfi | traefik-3.3 | — |
| traefik-3.4 | affected | chainguard | traefik-3.4 | — |
| traefik-3.4 | affected | wolfi | traefik-3.4 | — |
| traefik-fips-2.11 | affected | chainguard | traefik-fips-2.11 | — |
| trivy | affected | chainguard | trivy | — |
| trivy | affected | wolfi | trivy | — |
| trivy-fips | affected | chainguard | trivy-fips | — |
| trivy-operator | affected | wolfi | trivy-operator | — |
| trivy-operator | affected | chainguard | trivy-operator | — |
| wgcf | affected | chainguard | wgcf | — |
| wgcf | affected | wolfi | wgcf | — |
| witness | affected | chainguard | witness | — |
| witness | affected | wolfi | witness | — |
| wolfictl | affected | wolfi | wolfictl | — |
| wolfictl | affected | chainguard | wolfictl | — |
| zarf | affected | chainguard | zarf | — |
| zarf | affected | wolfi | zarf | — |
Update of golang
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | TuxCare:AlmaLinux:9.2 | golang | — |
| golang-bin | affected | TuxCare:AlmaLinux:9.2 | golang-bin | — |
| golang-docs | affected | TuxCare:AlmaLinux:9.2 | golang-docs | — |
| golang-misc | affected | TuxCare:AlmaLinux:9.2 | golang-misc | — |
| golang-src | affected | TuxCare:AlmaLinux:9.2 | golang-src | — |
| golang-tests | affected | TuxCare:AlmaLinux:9.2 | golang-tests | — |
| go-toolset | affected | TuxCare:AlmaLinux:9.2 | go-toolset | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.