Google Security Advisories · September 2025 — Google Security Advisories
481 advisories 332 CVEs 17 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2025-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 17 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ECHO-56a6-a351-03e9

Open SourceExploitedCISA KEV listed2025-09-15

ECHO-56a6-a351-03e9

Affected products

ProductStatusVendorPackageEcosystem
grpc-1.59 affected Echo grpc-1.59
traefik affected Echo traefik
Upstream advisory

openSUSE-SU-2025:15578-1

Open SourceExploitedCISA KEV listed2025-09-26

chromedriver-140.0.7339.207-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

GHSA-hmrc-68hp-82x6

Open SourceExploitedCISA KEV listedHIGH2025-09-24

GHSA-hmrc-68hp-82x6

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-10585

Open SourceExploitedCISA KEV listedCRITICAL2025-09-24

DEBIAN-CVE-2025-10585

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-6004-1

Open SourceExploitedCISA KEV listed2025-09-19

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2025-10585

GoogleExploitedCISA KEV listedCRITICAL2025-09-17

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10585

Affected products

ProductStatusVendorPackageEcosystem
cadra affected siemens
chrome affected google
Upstream advisory

CVE-2025-10585

GoogleExploitedCISA KEV listed2025-09-17

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10585

Upstream advisory

CVE-2025-10585

Project ZeroExploitedCISA KEV listed2025-09-17

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10585

Upstream advisory

CVE-2025-21043

Project ZeroExploitedCISA KEV listed2025-09-02

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVEs:CVE-2025-21043

Upstream advisory

CVE-2025-21043

Open SourceExploitedCISA KEV listedCRITICAL2025-09-02

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVEs:CVE-2025-21043

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-425282960

GoogleExploitedCISA KEV listedHIGH2025-09-01

ASB-A-425282960

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2025-48543

Open SourceExploitedCISA KEV listedHIGH2025-09-02

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2025-48543

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48543

Project ZeroExploitedCISA KEV listed2025-09-02

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-48543

Upstream advisory

ASB-A-396331793

GoogleExploitedVulnCheck KEV listedHIGH2025-09-01

ASB-A-396331793

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

DSA-6010-1

Open SourceActive exploitation (sightings)2025-09-25

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

GHSA-87pp-93jj-9944

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

GHSA-87pp-93jj-9944

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-10891

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

DEBIAN-CVE-2025-10891

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10891

GoogleActive exploitation (sightings)CRITICAL2025-09-23

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10891

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-4p86-6c66-43q2

Open SourceActive exploitation (sightings)2025-09-08

MINI-4p86-6c66-43q2

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

MINI-m594-9cx4-3f3v

Open SourceActive exploitation (sightings)2025-09-08

MINI-m594-9cx4-3f3v

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.34 affected MinimOS kube-apiserver-fips-1.34
kube-apiserver-fips-1.34-compat affected MinimOS kube-apiserver-fips-1.34-compat
kube-controller-manager-fips-1.34 affected MinimOS kube-controller-manager-fips-1.34
kube-controller-manager-fips-1.34-compat affected MinimOS kube-controller-manager-fips-1.34-compat
kubectl-fips-1.34 affected MinimOS kubectl-fips-1.34
kubectl-fips-1.34-compat affected MinimOS kubectl-fips-1.34-compat
kube-proxy-fips-1.34 affected MinimOS kube-proxy-fips-1.34
kube-proxy-fips-1.34-compat affected MinimOS kube-proxy-fips-1.34-compat
kubernetes-fips-1.34 affected MinimOS kubernetes-fips-1.34
kube-scheduler-fips-1.34 affected MinimOS kube-scheduler-fips-1.34
kube-scheduler-fips-1.34-compat affected MinimOS kube-scheduler-fips-1.34-compat
Upstream advisory

MINI-3256-rwg7-g8xr

Open SourceActive exploitation (sightings)2025-09-08

MINI-3256-rwg7-g8xr

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

MINI-2v84-775m-2c3g

Open SourceActive exploitation (sightings)2025-09-08

MINI-2v84-775m-2c3g

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.33 affected MinimOS kube-apiserver-fips-1.33
kube-apiserver-fips-1.33-compat affected MinimOS kube-apiserver-fips-1.33-compat
kube-controller-manager-fips-1.33 affected MinimOS kube-controller-manager-fips-1.33
kube-controller-manager-fips-1.33-compat affected MinimOS kube-controller-manager-fips-1.33-compat
kubectl-fips-1.33 affected MinimOS kubectl-fips-1.33
kubectl-fips-1.33-compat affected MinimOS kubectl-fips-1.33-compat
kubelet-fips-1.33 affected MinimOS kubelet-fips-1.33
kubelet-fips-1.33-compat affected MinimOS kubelet-fips-1.33-compat
kube-proxy-fips-1.33 affected MinimOS kube-proxy-fips-1.33
kube-proxy-fips-1.33-compat affected MinimOS kube-proxy-fips-1.33-compat
kubernetes-fips-1.33 affected MinimOS kubernetes-fips-1.33
kube-scheduler-fips-1.33 affected MinimOS kube-scheduler-fips-1.33
kube-scheduler-fips-1.33-compat affected MinimOS kube-scheduler-fips-1.33-compat
Upstream advisory

MINI-2hj8-5mrc-xh8c

Open SourceActive exploitation (sightings)2025-09-04

MINI-2hj8-5mrc-xh8c

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.34 affected MinimOS kube-apiserver-1.34
kube-apiserver-1.34-compat affected MinimOS kube-apiserver-1.34-compat
kube-controller-manager-1.34 affected MinimOS kube-controller-manager-1.34
kube-controller-manager-1.34-compat affected MinimOS kube-controller-manager-1.34-compat
kubectl-1.34 affected MinimOS kubectl-1.34
kubectl-1.34-advanced-compat affected MinimOS kubectl-1.34-advanced-compat
kubectl-1.34-compat affected MinimOS kubectl-1.34-compat
kube-proxy-1.34 affected MinimOS kube-proxy-1.34
kube-proxy-1.34-compat affected MinimOS kube-proxy-1.34-compat
kubernetes-1.34 affected MinimOS kubernetes-1.34
kube-scheduler-1.34 affected MinimOS kube-scheduler-1.34
kube-scheduler-1.34-compat affected MinimOS kube-scheduler-1.34-compat
Upstream advisory

RHBA-2025:15712

Open SourceActive exploitation (sightings)HIGH2025-09-17

Red Hat Bug Fix Advisory: OpenShift Container Platform 4.18.24 packages update

Affected products

ProductStatusVendorPackageEcosystem
bpftool affected Red Hat:openshift:4.18::el9 bpftool
bpftool-debuginfo affected Red Hat:openshift:4.18::el9 bpftool-debuginfo
container-selinux affected Red Hat:openshift:4.18::el9 container-selinux
cri-o affected Red Hat:openshift:4.18::el9 cri-o
cri-o affected Red Hat:openshift:4.18::el8 cri-o
cri-o-debuginfo affected Red Hat:openshift:4.18::el8 cri-o-debuginfo
cri-o-debuginfo affected Red Hat:openshift:4.18::el9 cri-o-debuginfo
cri-o-debugsource affected Red Hat:openshift:4.18::el8 cri-o-debugsource
cri-o-debugsource affected Red Hat:openshift:4.18::el9 cri-o-debugsource
kernel affected Red Hat:openshift:4.18::el9 kernel
kernel-64k affected Red Hat:openshift:4.18::el9 kernel-64k
kernel-64k-core affected Red Hat:openshift:4.18::el9 kernel-64k-core
kernel-64k-debug affected Red Hat:openshift:4.18::el9 kernel-64k-debug
kernel-64k-debug-core affected Red Hat:openshift:4.18::el9 kernel-64k-debug-core
kernel-64k-debug-debuginfo affected Red Hat:openshift:4.18::el9 kernel-64k-debug-debuginfo
kernel-64k-debug-devel affected Red Hat:openshift:4.18::el9 kernel-64k-debug-devel
kernel-64k-debug-devel-matched affected Red Hat:openshift:4.18::el9 kernel-64k-debug-devel-matched
kernel-64k-debuginfo affected Red Hat:openshift:4.18::el9 kernel-64k-debuginfo
kernel-64k-debug-modules affected Red Hat:openshift:4.18::el9 kernel-64k-debug-modules
kernel-64k-debug-modules-core affected Red Hat:openshift:4.18::el9 kernel-64k-debug-modules-core
kernel-64k-debug-modules-extra affected Red Hat:openshift:4.18::el9 kernel-64k-debug-modules-extra
kernel-64k-debug-modules-internal affected Red Hat:openshift:4.18::el9 kernel-64k-debug-modules-internal
kernel-64k-debug-modules-partner affected Red Hat:openshift:4.18::el9 kernel-64k-debug-modules-partner
kernel-64k-devel affected Red Hat:openshift:4.18::el9 kernel-64k-devel
kernel-64k-devel-matched affected Red Hat:openshift:4.18::el9 kernel-64k-devel-matched
kernel-64k-modules affected Red Hat:openshift:4.18::el9 kernel-64k-modules
kernel-64k-modules-core affected Red Hat:openshift:4.18::el9 kernel-64k-modules-core
kernel-64k-modules-extra affected Red Hat:openshift:4.18::el9 kernel-64k-modules-extra
kernel-64k-modules-internal affected Red Hat:openshift:4.18::el9 kernel-64k-modules-internal
kernel-64k-modules-partner affected Red Hat:openshift:4.18::el9 kernel-64k-modules-partner
kernel-abi-stablelists affected Red Hat:openshift:4.18::el9 kernel-abi-stablelists
kernel-core affected Red Hat:openshift:4.18::el9 kernel-core
kernel-debug affected Red Hat:openshift:4.18::el9 kernel-debug
kernel-debug-core affected Red Hat:openshift:4.18::el9 kernel-debug-core
kernel-debug-debuginfo affected Red Hat:openshift:4.18::el9 kernel-debug-debuginfo
kernel-debug-devel affected Red Hat:openshift:4.18::el9 kernel-debug-devel
kernel-debug-devel-matched affected Red Hat:openshift:4.18::el9 kernel-debug-devel-matched
kernel-debuginfo affected Red Hat:openshift:4.18::el9 kernel-debuginfo
kernel-debuginfo-common-aarch64 affected Red Hat:openshift:4.18::el9 kernel-debuginfo-common-aarch64
kernel-debuginfo-common-ppc64le affected Red Hat:openshift:4.18::el9 kernel-debuginfo-common-ppc64le
kernel-debuginfo-common-s390x affected Red Hat:openshift:4.18::el9 kernel-debuginfo-common-s390x
kernel-debuginfo-common-x86_64 affected Red Hat:openshift:4.18::el9 kernel-debuginfo-common-x86_64
kernel-debug-modules affected Red Hat:openshift:4.18::el9 kernel-debug-modules
kernel-debug-modules-core affected Red Hat:openshift:4.18::el9 kernel-debug-modules-core
kernel-debug-modules-extra affected Red Hat:openshift:4.18::el9 kernel-debug-modules-extra
kernel-debug-modules-internal affected Red Hat:openshift:4.18::el9 kernel-debug-modules-internal
kernel-debug-modules-partner affected Red Hat:openshift:4.18::el9 kernel-debug-modules-partner
kernel-debug-uki-virt affected Red Hat:openshift:4.18::el9 kernel-debug-uki-virt
kernel-devel affected Red Hat:openshift:4.18::el9 kernel-devel
kernel-devel-matched affected Red Hat:openshift:4.18::el9 kernel-devel-matched
kernel-doc affected Red Hat:openshift:4.18::el9 kernel-doc
kernel-ipaclones-internal affected Red Hat:openshift:4.18::el9 kernel-ipaclones-internal
kernel-modules affected Red Hat:openshift:4.18::el9 kernel-modules
kernel-modules-core affected Red Hat:openshift:4.18::el9 kernel-modules-core
kernel-modules-extra affected Red Hat:openshift:4.18::el9 kernel-modules-extra
kernel-modules-internal affected Red Hat:openshift:4.18::el9 kernel-modules-internal
kernel-modules-partner affected Red Hat:openshift:4.18::el9 kernel-modules-partner
kernel-rt affected Red Hat:openshift:4.18::el9 kernel-rt
kernel-rt-core affected Red Hat:openshift:4.18::el9 kernel-rt-core
kernel-rt-debug affected Red Hat:openshift:4.18::el9 kernel-rt-debug
kernel-rt-debug-core affected Red Hat:openshift:4.18::el9 kernel-rt-debug-core
kernel-rt-debug-debuginfo affected Red Hat:openshift:4.18::el9 kernel-rt-debug-debuginfo
kernel-rt-debug-devel affected Red Hat:openshift:4.18::el9 kernel-rt-debug-devel
kernel-rt-debug-devel-matched affected Red Hat:openshift:4.18::el9 kernel-rt-debug-devel-matched
kernel-rt-debuginfo affected Red Hat:openshift:4.18::el9 kernel-rt-debuginfo
kernel-rt-debug-kvm affected Red Hat:openshift:4.18::el9 kernel-rt-debug-kvm
kernel-rt-debug-modules affected Red Hat:openshift:4.18::el9 kernel-rt-debug-modules
kernel-rt-debug-modules-core affected Red Hat:openshift:4.18::el9 kernel-rt-debug-modules-core
kernel-rt-debug-modules-extra affected Red Hat:openshift:4.18::el9 kernel-rt-debug-modules-extra
kernel-rt-debug-modules-internal affected Red Hat:openshift:4.18::el9 kernel-rt-debug-modules-internal
kernel-rt-debug-modules-partner affected Red Hat:openshift:4.18::el9 kernel-rt-debug-modules-partner
kernel-rt-devel affected Red Hat:openshift:4.18::el9 kernel-rt-devel
kernel-rt-devel-matched affected Red Hat:openshift:4.18::el9 kernel-rt-devel-matched
kernel-rt-kvm affected Red Hat:openshift:4.18::el9 kernel-rt-kvm
kernel-rt-modules affected Red Hat:openshift:4.18::el9 kernel-rt-modules
kernel-rt-modules-core affected Red Hat:openshift:4.18::el9 kernel-rt-modules-core
kernel-rt-modules-extra affected Red Hat:openshift:4.18::el9 kernel-rt-modules-extra
kernel-rt-modules-internal affected Red Hat:openshift:4.18::el9 kernel-rt-modules-internal
kernel-rt-modules-partner affected Red Hat:openshift:4.18::el9 kernel-rt-modules-partner
kernel-selftests-internal affected Red Hat:openshift:4.18::el9 kernel-selftests-internal
kernel-tools affected Red Hat:openshift:4.18::el9 kernel-tools
kernel-tools-debuginfo affected Red Hat:openshift:4.18::el9 kernel-tools-debuginfo
kernel-tools-libs affected Red Hat:openshift:4.18::el9 kernel-tools-libs
kernel-tools-libs-devel affected Red Hat:openshift:4.18::el9 kernel-tools-libs-devel
kernel-uki-virt affected Red Hat:openshift:4.18::el9 kernel-uki-virt
kernel-zfcpdump affected Red Hat:openshift:4.18::el9 kernel-zfcpdump
kernel-zfcpdump-core affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-core
kernel-zfcpdump-debuginfo affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-debuginfo
kernel-zfcpdump-devel affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-devel
kernel-zfcpdump-devel-matched affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-devel-matched
kernel-zfcpdump-modules affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-modules
kernel-zfcpdump-modules-core affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-modules-core
kernel-zfcpdump-modules-extra affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-modules-extra
kernel-zfcpdump-modules-internal affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-modules-internal
kernel-zfcpdump-modules-partner affected Red Hat:openshift:4.18::el9 kernel-zfcpdump-modules-partner
libperf-debuginfo affected Red Hat:openshift:4.18::el9 libperf-debuginfo
openshift affected Red Hat:openshift:4.18::el9 openshift
openshift affected Red Hat:openshift:4.18::el8 openshift
openshift-ansible affected Red Hat:openshift:4.18::el9 openshift-ansible
openshift-ansible affected Red Hat:openshift:4.18::el8 openshift-ansible
openshift-ansible-test affected Red Hat:openshift:4.18::el9 openshift-ansible-test
openshift-ansible-test affected Red Hat:openshift:4.18::el8 openshift-ansible-test
openshift-hyperkube affected Red Hat:openshift:4.18::el8 openshift-hyperkube
openshift-hyperkube affected Red Hat:openshift:4.18::el9 openshift-hyperkube
openshift-kube-apiserver affected Red Hat:openshift:4.18::el9 openshift-kube-apiserver
openshift-kube-apiserver affected Red Hat:openshift:4.18::el8 openshift-kube-apiserver
openshift-kube-controller-manager affected Red Hat:openshift:4.18::el8 openshift-kube-controller-manager
openshift-kube-controller-manager affected Red Hat:openshift:4.18::el9 openshift-kube-controller-manager
openshift-kubelet affected Red Hat:openshift:4.18::el9 openshift-kubelet
openshift-kubelet affected Red Hat:openshift:4.18::el8 openshift-kubelet
openshift-kube-scheduler affected Red Hat:openshift:4.18::el8 openshift-kube-scheduler
openshift-kube-scheduler affected Red Hat:openshift:4.18::el9 openshift-kube-scheduler
perf affected Red Hat:openshift:4.18::el9 perf
perf-debuginfo affected Red Hat:openshift:4.18::el9 perf-debuginfo
podman affected Red Hat:openshift:4.18::el9 podman
podman-debuginfo affected Red Hat:openshift:4.18::el9 podman-debuginfo
podman-debugsource affected Red Hat:openshift:4.18::el9 podman-debugsource
podman-docker affected Red Hat:openshift:4.18::el9 podman-docker
podman-plugins affected Red Hat:openshift:4.18::el9 podman-plugins
podman-plugins-debuginfo affected Red Hat:openshift:4.18::el9 podman-plugins-debuginfo
podman-remote affected Red Hat:openshift:4.18::el9 podman-remote
podman-remote-debuginfo affected Red Hat:openshift:4.18::el9 podman-remote-debuginfo
podman-tests affected Red Hat:openshift:4.18::el9 podman-tests
python3-perf affected Red Hat:openshift:4.18::el9 python3-perf
python3-perf-debuginfo affected Red Hat:openshift:4.18::el9 python3-perf-debuginfo
rtla affected Red Hat:openshift:4.18::el9 rtla
Upstream advisory

RHBA-2025:15692

Open SourceActive exploitation (sightings)HIGH2025-09-16

Red Hat Bug Fix Advisory: OpenShift Container Platform 4.19.12 packages update

Affected products

ProductStatusVendorPackageEcosystem
container-selinux affected Red Hat:openshift:4.19::el9 container-selinux
cri-o affected Red Hat:openshift:4.19::el9 cri-o
cri-o-debuginfo affected Red Hat:openshift:4.19::el9 cri-o-debuginfo
cri-o-debugsource affected Red Hat:openshift:4.19::el9 cri-o-debugsource
openshift affected Red Hat:openshift:4.19::el9 openshift
openshift-hyperkube affected Red Hat:openshift:4.19::el9 openshift-hyperkube
openshift-kube-apiserver affected Red Hat:openshift:4.19::el9 openshift-kube-apiserver
openshift-kube-controller-manager affected Red Hat:openshift:4.19::el9 openshift-kube-controller-manager
openshift-kubelet affected Red Hat:openshift:4.19::el9 openshift-kubelet
openshift-kube-scheduler affected Red Hat:openshift:4.19::el9 openshift-kube-scheduler
podman affected Red Hat:openshift:4.19::el9 podman
podman-debuginfo affected Red Hat:openshift:4.19::el9 podman-debuginfo
podman-debugsource affected Red Hat:openshift:4.19::el9 podman-debugsource
podman-docker affected Red Hat:openshift:4.19::el9 podman-docker
podman-plugins affected Red Hat:openshift:4.19::el9 podman-plugins
podman-plugins-debuginfo affected Red Hat:openshift:4.19::el9 podman-plugins-debuginfo
podman-remote affected Red Hat:openshift:4.19::el9 podman-remote
podman-remote-debuginfo affected Red Hat:openshift:4.19::el9 podman-remote-debuginfo
podman-tests affected Red Hat:openshift:4.19::el9 podman-tests
podman-tests-debuginfo affected Red Hat:openshift:4.19::el9 podman-tests-debuginfo
Upstream advisory

CVE-2025-9276

Open SourceActive exploitation (sightings)CRITICAL2025-09-02

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-req...

CVEs:CVE-2025-9276

Affected products

ProductStatusVendorPackageEcosystem
cockroach-k8s-request-cert affected cockroachlabs
Upstream advisory

ECHO-633d-3526-5d52

Open SourceActive exploitation (sightings)2025-09-15

ECHO-633d-3526-5d52

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

openSUSE-SU-2025:15548-1

Open SourceActive exploitation (sightings)2025-09-12

chromedriver-140.0.7339.127-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

GHSA-9897-fp7v-93gp

Open SourceActive exploitation (sightings)CRITICAL2025-09-10

GHSA-9897-fp7v-93gp

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-10200

Open SourceActive exploitation (sightings)CRITICAL2025-09-10

DEBIAN-CVE-2025-10200

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DSA-5996-1

Open SourceActive exploitation (sightings)2025-09-10

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

CVE-2025-10200

GoogleActive exploitation (sightings)CRITICAL2025-09-09

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2025-10200

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-10200

GoogleActive exploitation (sightings)2025-09-09

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVEs:CVE-2025-10200

Upstream advisory

CVE-2025-59251

Open SourceActive exploitation (sightings)CRITICAL2025-09-09

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVEs:CVE-2025-59251

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

ASB-A-389976559

GoogleActive exploitation (sightings)2025-09-01

ASB-A-389976559

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-383851764

GoogleActive exploitation (sightings)2025-09-01

ASB-A-383851764

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-53791

Open SourceActive exploitation (sightings)MEDIUM2025-09-05

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVEs:CVE-2025-53791

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DSA-5993-1

Open SourceActive exploitation (sightings)2025-09-05

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
Upstream advisory

openSUSE-SU-2025:15524-1

Open SourceActive exploitation (sightings)2025-09-05

chromedriver-140.0.7339.80-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

DEBIAN-CVE-2025-9866

Open SourceActive exploitation (sightings)HIGH2025-09-03

DEBIAN-CVE-2025-9866

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-9866

GoogleActive exploitation (sightings)HIGH2025-09-02

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-9866

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-9866

GoogleActive exploitation (sightings)2025-09-02

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-9866

Upstream advisory

GHSA-68x2-mx4q-78m7

Open SourceActive exploitation (sightings)HIGH2025-09-10

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

Affected products

ProductStatusVendorPackageEcosystem
common affected nguniversal @nguniversal/common
platform-server affected angular @angular/platform-server
ssr affected angular @angular/ssr
Upstream advisory

GHSA-68x2-mx4q-78m7

Open SourceActive exploitation (sightings)HIGH2025-09-10

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

Affected products

ProductStatusVendorPackageEcosystem
common affected nguniversal @nguniversal/common
platform-server affected angular @angular/platform-server
ssr affected angular @angular/ssr
Upstream advisory

CVE-2025-59052

Open SourceActive exploitation (sightings)HIGH2025-09-10

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

CVEs:CVE-2025-59052

Affected products

ProductStatusVendorPackageEcosystem
common affected nguniversal @nguniversal/common
platform-server affected angular @angular/platform-server
ssr affected angular @angular/ssr
Upstream advisory

CVE-2025-59052

Open SourceActive exploitation (sightings)HIGH2025-09-10

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

CVEs:CVE-2025-59052

Affected products

ProductStatusVendorPackageEcosystem
common affected nguniversal @nguniversal/common
platform-server affected angular @angular/platform-server
ssr affected angular @angular/ssr
Upstream advisory

CVE-2025-59052

GoogleActive exploitation (sightings)HIGH2025-09-10

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side rendering. For h...

CVEs:CVE-2025-59052

Upstream advisory

ASB-A-421179224

GoogleActive exploitation (sightings)2025-09-01

ASB-A-421179224

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-w7r3-mgwf-4mqq

Open SourceActive exploitation (sightings)CRITICAL2025-09-17

Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

Affected products

ProductStatusVendorPackageEcosystem
KubernetesClient affected NuGet KubernetesClient
kubernetes-reflector affected chainguard kubernetes-reflector
kubernetes-reflector affected wolfi kubernetes-reflector
Upstream advisory

GHSA-w7r3-mgwf-4mqq

Open SourceActive exploitation (sightings)CRITICAL2025-09-17

Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

Affected products

ProductStatusVendorPackageEcosystem
KubernetesClient affected NuGet KubernetesClient
Upstream advisory

CVE-2025-9708

Open SourceActive exploitation (sightings)MEDIUM2025-09-16

Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

CVEs:CVE-2025-9708

Affected products

ProductStatusVendorPackageEcosystem
KubernetesClient affected NuGet KubernetesClient
Upstream advisory

CVE-2025-9708

GoogleActive exploitation (sightings)CRITICAL2025-09-16

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to pr...

CVEs:CVE-2025-9708

Upstream advisory

GHSA-95cp-mqgp-v35f

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

GHSA-95cp-mqgp-v35f

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-10890

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

DEBIAN-CVE-2025-10890

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10890

GoogleActive exploitation (sightings)CRITICAL2025-09-23

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10890

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2025-9867

Open SourceActive exploitation (sightings)MEDIUM2025-09-03

DEBIAN-CVE-2025-9867

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-9867

GoogleActive exploitation (sightings)2025-09-02

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-9867

Upstream advisory

CVE-2025-9867

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-9867

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2025-32318

Open SourceActive exploitation (sightings)HIGH2025-09-05

DEBIAN-CVE-2025-32318

Affected products

ProductStatusVendorPackageEcosystem
libskia affected Debian:14 libskia
Upstream advisory

CVE-2025-12907

GoogleActive exploitation (sightings)CRITICAL2025-09-02

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)

CVEs:CVE-2025-12907

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-36897

Open SourceActive exploitation (sightings)CRITICAL2025-09-03

In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-376027286

GoogleActive exploitation (sightings)HIGH2025-09-01

PUB-A-376027286

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-4q3x-7jmg-pjmq

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

GHSA-4q3x-7jmg-pjmq

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-10501

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

DEBIAN-CVE-2025-10501

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10501

GoogleActive exploitation (sightings)CRITICAL2025-09-17

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10501

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-10501

GoogleActive exploitation (sightings)2025-09-17

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10501

Upstream advisory

GHSA-h6c6-wc5c-vvgv

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

GHSA-h6c6-wc5c-vvgv

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-10892

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

DEBIAN-CVE-2025-10892

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10892

GoogleActive exploitation (sightings)CRITICAL2025-09-23

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10892

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-gf8v-xggh-3g7h

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

GHSA-gf8v-xggh-3g7h

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-10502

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

DEBIAN-CVE-2025-10502

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10502

GoogleActive exploitation (sightings)2025-09-17

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

CVEs:CVE-2025-10502

Upstream advisory

CVE-2025-10502

GoogleActive exploitation (sightings)CRITICAL2025-09-17

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

CVEs:CVE-2025-10502

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-55qp-h28c-5r3m

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

GHSA-55qp-h28c-5r3m

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-10500

Open SourceActive exploitation (sightings)CRITICAL2025-09-24

DEBIAN-CVE-2025-10500

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10500

GoogleActive exploitation (sightings)2025-09-17

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10500

Upstream advisory

CVE-2025-10500

GoogleActive exploitation (sightings)CRITICAL2025-09-17

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10500

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-fq52-757j-7h2p

Open SourceActive exploitation (sightings)HIGH2025-09-10

GHSA-fq52-757j-7h2p

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-10201

Open SourceActive exploitation (sightings)HIGH2025-09-10

DEBIAN-CVE-2025-10201

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-10201

GoogleActive exploitation (sightings)HIGH2025-09-09

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-10201

GoogleActive exploitation (sightings)2025-09-09

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-10201

Upstream advisory

DEBIAN-CVE-2025-9865

Open SourceActive exploitation (sightings)MEDIUM2025-09-03

DEBIAN-CVE-2025-9865

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-9865

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity:...

CVEs:CVE-2025-9865

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-9865

GoogleActive exploitation (sightings)2025-09-02

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-9865

Upstream advisory

CVE-2025-48539

Open SourceActive exploitation (sightings)HIGH2025-09-02

In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2025-48539

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-394278882

GoogleActive exploitation (sightings)2025-09-01

PUB-A-394278882

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-55559

GoogleActive exploitation (sightings)2025-09-25

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVEs:CVE-2025-55559

Upstream advisory

CVE-2025-55559

Open SourceActive exploitation (sightings)HIGH2025-09-25

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

CVEs:CVE-2025-55559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

DEBIAN-CVE-2025-55559

Open SourceActive exploitation (sightings)HIGH2025-09-25

DEBIAN-CVE-2025-55559

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Debian:14 tensorflow
Upstream advisory

ASB-A-382329905

GoogleActive exploitation (sightings)2025-09-01

ASB-A-382329905

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-13107

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-13107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

ASB-A-361573291

GoogleActive exploitation (sightings)MEDIUM2025-09-01

ASB-A-361573291

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-12909

GoogleActive exploitation (sightings)CRITICAL2025-09-02

Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)

CVEs:CVE-2025-12909

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GO-2025-3939

Open SourceActive exploitation (sightings)2025-09-17

secrets-store-sync-controller discloses service account tokens in logs in sigs.k8s.io/secrets-store-sync-controller

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-sync-controller affected sigs.k8s.io sigs.k8s.io/secrets-store-sync-controller
Upstream advisory

GHSA-rcw7-pqfp-735x

Open SourceActive exploitation (sightings)HIGH2025-09-05

secrets-store-sync-controller discloses service account tokens in logs

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-sync-controller affected sigs.k8s.io sigs.k8s.io/secrets-store-sync-controller
Upstream advisory

GHSA-rcw7-pqfp-735x

Open SourceActive exploitation (sightings)HIGH2025-09-05

secrets-store-sync-controller discloses service account tokens in logs

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-sync-controller affected sigs.k8s.io sigs.k8s.io/secrets-store-sync-controller
Upstream advisory

CVE-2025-7445

Open SourceActive exploitation (sightings)MEDIUM2025-09-04

secrets-store-sync-controller discloses service account tokens in logs

CVEs:CVE-2025-7445

Affected products

ProductStatusVendorPackageEcosystem
secrets-store-sync-controller affected sigs.k8s.io sigs.k8s.io/secrets-store-sync-controller
Upstream advisory

CVE-2025-12908

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-12908

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

ASB-A-382313133

GoogleActive exploitation (sightings)2025-09-01

ASB-A-382313133

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-55556

Open SourceActive exploitation (sightings)MEDIUM2025-09-25

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVEs:CVE-2025-55556

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected google
Upstream advisory

CVE-2025-55556

GoogleActive exploitation (sightings)2025-09-25

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVEs:CVE-2025-55556

Upstream advisory

DEBIAN-CVE-2025-55556

Open SourceActive exploitation (sightings)MEDIUM2025-09-25

DEBIAN-CVE-2025-55556

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Debian:14 tensorflow
Upstream advisory

ASB-A-381272949

GoogleActive exploitation (sightings)2025-09-01

ASB-A-381272949

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-381279421

GoogleActive exploitation (sightings)2025-09-01

ASB-A-381279421

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-21032

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

CVEs:CVE-2025-21032

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-12906

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-12906

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-12905

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-12905

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-12911

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-12911

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-36901

Open SourceActive exploitation (sightings)CRITICAL2025-09-03

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

CVEs:CVE-2025-36901

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-396462223

GoogleActive exploitation (sightings)2025-09-01

PUB-A-396462223

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-402121892

GoogleActive exploitation (sightings)2025-09-01

ASB-A-402121892

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-21034

Open SourceActive exploitation (sightings)HIGH2025-09-02

Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

CVEs:CVE-2025-21034

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-383186226

GoogleActive exploitation (sightings)2025-09-01

ASB-A-383186226

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-21031

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

CVEs:CVE-2025-21031

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-21041

Open SourceActive exploitation (sightings)MEDIUM2025-09-03

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

CVEs:CVE-2025-21041

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-48561

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2025-48561

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-421781778

GoogleActive exploitation (sightings)2025-09-01

ASB-A-421781778

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-21025

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.

CVEs:CVE-2025-21025

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-21033

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

CVEs:CVE-2025-21033

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-48549

Open SourceActive exploitation (sightings)HIGH2025-09-02

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2025-48549

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-21026

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

CVEs:CVE-2025-21026

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-21027

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.

CVEs:CVE-2025-21027

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-21029

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.

CVEs:CVE-2025-21029

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-21028

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.

CVEs:CVE-2025-21028

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-12910

GoogleActive exploitation (sightings)MEDIUM2025-09-02

Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low)

CVEs:CVE-2025-12910

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-20707

Open SourceActive exploitation (sightings)HIGH2025-09-01

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS0...

CVEs:CVE-2025-20707

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-20705

Open SourceActive exploitation (sightings)HIGH2025-09-01

In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AL...

CVEs:CVE-2025-20705

Affected products

ProductStatusVendorPackageEcosystem
android affected google
openwrt affected openwrt
yocto affected linuxfoundation
Upstream advisory

CVE-2025-20706

Open SourceActive exploitation (sightings)HIGH2025-09-01

In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS0992...

CVEs:CVE-2025-20706

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32324

Open SourceActive exploitation (sightings)HIGH2025-09-02

In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2025-32324

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48546

Open SourceActive exploitation (sightings)HIGH2025-09-02

In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2025-48546

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48553

Open SourceActive exploitation (sightings)HIGH2025-09-02

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2025-48553

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-409047487

GoogleActive exploitation (sightings)2025-09-01

ASB-A-409047487

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-409047527

GoogleActive exploitation (sightings)2025-09-01

ASB-A-409047527

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2025-48559

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2025-48559

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36898

Open SourceActive exploitation (sightings)HIGH2025-09-03

There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36905

Open SourceActive exploitation (sightings)HIGH2025-09-03

In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2025-36905

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-364028612

GoogleActive exploitation (sightings)HIGH2025-09-01

PUB-A-364028612

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-365960683

GoogleActive exploitation (sightings)NONE2025-09-01

PUB-A-365960683

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-48547

Open SourceActive exploitation (sightings)HIGH2025-09-02

In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2025-48547

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-409047250

GoogleActive exploitation (sightings)2025-09-01

ASB-A-409047250

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2025-36903

Open SourceActive exploitation (sightings)HIGH2025-09-03

In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36903

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-418224726

GoogleActive exploitation (sightings)NONE2025-09-01

PUB-A-418224726

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-36893

Open SourceActive exploitation (sightings)MEDIUM2025-09-03

In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48551

Open SourceActive exploitation (sightings)MEDIUM2025-09-02

In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed ...

CVEs:CVE-2025-48551

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-413471185

GoogleActive exploitation (sightings)MEDIUM2025-09-01

PUB-A-413471185

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

SUSE-SU-2025:20672-1

Open SourcePoC exploitCRITICAL2025-09-05

Security update for protobuf

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected SUSE:Linux Micro 6.1 protobuf
Upstream advisory

CLSA-2025-1757017511

Open SourcePoC exploitCRITICAL2025-09-04

protobuf: Fix of CVE-2024-7254

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected TuxCare:AlmaLinux:9.2 protobuf
protobuf-compiler affected TuxCare:AlmaLinux:9.2 protobuf-compiler
protobuf-devel affected TuxCare:AlmaLinux:9.2 protobuf-devel
protobuf-emacs affected TuxCare:AlmaLinux:9.2 protobuf-emacs
protobuf-lite affected TuxCare:AlmaLinux:9.2 protobuf-lite
protobuf-lite-devel affected TuxCare:AlmaLinux:9.2 protobuf-lite-devel
protobuf-lite-static affected TuxCare:AlmaLinux:9.2 protobuf-lite-static
protobuf-static affected TuxCare:AlmaLinux:9.2 protobuf-static
protobuf-vim affected TuxCare:AlmaLinux:9.2 protobuf-vim
python3-protobuf affected TuxCare:AlmaLinux:9.2 python3-protobuf
Upstream advisory

MINI-3g6g-9q63-fr5q

Open SourcePoC exploit2025-09-08

MINI-3g6g-9q63-fr5q

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

MINI-x8mp-pf5p-rc66

Open SourcePoC exploit2025-09-08

MINI-x8mp-pf5p-rc66

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.34 affected MinimOS kube-apiserver-fips-1.34
kube-apiserver-fips-1.34-compat affected MinimOS kube-apiserver-fips-1.34-compat
kube-controller-manager-fips-1.34 affected MinimOS kube-controller-manager-fips-1.34
kube-controller-manager-fips-1.34-compat affected MinimOS kube-controller-manager-fips-1.34-compat
kubectl-fips-1.34 affected MinimOS kubectl-fips-1.34
kubectl-fips-1.34-compat affected MinimOS kubectl-fips-1.34-compat
kube-proxy-fips-1.34 affected MinimOS kube-proxy-fips-1.34
kube-proxy-fips-1.34-compat affected MinimOS kube-proxy-fips-1.34-compat
kubernetes-fips-1.34 affected MinimOS kubernetes-fips-1.34
kube-scheduler-fips-1.34 affected MinimOS kube-scheduler-fips-1.34
kube-scheduler-fips-1.34-compat affected MinimOS kube-scheduler-fips-1.34-compat
Upstream advisory

MINI-h3c8-cqw6-8qqj

Open SourcePoC exploit2025-09-08

MINI-h3c8-cqw6-8qqj

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

MINI-4whp-8wx7-qrjj

Open SourcePoC exploit2025-09-08

MINI-4whp-8wx7-qrjj

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.33 affected MinimOS kube-apiserver-fips-1.33
kube-apiserver-fips-1.33-compat affected MinimOS kube-apiserver-fips-1.33-compat
kube-controller-manager-fips-1.33 affected MinimOS kube-controller-manager-fips-1.33
kube-controller-manager-fips-1.33-compat affected MinimOS kube-controller-manager-fips-1.33-compat
kubectl-fips-1.33 affected MinimOS kubectl-fips-1.33
kubectl-fips-1.33-compat affected MinimOS kubectl-fips-1.33-compat
kube-proxy-fips-1.33 affected MinimOS kube-proxy-fips-1.33
kube-proxy-fips-1.33-compat affected MinimOS kube-proxy-fips-1.33-compat
kubernetes-fips-1.33 affected MinimOS kubernetes-fips-1.33
kube-scheduler-fips-1.33 affected MinimOS kube-scheduler-fips-1.33
kube-scheduler-fips-1.33-compat affected MinimOS kube-scheduler-fips-1.33-compat
Upstream advisory

MINI-cc6c-rg45-h9gh

Open SourcePoC exploit2025-09-04

MINI-cc6c-rg45-h9gh

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.34 affected MinimOS kube-apiserver-1.34
kube-apiserver-1.34-compat affected MinimOS kube-apiserver-1.34-compat
kube-controller-manager-1.34 affected MinimOS kube-controller-manager-1.34
kube-controller-manager-1.34-compat affected MinimOS kube-controller-manager-1.34-compat
kubectl-1.34 affected MinimOS kubectl-1.34
kubectl-1.34-advanced-compat affected MinimOS kubectl-1.34-advanced-compat
kubectl-1.34-compat affected MinimOS kubectl-1.34-compat
kube-proxy-1.34 affected MinimOS kube-proxy-1.34
kube-proxy-1.34-compat affected MinimOS kube-proxy-1.34-compat
kubernetes-1.34 affected MinimOS kubernetes-1.34
kube-scheduler-1.34 affected MinimOS kube-scheduler-1.34
kube-scheduler-1.34-compat affected MinimOS kube-scheduler-1.34-compat
Upstream advisory

CLSA-2025-1758039948

Open SourcePoC exploitHIGH2025-09-16

protobuf: Fix of CVE-2022-1941

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected TuxCare:AlmaLinux:9.2 protobuf
protobuf-compiler affected TuxCare:AlmaLinux:9.2 protobuf-compiler
protobuf-devel affected TuxCare:AlmaLinux:9.2 protobuf-devel
protobuf-emacs affected TuxCare:AlmaLinux:9.2 protobuf-emacs
protobuf-lite affected TuxCare:AlmaLinux:9.2 protobuf-lite
protobuf-lite-devel affected TuxCare:AlmaLinux:9.2 protobuf-lite-devel
protobuf-lite-static affected TuxCare:AlmaLinux:9.2 protobuf-lite-static
protobuf-static affected TuxCare:AlmaLinux:9.2 protobuf-static
protobuf-vim affected TuxCare:AlmaLinux:9.2 protobuf-vim
python3-protobuf affected TuxCare:AlmaLinux:9.2 python3-protobuf
Upstream advisory

ECHO-0684-a311-5067

Open SourcePoC exploit2025-09-15

ECHO-0684-a311-5067

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
Upstream advisory

ECHO-04d2-d010-5594

Open SourcePoC exploit2025-09-15

ECHO-04d2-d010-5594

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
Upstream advisory

ECHO-e851-3ecb-a213

Open SourcePoC exploit2025-09-15

ECHO-e851-3ecb-a213

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
Upstream advisory

OESA-2025-2309

Open SourcePoC exploit2025-09-19

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS-SP2 golang
Upstream advisory

OESA-2025-2308

Open SourcePoC exploit2025-09-19

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS-SP1 golang
Upstream advisory

OESA-2025-2307

Open SourcePoC exploit2025-09-19

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS golang
Upstream advisory

ECHO-80a7-4b2d-05e0

Open SourcePoC exploit2025-09-15

ECHO-80a7-4b2d-05e0

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

RHSA-2025:15291

Open SourcePoC exploitMEDIUM2025-09-10

Red Hat Security Advisory: OpenShift Container Platform 4.19.11 packages and security update

Affected products

ProductStatusVendorPackageEcosystem
openshift affected Red Hat:openshift:4.19::el9 openshift
openshift-hyperkube affected Red Hat:openshift:4.19::el9 openshift-hyperkube
openshift-kube-apiserver affected Red Hat:openshift:4.19::el9 openshift-kube-apiserver
openshift-kube-controller-manager affected Red Hat:openshift:4.19::el9 openshift-kube-controller-manager
openshift-kubelet affected Red Hat:openshift:4.19::el9 openshift-kubelet
openshift-kube-scheduler affected Red Hat:openshift:4.19::el9 openshift-kube-scheduler
Upstream advisory

GHSA-fghv-69vj-qj49

GooglePoC exploitNONE2025-09-04

Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions

Affected products

ProductStatusVendorPackageEcosystem
io.netty:netty-codec-http affected Maven io.netty:netty-codec-http
Upstream advisory

GHSA-fghv-69vj-qj49

Open SourcePoC exploitNONE2025-09-04

Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions

Affected products

ProductStatusVendorPackageEcosystem
akhq affected wolfi akhq
akhq affected chainguard akhq
apache-activemq-artemis affected chainguard apache-activemq-artemis
apache-activemq-artemis affected wolfi apache-activemq-artemis
apache-hop affected chainguard apache-hop
apache-hop-fips affected chainguard apache-hop-fips
apache-nifi affected chainguard apache-nifi
apache-nifi affected wolfi apache-nifi
apache-pulsar affected chainguard apache-pulsar
apache-pulsar affected wolfi apache-pulsar
apicurio-registry affected chainguard apicurio-registry
apicurio-registry affected wolfi apicurio-registry
camunda-zeebe-8.6 affected chainguard camunda-zeebe-8.6
camunda-zeebe-8.7 affected chainguard camunda-zeebe-8.7
celeborn-0.5 affected chainguard celeborn-0.5
celeborn-0.6 affected wolfi celeborn-0.6
celeborn-0.6 affected chainguard celeborn-0.6
debezium-connector-vitess-3.0 affected wolfi debezium-connector-vitess-3.0
debezium-connector-vitess-3.0 affected chainguard debezium-connector-vitess-3.0
docker-selenium affected wolfi docker-selenium
docker-selenium affected chainguard docker-selenium
druid affected wolfi druid
druid affected chainguard druid
elasticsearch-7 affected chainguard elasticsearch-7
elasticsearch-8.17 affected chainguard elasticsearch-8.17
elasticsearch-8.18 affected chainguard elasticsearch-8.18
elasticsearch-8.19 affected chainguard elasticsearch-8.19
elasticsearch-9.0 affected chainguard elasticsearch-9.0
elasticsearch-9.1 affected chainguard elasticsearch-9.1
elasticsearch-fips-8.19 affected chainguard elasticsearch-fips-8.19
elasticsearch-fips-9.0 affected chainguard elasticsearch-fips-9.0
elasticsearch-fips-9.1 affected chainguard elasticsearch-fips-9.1
flyway affected chainguard flyway
flyway affected wolfi flyway
grpc-java-fips-1.56.0 affected chainguard grpc-java-fips-1.56.0
hadoop-fips-3.3.6 affected chainguard hadoop-fips-3.3.6
infinispan-15.0 affected chainguard infinispan-15.0
infinispan-15.1 affected chainguard infinispan-15.1
infinispan-15.2 affected chainguard infinispan-15.2
infinispan-15.2 affected wolfi infinispan-15.2
io.netty:netty-codec-http affected Maven io.netty:netty-codec-http
kayenta-2025.0 affected chainguard kayenta-2025.0
kayenta-2025.1 affected chainguard kayenta-2025.1
kayenta-2025.2 affected chainguard kayenta-2025.2
kayenta-fips-2025.0 affected chainguard kayenta-fips-2025.0
kayenta-fips-2025.1 affected chainguard kayenta-fips-2025.1
kayenta-fips-2025.2 affected chainguard kayenta-fips-2025.2
keycloak-21.1 affected chainguard keycloak-21.1
keycloak-26.2 affected chainguard keycloak-26.2
keycloak-26.3 affected wolfi keycloak-26.3
keycloak-26.3 affected chainguard keycloak-26.3
keycloak-fips-26.2 affected chainguard keycloak-fips-26.2
keycloak-fips-26.3 affected chainguard keycloak-fips-26.3
keycloak-operator affected chainguard keycloak-operator
keycloak-operator affected wolfi keycloak-operator
keycloak-operator-fips affected chainguard keycloak-operator-fips
knative-kafka-broker-1.17 affected chainguard knative-kafka-broker-1.17
kserve-modelmesh affected wolfi kserve-modelmesh
kserve-modelmesh affected chainguard kserve-modelmesh
localstack affected chainguard localstack
logstash-8.17 affected chainguard logstash-8.17
logstash-8.18 affected chainguard logstash-8.18
logstash-8.19 affected chainguard logstash-8.19
logstash-9 affected chainguard logstash-9
logstash-9 affected wolfi logstash-9
logstash-9.0 affected chainguard logstash-9.0
logstash-9.1 affected wolfi logstash-9.1
logstash-9.1 affected chainguard logstash-9.1
management-api-for-apache-cassandra-4.0 affected chainguard management-api-for-apache-cassandra-4.0
management-api-for-apache-cassandra-4.1 affected wolfi management-api-for-apache-cassandra-4.1
management-api-for-apache-cassandra-4.1 affected chainguard management-api-for-apache-cassandra-4.1
neo4j-2025.02 affected wolfi neo4j-2025.02
neo4j-2025.02 affected chainguard neo4j-2025.02
neo4j-2025.03 affected wolfi neo4j-2025.03
neo4j-2025.03 affected chainguard neo4j-2025.03
neo4j-2025.04 affected wolfi neo4j-2025.04
neo4j-2025.04 affected chainguard neo4j-2025.04
neo4j-2025.05 affected wolfi neo4j-2025.05
neo4j-2025.05 affected chainguard neo4j-2025.05
neo4j-2025.06 affected wolfi neo4j-2025.06
neo4j-2025.06 affected chainguard neo4j-2025.06
neo4j-2025.07 affected chainguard neo4j-2025.07
neo4j-2025.07 affected wolfi neo4j-2025.07
neo4j-2025.08 affected wolfi neo4j-2025.08
neo4j-2025.08 affected chainguard neo4j-2025.08
neo4j-5.26 affected wolfi neo4j-5.26
neo4j-5.26 affected chainguard neo4j-5.26
opensearch-2 affected chainguard opensearch-2
opensearch-2 affected wolfi opensearch-2
prometheus-jmx-exporter affected chainguard prometheus-jmx-exporter
seata affected chainguard seata
selenium affected wolfi selenium
selenium affected chainguard selenium
sonarqube affected chainguard sonarqube
sonarqube affected wolfi sonarqube
spark-3.5 affected wolfi spark-3.5
spark-3.5 affected chainguard spark-3.5
spark-fips-3.5 affected chainguard spark-fips-3.5
strimzi-kafka-operator affected chainguard strimzi-kafka-operator
strimzi-kafka-operator affected wolfi strimzi-kafka-operator
tez affected chainguard tez
tez affected wolfi tez
thingsboard affected chainguard thingsboard
thingsboard affected wolfi thingsboard
trino affected chainguard trino
trino affected wolfi trino
wavefront-proxy affected chainguard wavefront-proxy
wavefront-proxy affected wolfi wavefront-proxy
wildfly affected wolfi wildfly
wildfly affected chainguard wildfly
zipkin affected chainguard zipkin
zipkin affected wolfi zipkin
Upstream advisory

ECHO-befe-522f-1557

Open SourcePoC exploit2025-09-15

ECHO-befe-522f-1557

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

ECHO-eb07-f8c0-c0ff

Open SourcePoC exploit2025-09-15

ECHO-eb07-f8c0-c0ff

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

CLSA-2025-1758101956

Open SourcePoC exploitHIGH2025-09-17

Fix CVE(s): CVE-2025-8194

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

CLSA-2025-1758101854

Open SourcePoC exploitHIGH2025-09-17

Fix CVE(s): CVE-2025-8194

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.5 affected TuxCare:Ubuntu:16.04 idle-python3.5
libpython3.5 affected TuxCare:Ubuntu:16.04 libpython3.5
libpython3.5-dev affected TuxCare:Ubuntu:16.04 libpython3.5-dev
libpython3.5-minimal affected TuxCare:Ubuntu:16.04 libpython3.5-minimal
libpython3.5-stdlib affected TuxCare:Ubuntu:16.04 libpython3.5-stdlib
libpython3.5-testsuite affected TuxCare:Ubuntu:16.04 libpython3.5-testsuite
python3.5 affected TuxCare:Ubuntu:16.04 python3.5
python3.5-dev affected TuxCare:Ubuntu:16.04 python3.5-dev
python3.5-doc affected TuxCare:Ubuntu:16.04 python3.5-doc
python3.5-examples affected TuxCare:Ubuntu:16.04 python3.5-examples
python3.5-minimal affected TuxCare:Ubuntu:16.04 python3.5-minimal
python3.5-venv affected TuxCare:Ubuntu:16.04 python3.5-venv
Upstream advisory

GHSA-3p8m-j85q-pgmj

Open SourcePoC exploitHIGH2025-09-03

Netty's decoders vulnerable to DoS via zip bomb style attack

Affected products

ProductStatusVendorPackageEcosystem
akhq affected wolfi akhq
akhq affected chainguard akhq
apache-activemq-artemis affected chainguard apache-activemq-artemis
apache-activemq-artemis affected wolfi apache-activemq-artemis
apache-hop affected chainguard apache-hop
apache-hop-fips affected chainguard apache-hop-fips
apache-nifi affected wolfi apache-nifi
apache-nifi affected chainguard apache-nifi
apache-pulsar affected wolfi apache-pulsar
apache-pulsar affected chainguard apache-pulsar
apicurio-registry affected wolfi apicurio-registry
apicurio-registry affected chainguard apicurio-registry
camunda-zeebe-8.6 affected chainguard camunda-zeebe-8.6
camunda-zeebe-8.7 affected chainguard camunda-zeebe-8.7
cassandra-5.0 affected chainguard cassandra-5.0
cassandra-5.0 affected wolfi cassandra-5.0
cassandra-fips-5.0 affected chainguard cassandra-fips-5.0
cassandra-reaper affected wolfi cassandra-reaper
cassandra-reaper affected chainguard cassandra-reaper
celeborn-0.5 affected chainguard celeborn-0.5
celeborn-0.6 affected chainguard celeborn-0.6
celeborn-0.6 affected wolfi celeborn-0.6
cloudwatch-exporter affected wolfi cloudwatch-exporter
cloudwatch-exporter affected chainguard cloudwatch-exporter
docker-selenium affected chainguard docker-selenium
docker-selenium affected wolfi docker-selenium
druid affected chainguard druid
druid affected wolfi druid
elasticsearch-7 affected chainguard elasticsearch-7
elasticsearch-8.17 affected chainguard elasticsearch-8.17
elasticsearch-8.18 affected chainguard elasticsearch-8.18
elasticsearch-8.19 affected chainguard elasticsearch-8.19
elasticsearch-9.0 affected chainguard elasticsearch-9.0
elasticsearch-9.1 affected chainguard elasticsearch-9.1
elasticsearch-fips-8.19 affected chainguard elasticsearch-fips-8.19
elasticsearch-fips-9.0 affected chainguard elasticsearch-fips-9.0
elasticsearch-fips-9.1 affected chainguard elasticsearch-fips-9.1
flyway affected wolfi flyway
flyway affected chainguard flyway
grpc-java-fips-1.56.0 affected chainguard grpc-java-fips-1.56.0
hadoop-fips-3.3.6 affected chainguard hadoop-fips-3.3.6
infinispan-15.0 affected chainguard infinispan-15.0
infinispan-15.1 affected chainguard infinispan-15.1
infinispan-15.2 affected wolfi infinispan-15.2
infinispan-15.2 affected chainguard infinispan-15.2
io.netty:netty-codec affected Maven io.netty:netty-codec
io.netty:netty-codec-compression affected Maven io.netty:netty-codec-compression
kafka-3.7 affected chainguard kafka-3.7
kafka-3.8 affected wolfi kafka-3.8
kafka-3.8 affected chainguard kafka-3.8
kafka-3.9 affected wolfi kafka-3.9
kafka-3.9 affected chainguard kafka-3.9
keycloak-21.1 affected chainguard keycloak-21.1
keycloak-26.2 affected chainguard keycloak-26.2
keycloak-26.3 affected chainguard keycloak-26.3
keycloak-26.3 affected wolfi keycloak-26.3
keycloak-fips-26.2 affected chainguard keycloak-fips-26.2
keycloak-fips-26.3 affected chainguard keycloak-fips-26.3
keycloak-operator affected chainguard keycloak-operator
keycloak-operator affected wolfi keycloak-operator
keycloak-operator-fips affected chainguard keycloak-operator-fips
knative-kafka-broker-1.17 affected chainguard knative-kafka-broker-1.17
kserve-modelmesh affected wolfi kserve-modelmesh
kserve-modelmesh affected chainguard kserve-modelmesh
localstack affected chainguard localstack
logstash-8.17 affected chainguard logstash-8.17
logstash-8.18 affected chainguard logstash-8.18
logstash-8.19 affected chainguard logstash-8.19
logstash-9 affected wolfi logstash-9
logstash-9 affected chainguard logstash-9
logstash-9.0 affected chainguard logstash-9.0
logstash-9.1 affected chainguard logstash-9.1
logstash-9.1 affected wolfi logstash-9.1
logstash-input-beats affected chainguard logstash-input-beats
logstash-input-beats affected wolfi logstash-input-beats
logstash-input-http affected chainguard logstash-input-http
logstash-input-http affected wolfi logstash-input-http
logstash-input-tcp affected chainguard logstash-input-tcp
logstash-input-tcp affected wolfi logstash-input-tcp
management-api-for-apache-cassandra-4.0 affected chainguard management-api-for-apache-cassandra-4.0
management-api-for-apache-cassandra-4.1 affected wolfi management-api-for-apache-cassandra-4.1
management-api-for-apache-cassandra-4.1 affected chainguard management-api-for-apache-cassandra-4.1
management-api-for-apache-cassandra-5.0 affected wolfi management-api-for-apache-cassandra-5.0
management-api-for-apache-cassandra-5.0 affected chainguard management-api-for-apache-cassandra-5.0
neo4j-2025.02 affected chainguard neo4j-2025.02
neo4j-2025.02 affected wolfi neo4j-2025.02
neo4j-2025.03 affected chainguard neo4j-2025.03
neo4j-2025.03 affected wolfi neo4j-2025.03
neo4j-2025.04 affected wolfi neo4j-2025.04
neo4j-2025.04 affected chainguard neo4j-2025.04
neo4j-2025.05 affected wolfi neo4j-2025.05
neo4j-2025.05 affected chainguard neo4j-2025.05
neo4j-2025.06 affected wolfi neo4j-2025.06
neo4j-2025.06 affected chainguard neo4j-2025.06
neo4j-2025.07 affected wolfi neo4j-2025.07
neo4j-2025.07 affected chainguard neo4j-2025.07
neo4j-4.4 affected chainguard neo4j-4.4
neo4j-5.26 affected chainguard neo4j-5.26
neo4j-5.26 affected wolfi neo4j-5.26
opensearch-2 affected wolfi opensearch-2
opensearch-2 affected chainguard opensearch-2
prometheus-jmx-exporter affected chainguard prometheus-jmx-exporter
seata affected chainguard seata
selenium affected chainguard selenium
selenium affected wolfi selenium
solr affected chainguard solr
solr affected wolfi solr
sonarqube affected chainguard sonarqube
sonarqube affected wolfi sonarqube
spark-3.5 affected chainguard spark-3.5
spark-3.5 affected wolfi spark-3.5
spark-4.0 affected wolfi spark-4.0
spark-4.0 affected chainguard spark-4.0
spark-fips-3.5 affected chainguard spark-fips-3.5
strimzi-kafka-operator affected chainguard strimzi-kafka-operator
strimzi-kafka-operator affected wolfi strimzi-kafka-operator
tez affected wolfi tez
tez affected chainguard tez
thingsboard affected chainguard thingsboard
thingsboard affected wolfi thingsboard
trino affected chainguard trino
trino affected wolfi trino
wavefront-proxy affected wolfi wavefront-proxy
wavefront-proxy affected chainguard wavefront-proxy
wildfly affected chainguard wildfly
wildfly affected wolfi wildfly
zipkin affected chainguard zipkin
zipkin affected wolfi zipkin
zookeeper-3.8 affected chainguard zookeeper-3.8
zookeeper-3.8 affected wolfi zookeeper-3.8
zookeeper-3.9 affected chainguard zookeeper-3.9
zookeeper-3.9 affected wolfi zookeeper-3.9
zookeeper-custom affected chainguard zookeeper-custom
zookeeper-fips-3.8 affected chainguard zookeeper-fips-3.8
zookeeper-fips-3.9 affected chainguard zookeeper-fips-3.9
Upstream advisory

GHSA-3p8m-j85q-pgmj

GooglePoC exploitHIGH2025-09-03

Netty's decoders vulnerable to DoS via zip bomb style attack

Affected products

ProductStatusVendorPackageEcosystem
io.netty:netty-codec affected Maven io.netty:netty-codec
io.netty:netty-codec-compression affected Maven io.netty:netty-codec-compression
Upstream advisory

MINI-j99w-vr94-2fx3

Open SourcePoC exploit2025-09-20

MINI-j99w-vr94-2fx3

Affected products

ProductStatusVendorPackageEcosystem
istio-1.26 affected MinimOS istio-1.26
istio-cni-1.26 affected MinimOS istio-cni-1.26
istio-cni-1.26-compat affected MinimOS istio-cni-1.26-compat
istioctl-1.26 affected MinimOS istioctl-1.26
istioctl-bash-completion-1.26 affected MinimOS istioctl-bash-completion-1.26
istioctl-zsh-completion-1.26 affected MinimOS istioctl-zsh-completion-1.26
istio-install-cni-1.26 affected MinimOS istio-install-cni-1.26
istio-install-cni-1.26-compat affected MinimOS istio-install-cni-1.26-compat
istio-pilot-agent-1.26 affected MinimOS istio-pilot-agent-1.26
istio-pilot-agent-1.26-compat affected MinimOS istio-pilot-agent-1.26-compat
istio-pilot-discovery-1.26 affected MinimOS istio-pilot-discovery-1.26
istio-pilot-discovery-1.26-compat affected MinimOS istio-pilot-discovery-1.26-compat
Upstream advisory

MINI-8xfq-jqp9-xxpr

Open SourcePoC exploit2025-09-20

MINI-8xfq-jqp9-xxpr

Affected products

ProductStatusVendorPackageEcosystem
istio-1.22 affected MinimOS istio-1.22
istio-cni-1.22 affected MinimOS istio-cni-1.22
istio-cni-1.22-compat affected MinimOS istio-cni-1.22-compat
istioctl-1.22 affected MinimOS istioctl-1.22
istioctl-bash-completion-1.22 affected MinimOS istioctl-bash-completion-1.22
istioctl-zsh-completion-1.22 affected MinimOS istioctl-zsh-completion-1.22
istio-install-cni-1.22 affected MinimOS istio-install-cni-1.22
istio-install-cni-1.22-compat affected MinimOS istio-install-cni-1.22-compat
istio-pilot-agent-1.22 affected MinimOS istio-pilot-agent-1.22
istio-pilot-agent-1.22-compat affected MinimOS istio-pilot-agent-1.22-compat
istio-pilot-discovery-1.22 affected MinimOS istio-pilot-discovery-1.22
istio-pilot-discovery-1.22-compat affected MinimOS istio-pilot-discovery-1.22-compat
Upstream advisory

MINI-x347-j2f7-4ppw

Open SourcePoC exploit2025-09-20

MINI-x347-j2f7-4ppw

Affected products

ProductStatusVendorPackageEcosystem
istio-1.24 affected MinimOS istio-1.24
istio-cni-1.24 affected MinimOS istio-cni-1.24
istio-cni-1.24-compat affected MinimOS istio-cni-1.24-compat
istioctl-1.24 affected MinimOS istioctl-1.24
istioctl-bash-completion-1.24 affected MinimOS istioctl-bash-completion-1.24
istioctl-zsh-completion-1.24 affected MinimOS istioctl-zsh-completion-1.24
istio-install-cni-1.24 affected MinimOS istio-install-cni-1.24
istio-install-cni-1.24-compat affected MinimOS istio-install-cni-1.24-compat
istio-pilot-agent-1.24 affected MinimOS istio-pilot-agent-1.24
istio-pilot-agent-1.24-compat affected MinimOS istio-pilot-agent-1.24-compat
istio-pilot-discovery-1.24 affected MinimOS istio-pilot-discovery-1.24
istio-pilot-discovery-1.24-compat affected MinimOS istio-pilot-discovery-1.24-compat
Upstream advisory

MINI-vqfx-q85p-4cg3

Open SourcePoC exploit2025-09-20

MINI-vqfx-q85p-4cg3

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

MINI-5884-2q6q-qq94

Open SourcePoC exploit2025-09-20

MINI-5884-2q6q-qq94

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-4hgp-j37q-86v4

Open SourcePoC exploit2025-09-20

MINI-4hgp-j37q-86v4

Affected products

ProductStatusVendorPackageEcosystem
istio-1.25 affected MinimOS istio-1.25
istio-cni-1.25 affected MinimOS istio-cni-1.25
istio-cni-1.25-compat affected MinimOS istio-cni-1.25-compat
istioctl-1.25 affected MinimOS istioctl-1.25
istioctl-bash-completion-1.25 affected MinimOS istioctl-bash-completion-1.25
istioctl-zsh-completion-1.25 affected MinimOS istioctl-zsh-completion-1.25
istio-install-cni-1.25 affected MinimOS istio-install-cni-1.25
istio-install-cni-1.25-compat affected MinimOS istio-install-cni-1.25-compat
istio-pilot-agent-1.25 affected MinimOS istio-pilot-agent-1.25
istio-pilot-agent-1.25-compat affected MinimOS istio-pilot-agent-1.25-compat
istio-pilot-discovery-1.25 affected MinimOS istio-pilot-discovery-1.25
istio-pilot-discovery-1.25-compat affected MinimOS istio-pilot-discovery-1.25-compat
Upstream advisory

MINI-3g6f-44rv-x9hj

Open SourcePoC exploit2025-09-20

MINI-3g6f-44rv-x9hj

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.33 affected MinimOS kube-apiserver-1.33
kube-apiserver-1.33-compat affected MinimOS kube-apiserver-1.33-compat
kube-controller-manager-1.33 affected MinimOS kube-controller-manager-1.33
kube-controller-manager-1.33-compat affected MinimOS kube-controller-manager-1.33-compat
kubectl-1.33 affected MinimOS kubectl-1.33
kubectl-1.33-advanced-compat affected MinimOS kubectl-1.33-advanced-compat
kubectl-1.33-compat affected MinimOS kubectl-1.33-compat
kube-proxy-1.33 affected MinimOS kube-proxy-1.33
kube-proxy-1.33-compat affected MinimOS kube-proxy-1.33-compat
kubernetes-1.33 affected MinimOS kubernetes-1.33
kube-scheduler-1.33 affected MinimOS kube-scheduler-1.33
kube-scheduler-1.33-compat affected MinimOS kube-scheduler-1.33-compat
Upstream advisory

MINI-338r-4qrv-wgh3

Open SourcePoC exploit2025-09-20

MINI-338r-4qrv-wgh3

Affected products

ProductStatusVendorPackageEcosystem
istio-1.23 affected MinimOS istio-1.23
istio-cni-1.23 affected MinimOS istio-cni-1.23
istio-cni-1.23-compat affected MinimOS istio-cni-1.23-compat
istioctl-1.23 affected MinimOS istioctl-1.23
istioctl-bash-completion-1.23 affected MinimOS istioctl-bash-completion-1.23
istioctl-zsh-completion-1.23 affected MinimOS istioctl-zsh-completion-1.23
istio-install-cni-1.23 affected MinimOS istio-install-cni-1.23
istio-install-cni-1.23-compat affected MinimOS istio-install-cni-1.23-compat
istio-pilot-agent-1.23 affected MinimOS istio-pilot-agent-1.23
istio-pilot-agent-1.23-compat affected MinimOS istio-pilot-agent-1.23-compat
istio-pilot-discovery-1.23 affected MinimOS istio-pilot-discovery-1.23
istio-pilot-discovery-1.23-compat affected MinimOS istio-pilot-discovery-1.23-compat
Upstream advisory

BIT-golang-2025-47906

Open SourcePoC exploitMEDIUM2025-09-20

Unexpected paths returned from LookPath in os/exec

Affected products

ProductStatusVendorPackageEcosystem
golang affected Bitnami golang
Upstream advisory

GHSA-gwrf-jf3h-w649

Open SourcePoC exploitMEDIUM2025-09-18

GHSA-gwrf-jf3h-w649

Affected products

ProductStatusVendorPackageEcosystem
addon-resizer affected wolfi addon-resizer
addon-resizer affected chainguard addon-resizer
apm-server-fips-7.17 affected chainguard apm-server-fips-7.17
azuredisk-csi-fips-1.28 affected chainguard azuredisk-csi-fips-1.28
azurefile-csi-fips-1.31 affected chainguard azurefile-csi-fips-1.31
bank-vaults affected chainguard bank-vaults
bank-vaults affected wolfi bank-vaults
blob-csi-fips-1.24 affected chainguard blob-csi-fips-1.24
blobfuse2 affected wolfi blobfuse2
blobfuse2 affected chainguard blobfuse2
checksec affected chainguard checksec
checksec affected wolfi checksec
cloud-provider-aws-1.30 affected chainguard cloud-provider-aws-1.30
cloud-provider-aws-1.31 affected wolfi cloud-provider-aws-1.31
cloud-provider-aws-1.31 affected chainguard cloud-provider-aws-1.31
cloud-provider-aws-fips-1.29 affected chainguard cloud-provider-aws-fips-1.29
cloud-provider-aws-fips-1.31 affected chainguard cloud-provider-aws-fips-1.31
cluster-api-1.7 affected chainguard cluster-api-1.7
cluster-autoscaler-fips-1.28 affected chainguard cluster-autoscaler-fips-1.28
cluster-autoscaler-fips-1.29 affected chainguard cluster-autoscaler-fips-1.29
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
configmap-reload-fips-0.12 affected chainguard configmap-reload-fips-0.12
confluent-common-docker affected wolfi confluent-common-docker
confluent-common-docker affected chainguard confluent-common-docker
consul-fips-1.19 affected chainguard consul-fips-1.19
container-object-storage-interface affected wolfi container-object-storage-interface
container-object-storage-interface affected chainguard container-object-storage-interface
ctop affected wolfi ctop
ctop affected chainguard ctop
custom-pod-autoscaler-operator affected chainguard custom-pod-autoscaler-operator
custom-pod-autoscaler-operator affected wolfi custom-pod-autoscaler-operator
dagdotdev affected chainguard dagdotdev
dagdotdev affected wolfi dagdotdev
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
eks-distro-fips-1.33 affected chainguard eks-distro-fips-1.33
etcd-fips-3.4 affected chainguard etcd-fips-3.4
falco affected chainguard falco
falco affected wolfi falco
gcp-compute-persistent-disk-csi-driver-fips-1.13 affected chainguard gcp-compute-persistent-disk-csi-driver-fips-1.13
gcp-compute-persistent-disk-csi-driver-fips-1.18 affected chainguard gcp-compute-persistent-disk-csi-driver-fips-1.18
gitlab-runner-18.1 affected chainguard gitlab-runner-18.1
gitlab-runner-18.1 affected wolfi gitlab-runner-18.1
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gostatsd affected wolfi gostatsd
gostatsd affected chainguard gostatsd
grafana-operator affected wolfi grafana-operator
grafana-operator affected chainguard grafana-operator
hivemind affected chainguard hivemind
hivemind affected wolfi hivemind
k8sgpt-operator affected wolfi k8sgpt-operator
k8sgpt-operator affected chainguard k8sgpt-operator
karma-fips affected chainguard karma-fips
karpenter-0.33 affected chainguard karpenter-0.33
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-1.2 affected wolfi karpenter-1.2
karpenter-1.2 affected chainguard karpenter-1.2
karpenter-fips-0.33 affected chainguard karpenter-fips-0.33
karpenter-fips-0.34 affected chainguard karpenter-fips-0.34
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-1.0 affected chainguard karpenter-fips-1.0
karpenter-fips-1.1 affected chainguard karpenter-fips-1.1
knative-eventing-1.17 affected chainguard knative-eventing-1.17
knative-eventing-fips-1.17 affected chainguard knative-eventing-fips-1.17
knative-serving-1.17 affected wolfi knative-serving-1.17
knative-serving-1.17 affected chainguard knative-serving-1.17
kserve-rest-proxy affected wolfi kserve-rest-proxy
kserve-rest-proxy affected chainguard kserve-rest-proxy
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-logging-operator-custom-runner-fips affected chainguard kube-logging-operator-custom-runner-fips
kuberay-operator affected chainguard kuberay-operator
kuberay-operator affected wolfi kuberay-operator
kubernetes-csi-node-driver-registrar-2.13 affected wolfi kubernetes-csi-node-driver-registrar-2.13
kubernetes-csi-node-driver-registrar-2.13 affected chainguard kubernetes-csi-node-driver-registrar-2.13
kubernetes-csi-node-driver-registrar-fips-2.14 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.14
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kube-vip affected wolfi kube-vip
kube-vip affected chainguard kube-vip
kube-vip-cloud-provider affected chainguard kube-vip-cloud-provider
kube-vip-cloud-provider affected wolfi kube-vip-cloud-provider
linkerd2-proxy-init affected chainguard linkerd2-proxy-init
linkerd2-proxy-init affected wolfi linkerd2-proxy-init
local-path-provisioner affected wolfi local-path-provisioner
local-path-provisioner affected chainguard local-path-provisioner
lvm-driver affected wolfi lvm-driver
lvm-driver affected chainguard lvm-driver
mattmoor-chainit affected chainguard mattmoor-chainit
memcached-exporter-fips affected chainguard memcached-exporter-fips
modelmesh-runtime-adapter affected wolfi modelmesh-runtime-adapter
modelmesh-runtime-adapter affected chainguard modelmesh-runtime-adapter
mongodb-k8s-operator-version-upgrade-post-start-hook affected chainguard mongodb-k8s-operator-version-upgrade-post-start-hook
mongodb-kubernetes-operator affected wolfi mongodb-kubernetes-operator
mongodb-kubernetes-operator affected chainguard mongodb-kubernetes-operator
nats affected chainguard nats
nats affected wolfi nats
nemo affected chainguard nemo
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
node-problem-detector-fips-0.8 affected chainguard node-problem-detector-fips-0.8
nvidia-nsight-compute-12.8 affected chainguard nvidia-nsight-compute-12.8
nvidia-nsight-compute-12.9 affected chainguard nvidia-nsight-compute-12.9
nvidia-nsight-compute-13.0 affected chainguard nvidia-nsight-compute-13.0
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
octo-sts affected wolfi octo-sts
octo-sts affected chainguard octo-sts
openbao-k8s-fips affected chainguard openbao-k8s-fips
php-fpm_exporter affected chainguard php-fpm_exporter
php-fpm_exporter affected wolfi php-fpm_exporter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-bind-exporter affected wolfi prometheus-bind-exporter
prometheus-nats-exporter affected wolfi prometheus-nats-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-process-exporter affected chainguard prometheus-process-exporter
pvc-autoresizer affected chainguard pvc-autoresizer
pvc-autoresizer affected wolfi pvc-autoresizer
rancher-machine affected chainguard rancher-machine
rancher-machine affected wolfi rancher-machine
scanner-test-golang-vulnerability-unfixed affected chainguard scanner-test-golang-vulnerability-unfixed
secrets-store-csi-driver-fips affected chainguard secrets-store-csi-driver-fips
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws-fips affected chainguard secrets-store-csi-driver-provider-aws-fips
sftpgo-plugin-geoipfilter affected wolfi sftpgo-plugin-geoipfilter
sftpgo-plugin-geoipfilter affected chainguard sftpgo-plugin-geoipfilter
sftpgo-plugin-pubsub affected chainguard sftpgo-plugin-pubsub
sftpgo-plugin-pubsub affected wolfi sftpgo-plugin-pubsub
shfmt affected chainguard shfmt
shfmt affected wolfi shfmt
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
terraform-provider-time affected wolfi terraform-provider-time
terraform-provider-time affected chainguard terraform-provider-time
terraform-provider-tls-fips affected chainguard terraform-provider-tls-fips
vault-benchmark affected wolfi vault-benchmark
vault-benchmark affected chainguard vault-benchmark
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
vexctl affected wolfi vexctl
vexctl affected chainguard vexctl
wazero-fips affected chainguard wazero-fips
yace-fips affected chainguard yace-fips
Upstream advisory

AZL-66128

Open SourcePoC exploit2025-09-18

CVE-2025-47906 affecting package golang for versions less than 1.22.7-5

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-66131

Open SourcePoC exploit2025-09-18

CVE-2025-47906 affecting package golang for versions less than 1.24.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-67512

Open SourcePoC exploit2025-09-18

CVE-2025-47906 affecting package golang for versions less than 1.18.8-10

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

DEBIAN-CVE-2025-47906

Open SourcePoC exploitMEDIUM2025-09-18

DEBIAN-CVE-2025-47906

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
golang-1.24 affected Debian:13 golang-1.24
Upstream advisory

GO-2025-3956

Open SourcePoC exploit2025-09-18

Unexpected paths returned from LookPath in os/exec

Affected products

ProductStatusVendorPackageEcosystem
addon-resizer affected wolfi addon-resizer
addon-resizer affected chainguard addon-resizer
apm-server-fips-7.17 affected chainguard apm-server-fips-7.17
azuredisk-csi-fips-1.28 affected chainguard azuredisk-csi-fips-1.28
azurefile-csi-fips-1.31 affected chainguard azurefile-csi-fips-1.31
bank-vaults affected wolfi bank-vaults
bank-vaults affected chainguard bank-vaults
blob-csi-fips-1.24 affected chainguard blob-csi-fips-1.24
blobfuse2 affected wolfi blobfuse2
blobfuse2 affected chainguard blobfuse2
checksec affected chainguard checksec
checksec affected wolfi checksec
cloud-provider-aws-1.30 affected chainguard cloud-provider-aws-1.30
cloud-provider-aws-1.31 affected wolfi cloud-provider-aws-1.31
cloud-provider-aws-1.31 affected chainguard cloud-provider-aws-1.31
cloud-provider-aws-fips-1.29 affected chainguard cloud-provider-aws-fips-1.29
cloud-provider-aws-fips-1.31 affected chainguard cloud-provider-aws-fips-1.31
cluster-api-1.7 affected chainguard cluster-api-1.7
configmap-reload-fips-0.11 affected chainguard configmap-reload-fips-0.11
configmap-reload-fips-0.12 affected chainguard configmap-reload-fips-0.12
confluent-common-docker affected wolfi confluent-common-docker
confluent-common-docker affected chainguard confluent-common-docker
consul-fips-1.19 affected chainguard consul-fips-1.19
container-object-storage-interface affected wolfi container-object-storage-interface
container-object-storage-interface affected chainguard container-object-storage-interface
ctop affected chainguard ctop
ctop affected wolfi ctop
custom-pod-autoscaler-operator affected chainguard custom-pod-autoscaler-operator
custom-pod-autoscaler-operator affected wolfi custom-pod-autoscaler-operator
dagdotdev affected chainguard dagdotdev
dagdotdev affected wolfi dagdotdev
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
docker-credential-ecr-login affected wolfi docker-credential-ecr-login
docker-credential-ecr-login affected chainguard docker-credential-ecr-login
eks-distro-fips-1.33 affected chainguard eks-distro-fips-1.33
etcd-fips-3.4 affected chainguard etcd-fips-3.4
gcp-compute-persistent-disk-csi-driver-fips-1.13 affected chainguard gcp-compute-persistent-disk-csi-driver-fips-1.13
gcp-compute-persistent-disk-csi-driver-fips-1.18 affected chainguard gcp-compute-persistent-disk-csi-driver-fips-1.18
git-lfs affected chainguard git-lfs
git-lfs affected wolfi git-lfs
gitsign affected wolfi gitsign
gitsign affected chainguard gitsign
gostatsd affected chainguard gostatsd
gostatsd affected wolfi gostatsd
grafana-operator affected chainguard grafana-operator
grafana-operator affected wolfi grafana-operator
hivemind affected chainguard hivemind
hivemind affected wolfi hivemind
k8sgpt-operator affected chainguard k8sgpt-operator
k8sgpt-operator affected wolfi k8sgpt-operator
karma-fips affected chainguard karma-fips
karpenter-0.33 affected chainguard karpenter-0.33
karpenter-0.35 affected chainguard karpenter-0.35
karpenter-1.2 affected chainguard karpenter-1.2
karpenter-fips-0.33 affected chainguard karpenter-fips-0.33
karpenter-fips-0.34 affected chainguard karpenter-fips-0.34
karpenter-fips-0.35 affected chainguard karpenter-fips-0.35
karpenter-fips-1.0 affected chainguard karpenter-fips-1.0
karpenter-fips-1.1 affected chainguard karpenter-fips-1.1
knative-eventing-1.17 affected chainguard knative-eventing-1.17
knative-eventing-fips-1.17 affected chainguard knative-eventing-fips-1.17
knative-serving-1.17 affected chainguard knative-serving-1.17
kserve-rest-proxy affected wolfi kserve-rest-proxy
kserve-rest-proxy affected chainguard kserve-rest-proxy
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
kube-logging-operator-custom-runner-fips affected chainguard kube-logging-operator-custom-runner-fips
kuberay-operator affected chainguard kuberay-operator
kuberay-operator affected wolfi kuberay-operator
kubernetes-csi-node-driver-registrar-fips-2.14 affected chainguard kubernetes-csi-node-driver-registrar-fips-2.14
kubernetes-dashboard-fips affected chainguard kubernetes-dashboard-fips
kube-vip affected wolfi kube-vip
kube-vip affected chainguard kube-vip
kube-vip-cloud-provider affected chainguard kube-vip-cloud-provider
kube-vip-cloud-provider affected wolfi kube-vip-cloud-provider
linkerd2-proxy-init affected chainguard linkerd2-proxy-init
linkerd2-proxy-init affected wolfi linkerd2-proxy-init
local-path-provisioner affected chainguard local-path-provisioner
local-path-provisioner affected wolfi local-path-provisioner
lvm-driver affected wolfi lvm-driver
lvm-driver affected chainguard lvm-driver
mattmoor-chainit affected chainguard mattmoor-chainit
memcached-exporter-fips affected chainguard memcached-exporter-fips
modelmesh-runtime-adapter affected chainguard modelmesh-runtime-adapter
mongodb-k8s-operator-version-upgrade-post-start-hook affected chainguard mongodb-k8s-operator-version-upgrade-post-start-hook
mongodb-kubernetes-operator affected chainguard mongodb-kubernetes-operator
mongodb-kubernetes-operator affected wolfi mongodb-kubernetes-operator
nats affected wolfi nats
nats affected chainguard nats
nemo affected chainguard nemo
newrelic-fluent-bit-output affected wolfi newrelic-fluent-bit-output
newrelic-fluent-bit-output affected chainguard newrelic-fluent-bit-output
newrelic-nri-statsd affected chainguard newrelic-nri-statsd
newrelic-nri-statsd affected wolfi newrelic-nri-statsd
node-problem-detector-fips-0.8 affected chainguard node-problem-detector-fips-0.8
nvidia-nsight-compute-12.8 affected chainguard nvidia-nsight-compute-12.8
nvidia-nsight-compute-12.9 affected chainguard nvidia-nsight-compute-12.9
nvidia-nsight-compute-13.0 affected chainguard nvidia-nsight-compute-13.0
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
octo-sts affected chainguard octo-sts
octo-sts affected wolfi octo-sts
openbao-k8s-fips affected chainguard openbao-k8s-fips
php-fpm_exporter affected wolfi php-fpm_exporter
php-fpm_exporter affected chainguard php-fpm_exporter
prometheus-adapter-0.10 affected chainguard prometheus-adapter-0.10
prometheus-beat-exporter-fips affected chainguard prometheus-beat-exporter-fips
prometheus-bind-exporter affected chainguard prometheus-bind-exporter
prometheus-nats-exporter affected chainguard prometheus-nats-exporter
prometheus-node-exporter-fips affected chainguard prometheus-node-exporter-fips
prometheus-process-exporter affected chainguard prometheus-process-exporter
pvc-autoresizer affected chainguard pvc-autoresizer
pvc-autoresizer affected wolfi pvc-autoresizer
rancher-machine affected chainguard rancher-machine
rancher-machine affected wolfi rancher-machine
scanner-test-golang-vulnerability-unfixed affected chainguard scanner-test-golang-vulnerability-unfixed
secrets-store-csi-driver-fips affected chainguard secrets-store-csi-driver-fips
secrets-store-csi-driver-provider-aws affected chainguard secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws affected wolfi secrets-store-csi-driver-provider-aws
secrets-store-csi-driver-provider-aws-fips affected chainguard secrets-store-csi-driver-provider-aws-fips
sftpgo-plugin-geoipfilter affected wolfi sftpgo-plugin-geoipfilter
sftpgo-plugin-geoipfilter affected chainguard sftpgo-plugin-geoipfilter
sftpgo-plugin-pubsub affected wolfi sftpgo-plugin-pubsub
sftpgo-plugin-pubsub affected chainguard sftpgo-plugin-pubsub
shfmt affected wolfi shfmt
shfmt affected chainguard shfmt
smarter-device-manager-fips affected chainguard smarter-device-manager-fips
stakater-reloader-0.0.119 affected chainguard stakater-reloader-0.0.119
stakater-reloader-0.0.128 affected chainguard stakater-reloader-0.0.128
stdlib affected Go stdlib
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
terraform-provider-time affected chainguard terraform-provider-time
terraform-provider-time affected wolfi terraform-provider-time
terraform-provider-tls-fips affected chainguard terraform-provider-tls-fips
vault-benchmark affected wolfi vault-benchmark
vault-benchmark affected chainguard vault-benchmark
vault-k8s affected chainguard vault-k8s
vault-k8s affected wolfi vault-k8s
vexctl affected chainguard vexctl
vexctl affected wolfi vexctl
wazero-fips affected chainguard wazero-fips
yace-fips affected chainguard yace-fips
Upstream advisory

ECHO-720b-9e21-965c

Open SourcePoC exploit2025-09-15

ECHO-720b-9e21-965c

Affected products

ProductStatusVendorPackageEcosystem
golang-1.24 affected Echo golang-1.24
Upstream advisory

OESA-2025-2260

Open SourcePoC exploitNONE2025-09-12

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS golang
Upstream advisory

OESA-2025-2184

Open SourcePoC exploitNONE2025-09-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP3 golang
Upstream advisory

OESA-2025-2183

Open SourcePoC exploitNONE2025-09-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:20.03-LTS-SP4 golang
Upstream advisory

OESA-2025-2182

Open SourcePoC exploitNONE2025-09-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS-SP2 golang
Upstream advisory

OESA-2025-2181

Open SourcePoC exploitNONE2025-09-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:24.03-LTS-SP1 golang
Upstream advisory

OESA-2025-2180

Open SourcePoC exploitNONE2025-09-05

golang security update

Affected products

ProductStatusVendorPackageEcosystem
golang affected openEuler:22.03-LTS-SP4 golang
Upstream advisory

MGASA-2025-0221

Open SourcePoC exploit2025-09-01

Updated golang packages fix vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:9 golang
Upstream advisory

ECHO-9504-f3b5-b586

Open SourcePoC exploit2025-09-15

ECHO-9504-f3b5-b586

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

ECHO-6d3f-307e-c4cf

Open SourcePoC exploit2025-09-15

ECHO-6d3f-307e-c4cf

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

ECHO-e7cb-18a6-dea3

Open SourcePoC exploit2025-09-15

ECHO-e7cb-18a6-dea3

Affected products

ProductStatusVendorPackageEcosystem
golang-1.24 affected Echo golang-1.24
Upstream advisory

MINI-x5c2-g7h2-5q25

Open SourcePoC exploit2025-09-28

MINI-x5c2-g7h2-5q25

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.34 affected MinimOS kube-apiserver-fips-1.34
kube-apiserver-fips-1.34-compat affected MinimOS kube-apiserver-fips-1.34-compat
kube-controller-manager-fips-1.34 affected MinimOS kube-controller-manager-fips-1.34
kube-controller-manager-fips-1.34-compat affected MinimOS kube-controller-manager-fips-1.34-compat
kubectl-fips-1.34 affected MinimOS kubectl-fips-1.34
kubectl-fips-1.34-compat affected MinimOS kubectl-fips-1.34-compat
kube-proxy-fips-1.34 affected MinimOS kube-proxy-fips-1.34
kube-proxy-fips-1.34-compat affected MinimOS kube-proxy-fips-1.34-compat
kubernetes-fips-1.34 affected MinimOS kubernetes-fips-1.34
kube-scheduler-fips-1.34 affected MinimOS kube-scheduler-fips-1.34
kube-scheduler-fips-1.34-compat affected MinimOS kube-scheduler-fips-1.34-compat
Upstream advisory

MINI-4c7g-g7c7-pfg7

Open SourcePoC exploit2025-09-28

MINI-4c7g-g7c7-pfg7

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-fips-1.26 affected MinimOS istio-cni-fips-1.26
istioctl-bash-completion-fips-1.26 affected MinimOS istioctl-bash-completion-fips-1.26
istioctl-fips-1.26 affected MinimOS istioctl-fips-1.26
istioctl-zsh-completion-fips-1.26 affected MinimOS istioctl-zsh-completion-fips-1.26
istio-fips-1.26 affected MinimOS istio-fips-1.26
istio-install-cni-fips-1.26 affected MinimOS istio-install-cni-fips-1.26
istio-pilot-agent-fips-1.26 affected MinimOS istio-pilot-agent-fips-1.26
istio-pilot-discovery-fips-1.26 affected MinimOS istio-pilot-discovery-fips-1.26
Upstream advisory

MINI-g6hm-9p2p-6qgp

Open SourcePoC exploit2025-09-28

MINI-g6hm-9p2p-6qgp

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-fips-1.25 affected MinimOS istio-cni-fips-1.25
istioctl-bash-completion-fips-1.25 affected MinimOS istioctl-bash-completion-fips-1.25
istioctl-fips-1.25 affected MinimOS istioctl-fips-1.25
istioctl-zsh-completion-fips-1.25 affected MinimOS istioctl-zsh-completion-fips-1.25
istio-fips-1.25 affected MinimOS istio-fips-1.25
istio-install-cni-fips-1.25 affected MinimOS istio-install-cni-fips-1.25
istio-pilot-agent-fips-1.25 affected MinimOS istio-pilot-agent-fips-1.25
istio-pilot-discovery-fips-1.25 affected MinimOS istio-pilot-discovery-fips-1.25
Upstream advisory

MINI-p86h-26r7-gr3f

Open SourcePoC exploit2025-09-28

MINI-p86h-26r7-gr3f

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.33 affected MinimOS kube-apiserver-fips-1.33
kube-apiserver-fips-1.33-compat affected MinimOS kube-apiserver-fips-1.33-compat
kube-controller-manager-fips-1.33 affected MinimOS kube-controller-manager-fips-1.33
kube-controller-manager-fips-1.33-compat affected MinimOS kube-controller-manager-fips-1.33-compat
kubectl-fips-1.33 affected MinimOS kubectl-fips-1.33
kubectl-fips-1.33-compat affected MinimOS kubectl-fips-1.33-compat
kube-proxy-fips-1.33 affected MinimOS kube-proxy-fips-1.33
kube-proxy-fips-1.33-compat affected MinimOS kube-proxy-fips-1.33-compat
kubernetes-fips-1.33 affected MinimOS kubernetes-fips-1.33
kube-scheduler-fips-1.33 affected MinimOS kube-scheduler-fips-1.33
kube-scheduler-fips-1.33-compat affected MinimOS kube-scheduler-fips-1.33-compat
Upstream advisory

MINI-q5c2-hx55-f54r

Open SourcePoC exploit2025-09-28

MINI-q5c2-hx55-f54r

Affected products

ProductStatusVendorPackageEcosystem
istio-1.25 affected MinimOS istio-1.25
istio-cni-1.25 affected MinimOS istio-cni-1.25
istio-cni-1.25-compat affected MinimOS istio-cni-1.25-compat
istioctl-1.25 affected MinimOS istioctl-1.25
istioctl-bash-completion-1.25 affected MinimOS istioctl-bash-completion-1.25
istioctl-zsh-completion-1.25 affected MinimOS istioctl-zsh-completion-1.25
istio-install-cni-1.25 affected MinimOS istio-install-cni-1.25
istio-install-cni-1.25-compat affected MinimOS istio-install-cni-1.25-compat
istio-pilot-agent-1.25 affected MinimOS istio-pilot-agent-1.25
istio-pilot-agent-1.25-compat affected MinimOS istio-pilot-agent-1.25-compat
istio-pilot-discovery-1.25 affected MinimOS istio-pilot-discovery-1.25
istio-pilot-discovery-1.25-compat affected MinimOS istio-pilot-discovery-1.25-compat
Upstream advisory

MINI-8crr-3qwv-8vq9

Open SourcePoC exploit2025-09-28

MINI-8crr-3qwv-8vq9

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

MINI-44vx-6qf3-v2h4

Open SourcePoC exploit2025-09-28

MINI-44vx-6qf3-v2h4

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

MINI-293j-mpj5-722c

Open SourcePoC exploit2025-09-28

MINI-293j-mpj5-722c

Affected products

ProductStatusVendorPackageEcosystem
istio-1.26 affected MinimOS istio-1.26
istio-cni-1.26 affected MinimOS istio-cni-1.26
istio-cni-1.26-compat affected MinimOS istio-cni-1.26-compat
istioctl-1.26 affected MinimOS istioctl-1.26
istioctl-bash-completion-1.26 affected MinimOS istioctl-bash-completion-1.26
istioctl-zsh-completion-1.26 affected MinimOS istioctl-zsh-completion-1.26
istio-install-cni-1.26 affected MinimOS istio-install-cni-1.26
istio-install-cni-1.26-compat affected MinimOS istio-install-cni-1.26-compat
istio-pilot-agent-1.26 affected MinimOS istio-pilot-agent-1.26
istio-pilot-agent-1.26-compat affected MinimOS istio-pilot-agent-1.26-compat
istio-pilot-discovery-1.26 affected MinimOS istio-pilot-discovery-1.26
istio-pilot-discovery-1.26-compat affected MinimOS istio-pilot-discovery-1.26-compat
Upstream advisory

MINI-cvqp-xmj7-6c25

Open SourcePoC exploit2025-09-24

MINI-cvqp-xmj7-6c25

Affected products

ProductStatusVendorPackageEcosystem
volume-modifier-for-k8s-fips affected MinimOS volume-modifier-for-k8s-fips
Upstream advisory

MINI-5qw6-3cpj-m26g

Open SourcePoC exploit2025-09-24

MINI-5qw6-3cpj-m26g

Affected products

ProductStatusVendorPackageEcosystem
volume-modifier-for-k8s affected MinimOS volume-modifier-for-k8s
Upstream advisory

MINI-vm2m-jvr3-gcgp

Open SourcePoC exploit2025-09-24

MINI-vm2m-jvr3-gcgp

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-fips-1.24 affected MinimOS istio-cni-fips-1.24
istioctl-bash-completion-fips-1.24 affected MinimOS istioctl-bash-completion-fips-1.24
istioctl-fips-1.24 affected MinimOS istioctl-fips-1.24
istioctl-zsh-completion-fips-1.24 affected MinimOS istioctl-zsh-completion-fips-1.24
istio-fips-1.24 affected MinimOS istio-fips-1.24
istio-install-cni-fips-1.24 affected MinimOS istio-install-cni-fips-1.24
istio-pilot-agent-fips-1.24 affected MinimOS istio-pilot-agent-fips-1.24
istio-pilot-discovery-fips-1.24 affected MinimOS istio-pilot-discovery-fips-1.24
Upstream advisory

MINI-pvff-983p-94cc

Open SourcePoC exploit2025-09-24

MINI-pvff-983p-94cc

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-fips-1.23 affected MinimOS istio-cni-fips-1.23
istioctl-bash-completion-fips-1.23 affected MinimOS istioctl-bash-completion-fips-1.23
istioctl-fips-1.23 affected MinimOS istioctl-fips-1.23
istioctl-zsh-completion-fips-1.23 affected MinimOS istioctl-zsh-completion-fips-1.23
istio-fips-1.23 affected MinimOS istio-fips-1.23
istio-install-cni-fips-1.23 affected MinimOS istio-install-cni-fips-1.23
istio-pilot-agent-fips-1.23 affected MinimOS istio-pilot-agent-fips-1.23
istio-pilot-discovery-fips-1.23 affected MinimOS istio-pilot-discovery-fips-1.23
Upstream advisory

MINI-8r52-949j-p23p

Open SourcePoC exploit2025-09-24

MINI-8r52-949j-p23p

Affected products

ProductStatusVendorPackageEcosystem
istio-cni-fips-1.22 affected MinimOS istio-cni-fips-1.22
istioctl-bash-completion-fips-1.22 affected MinimOS istioctl-bash-completion-fips-1.22
istioctl-fips-1.22 affected MinimOS istioctl-fips-1.22
istioctl-zsh-completion-fips-1.22 affected MinimOS istioctl-zsh-completion-fips-1.22
istio-fips-1.22 affected MinimOS istio-fips-1.22
istio-install-cni-fips-1.22 affected MinimOS istio-install-cni-fips-1.22
istio-pilot-agent-fips-1.22 affected MinimOS istio-pilot-agent-fips-1.22
istio-pilot-discovery-fips-1.22 affected MinimOS istio-pilot-discovery-fips-1.22
Upstream advisory

ECHO-4b0c-aa52-8cd0

Open SourcePoC exploit2025-09-24

ECHO-4b0c-aa52-8cd0

Affected products

ProductStatusVendorPackageEcosystem
golang-1.25 affected Echo golang-1.25
Upstream advisory

BIT-golang-2025-47910

Open SourcePoC exploitMEDIUM2025-09-24

CrossOriginProtection insecure bypass patterns not limited to exact matches in net/http

Affected products

ProductStatusVendorPackageEcosystem
golang affected Bitnami golang
Upstream advisory

GHSA-8pjc-487g-w6p2

Open SourcePoC exploitMEDIUM2025-09-22

GHSA-8pjc-487g-w6p2

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
amazon-cloudwatch-agent-operator affected chainguard amazon-cloudwatch-agent-operator
amazon-cloudwatch-agent-operator affected wolfi amazon-cloudwatch-agent-operator
apm-server-8.17 affected chainguard apm-server-8.17
argo-events affected wolfi argo-events
argo-events affected chainguard argo-events
aws-application-networking-k8s affected wolfi aws-application-networking-k8s
aws-application-networking-k8s affected chainguard aws-application-networking-k8s
aws-eks-pod-identity-agent affected wolfi aws-eks-pod-identity-agent
aws-eks-pod-identity-agent affected chainguard aws-eks-pod-identity-agent
aws-otel-collector affected chainguard aws-otel-collector
aws-otel-collector affected wolfi aws-otel-collector
aws-privateca-issuer affected wolfi aws-privateca-issuer
aws-privateca-issuer affected chainguard aws-privateca-issuer
azuredisk-csi-1.31 affected chainguard azuredisk-csi-1.31
azuredisk-csi-1.31 affected wolfi azuredisk-csi-1.31
azure-service-operator affected chainguard azure-service-operator
azure-service-operator affected wolfi azure-service-operator
blob-csi-1.25 affected chainguard blob-csi-1.25
blob-csi-1.26 affected chainguard blob-csi-1.26
blob-csi-1.26 affected wolfi blob-csi-1.26
bom affected wolfi bom
bom affected chainguard bom
buildkitd affected wolfi buildkitd
buildkitd affected chainguard buildkitd
caddy affected chainguard caddy
caddy affected wolfi caddy
caddy-fips affected chainguard caddy-fips
cerbos affected chainguard cerbos
cerbos affected wolfi cerbos
cert-manager-1.12 affected chainguard cert-manager-1.12
cert-manager-1.12 affected wolfi cert-manager-1.12
cert-manager-1.18 affected wolfi cert-manager-1.18
cert-manager-1.18 affected chainguard cert-manager-1.18
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl affected wolfi cert-manager-cmctl
cg affected chainguard cg
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chart-testing affected chainguard chart-testing
chart-testing affected wolfi chart-testing
cilium-cli affected wolfi cilium-cli
cilium-cli affected chainguard cilium-cli
cis-operator-1.2 affected chainguard cis-operator-1.2
cis-operator-1.3 affected chainguard cis-operator-1.3
cis-operator-1.4 affected chainguard cis-operator-1.4
cis-operator-1.4 affected wolfi cis-operator-1.4
clickhouse-operator affected chainguard clickhouse-operator
clickhouse-operator affected wolfi clickhouse-operator
cloud-provider-gcp-cloud-controller-manager affected chainguard cloud-provider-gcp-cloud-controller-manager
cloud-provider-gcp-cloud-controller-manager affected wolfi cloud-provider-gcp-cloud-controller-manager
cloud-provider-vsphere affected chainguard cloud-provider-vsphere
cloud-provider-vsphere affected wolfi cloud-provider-vsphere
cloud-sql-proxy-2.16 affected wolfi cloud-sql-proxy-2.16
cloud-sql-proxy-2.16 affected chainguard cloud-sql-proxy-2.16
cloud-sql-proxy-2.18 affected wolfi cloud-sql-proxy-2.18
cloud-sql-proxy-2.18 affected chainguard cloud-sql-proxy-2.18
cluster-api-1.8 affected chainguard cluster-api-1.8
cluster-api-1.9 affected chainguard cluster-api-1.9
cluster-api-1.9 affected wolfi cluster-api-1.9
cluster-api-azure-controller affected wolfi cluster-api-azure-controller
cluster-api-azure-controller affected chainguard cluster-api-azure-controller
cluster-api-helm-controller affected wolfi cluster-api-helm-controller
cluster-api-helm-controller affected chainguard cluster-api-helm-controller
cluster-api-provider-vsphere affected chainguard cluster-api-provider-vsphere
cluster-api-provider-vsphere affected wolfi cluster-api-provider-vsphere
cni-plugins affected chainguard cni-plugins
cni-plugins affected wolfi cni-plugins
conftest affected chainguard conftest
conftest affected wolfi conftest
consul-1.21 affected chainguard consul-1.21
consul-k8s-1.1 affected chainguard consul-k8s-1.1
consul-k8s-1.3 affected chainguard consul-k8s-1.3
consul-k8s-1.4 affected chainguard consul-k8s-1.4
consul-k8s-1.5 affected wolfi consul-k8s-1.5
consul-k8s-1.5 affected chainguard consul-k8s-1.5
consul-k8s-1.6 affected wolfi consul-k8s-1.6
consul-k8s-1.6 affected chainguard consul-k8s-1.6
consul-k8s-1.7 affected wolfi consul-k8s-1.7
consul-k8s-1.7 affected chainguard consul-k8s-1.7
containerd-1 affected chainguard containerd-1
containerd-1 affected wolfi containerd-1
containerd-2 affected chainguard containerd-2
containerd-2 affected wolfi containerd-2
contour-1.30 affected chainguard contour-1.30
contour-1.30 affected wolfi contour-1.30
contour-1.31 affected chainguard contour-1.31
contour-1.31 affected wolfi contour-1.31
controller-gen affected wolfi controller-gen
controller-gen affected chainguard controller-gen
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
dapr-1.13 affected chainguard dapr-1.13
dapr-1.14 affected chainguard dapr-1.14
db-operator affected chainguard db-operator
db-operator affected wolfi db-operator
delve affected chainguard delve
delve affected wolfi delve
dex affected wolfi dex
dex affected chainguard dex
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dive affected wolfi dive
dive affected chainguard dive
docker-cli affected chainguard docker-cli
docker-cli affected wolfi docker-cli
docker-cli-buildx affected wolfi docker-cli-buildx
docker-cli-buildx affected chainguard docker-cli-buildx
docker-credential-gcr affected wolfi docker-credential-gcr
docker-credential-gcr affected chainguard docker-credential-gcr
dockerize affected wolfi dockerize
dockerize affected chainguard dockerize
docker-machine-driver-harvester affected wolfi docker-machine-driver-harvester
docker-machine-driver-harvester affected chainguard docker-machine-driver-harvester
dragonfly-operator affected chainguard dragonfly-operator
eck-operator affected chainguard eck-operator
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
emissary affected chainguard emissary
emissary affected wolfi emissary
envconsul affected chainguard envconsul
envconsul affected wolfi envconsul
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
flannel affected chainguard flannel
flannel affected wolfi flannel
flux affected wolfi flux
flux affected chainguard flux
flux-0 affected chainguard flux-0
flux-2.5 affected wolfi flux-2.5
flux-2.5 affected chainguard flux-2.5
flux-2.6 affected wolfi flux-2.6
flux-2.6 affected chainguard flux-2.6
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-operator affected wolfi flux-operator
flux-operator affected chainguard flux-operator
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fzf affected chainguard fzf
fzf affected wolfi fzf
gatekeeper-3.17 affected chainguard gatekeeper-3.17
gatekeeper-3.17 affected wolfi gatekeeper-3.17
gatekeeper-3.18 affected chainguard gatekeeper-3.18
gatekeeper-3.18 affected wolfi gatekeeper-3.18
gatekeeper-3.19 affected wolfi gatekeeper-3.19
gatekeeper-3.19 affected chainguard gatekeeper-3.19
gcp-compute-persistent-disk-csi-driver-1.12 affected chainguard gcp-compute-persistent-disk-csi-driver-1.12
gcp-compute-persistent-disk-csi-driver-1.15 affected chainguard gcp-compute-persistent-disk-csi-driver-1.15
gcp-compute-persistent-disk-csi-driver-1.15 affected wolfi gcp-compute-persistent-disk-csi-driver-1.15
gcp-compute-persistent-disk-csi-driver-1.16 affected chainguard gcp-compute-persistent-disk-csi-driver-1.16
gcp-compute-persistent-disk-csi-driver-1.16 affected wolfi gcp-compute-persistent-disk-csi-driver-1.16
gcp-compute-persistent-disk-csi-driver-1.18 affected wolfi gcp-compute-persistent-disk-csi-driver-1.18
gcp-compute-persistent-disk-csi-driver-1.18 affected chainguard gcp-compute-persistent-disk-csi-driver-1.18
gcp-compute-persistent-disk-csi-driver-1.19 affected wolfi gcp-compute-persistent-disk-csi-driver-1.19
gcp-compute-persistent-disk-csi-driver-1.19 affected chainguard gcp-compute-persistent-disk-csi-driver-1.19
gcsfuse affected chainguard gcsfuse
gcsfuse affected wolfi gcsfuse
gendesk affected chainguard gendesk
gitleaks affected wolfi gitleaks
gitleaks affected chainguard gitleaks
glow affected chainguard glow
glow affected wolfi glow
gobump affected wolfi gobump
gobump affected chainguard gobump
gobuster affected chainguard gobuster
gobuster affected wolfi gobuster
google-osconfig-agent affected chainguard google-osconfig-agent
gptscript affected wolfi gptscript
gptscript affected chainguard gptscript
grafana-alloy affected chainguard grafana-alloy
grafana-alloy affected wolfi grafana-alloy
grafana-pyroscope-1.13 affected wolfi grafana-pyroscope-1.13
grafana-pyroscope-1.13 affected chainguard grafana-pyroscope-1.13
grafana-rollout-operator affected chainguard grafana-rollout-operator
grafana-rollout-operator affected wolfi grafana-rollout-operator
guac affected chainguard guac
guac affected wolfi guac
harbor-2.13 affected wolfi harbor-2.13
harbor-2.13 affected chainguard harbor-2.13
harbor-cli affected wolfi harbor-cli
harbor-cli affected chainguard harbor-cli
harbor-registry affected wolfi harbor-registry
harbor-registry affected chainguard harbor-registry
headlamp affected wolfi headlamp
headlamp affected chainguard headlamp
helm-docs affected wolfi helm-docs
helm-docs affected chainguard helm-docs
helm-mapkubeapis affected wolfi helm-mapkubeapis
helm-mapkubeapis affected chainguard helm-mapkubeapis
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-push affected chainguard helm-push
helm-push affected wolfi helm-push
helm-set-status affected chainguard helm-set-status
helm-set-status affected wolfi helm-set-status
hubble affected chainguard hubble
hubble affected wolfi hubble
hubble-ui affected chainguard hubble-ui
hubble-ui affected wolfi hubble-ui
hubble-ui-backend affected chainguard hubble-ui-backend
ini-file affected wolfi ini-file
ini-file affected chainguard ini-file
ipfs-cluster affected wolfi ipfs-cluster
ipfs-cluster affected chainguard ipfs-cluster
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
jaeger affected wolfi jaeger
jaeger affected chainguard jaeger
jitsucom-bulker affected wolfi jitsucom-bulker
jitsucom-bulker affected chainguard jitsucom-bulker
k3d affected chainguard k3d
k3d affected wolfi k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k3s-1.32 affected chainguard k3s-1.32
k3s-1.32 affected wolfi k3s-1.32
k8s_gateway affected wolfi k8s_gateway
k8s_gateway affected chainguard k8s_gateway
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
kapp affected chainguard kapp
kapp affected wolfi kapp
kapp-controller affected wolfi kapp-controller
kapp-controller affected chainguard kapp-controller
karpenter-1.5 affected chainguard karpenter-1.5
karpenter-1.5 affected wolfi karpenter-1.5
karpenter-1.6 affected chainguard karpenter-1.6
karpenter-1.6 affected wolfi karpenter-1.6
keda-2.15 affected wolfi keda-2.15
keda-2.15 affected chainguard keda-2.15
kind affected wolfi kind
kind affected chainguard kind
knative-serving-1.16 affected chainguard knative-serving-1.16
knative-serving-1.16 affected wolfi knative-serving-1.16
knative-serving-1.18 affected chainguard knative-serving-1.18
knative-serving-1.18 affected wolfi knative-serving-1.18
ko affected wolfi ko
ko affected chainguard ko
kor affected chainguard kor
kor affected wolfi kor
kpt affected chainguard kpt
kpt affected wolfi kpt
kube-arangodb affected chainguard kube-arangodb
kube-arangodb affected wolfi kube-arangodb
kube-bench affected chainguard kube-bench
kube-bench affected wolfi kube-bench
kubecolor affected wolfi kubecolor
kubecolor affected chainguard kubecolor
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kuberlr affected wolfi kuberlr
kuberlr affected chainguard kuberlr
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-nfs affected chainguard kubernetes-csi-driver-nfs
kubernetes-csi-driver-nfs affected wolfi kubernetes-csi-driver-nfs
kubernetes-csi-external-health-monitor affected chainguard kubernetes-csi-external-health-monitor
kubernetes-csi-external-health-monitor affected wolfi kubernetes-csi-external-health-monitor
kubernetes-csi-external-snapshotter-8.3 affected wolfi kubernetes-csi-external-snapshotter-8.3
kubernetes-csi-external-snapshotter-8.3 affected chainguard kubernetes-csi-external-snapshotter-8.3
kubernetes-csi-node-driver-registrar-2.14 affected wolfi kubernetes-csi-node-driver-registrar-2.14
kubernetes-csi-node-driver-registrar-2.14 affected chainguard kubernetes-csi-node-driver-registrar-2.14
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard-api affected chainguard kubernetes-dashboard-api
kubernetes-dashboard-api affected wolfi kubernetes-dashboard-api
kubernetes-dashboard-auth affected wolfi kubernetes-dashboard-auth
kubernetes-dashboard-auth affected chainguard kubernetes-dashboard-auth
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-web affected chainguard kubernetes-dashboard-web
kubernetes-dashboard-web affected wolfi kubernetes-dashboard-web
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kubo affected chainguard kubo
kubo affected wolfi kubo
kuma-2.10 affected wolfi kuma-2.10
kuma-2.10 affected chainguard kuma-2.10
kuma-2.7 affected chainguard kuma-2.7
kuma-2.9 affected wolfi kuma-2.9
kuma-2.9 affected chainguard kuma-2.9
kyverno-1.13 affected chainguard kyverno-1.13
kyverno-1.13 affected wolfi kyverno-1.13
kyverno-1.14 affected chainguard kyverno-1.14
kyverno-1.14 affected wolfi kyverno-1.14
kyverno-notation-aws affected chainguard kyverno-notation-aws
kyverno-notation-aws affected wolfi kyverno-notation-aws
lazydocker affected wolfi lazydocker
lazydocker affected chainguard lazydocker
libnvidia-container affected wolfi libnvidia-container
libnvidia-container affected chainguard libnvidia-container
linkerd2-cni-plugin affected chainguard linkerd2-cni-plugin
logstash-9 affected chainguard logstash-9
logstash-9 affected wolfi logstash-9
mattermost-10.4 affected wolfi mattermost-10.4
mattermost-10.4 affected chainguard mattermost-10.4
mattermost-10.6 affected wolfi mattermost-10.6
mattermost-10.6 affected chainguard mattermost-10.6
mattermost-10.7 affected wolfi mattermost-10.7
mattermost-10.7 affected chainguard mattermost-10.7
mattermost-10.8 affected wolfi mattermost-10.8
mattermost-10.8 affected chainguard mattermost-10.8
mattermost-10.9 affected wolfi mattermost-10.9
mattermost-10.9 affected chainguard mattermost-10.9
mattermost-9.11 affected chainguard mattermost-9.11
mesosphere-vsphere-csi affected wolfi mesosphere-vsphere-csi
mesosphere-vsphere-csi affected chainguard mesosphere-vsphere-csi
migrate affected wolfi migrate
migrate affected chainguard migrate
mockgen affected wolfi mockgen
mockgen affected chainguard mockgen
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
monstache affected chainguard monstache
nats-server-config-reloader affected chainguard nats-server-config-reloader
nats-server-config-reloader affected wolfi nats-server-config-reloader
neuvector affected wolfi neuvector
neuvector affected chainguard neuvector
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
nginx-prometheus-exporter affected chainguard nginx-prometheus-exporter
nginx-prometheus-exporter affected wolfi nginx-prometheus-exporter
node-problem-detector-0.8 affected wolfi node-problem-detector-0.8
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nova affected wolfi nova
nova affected chainguard nova
nri-apache affected chainguard nri-apache
nri-apache affected wolfi nri-apache
nri-consul affected chainguard nri-consul
nri-consul affected wolfi nri-consul
nri-f5 affected chainguard nri-f5
nri-f5 affected wolfi nri-f5
nri-haproxy affected chainguard nri-haproxy
nri-haproxy affected wolfi nri-haproxy
nri-memcached affected chainguard nri-memcached
nri-memcached affected wolfi nri-memcached
nri-mongodb affected wolfi nri-mongodb
nri-mongodb affected chainguard nri-mongodb
nri-mysql affected wolfi nri-mysql
nri-mysql affected chainguard nri-mysql
nri-nagios affected wolfi nri-nagios
nri-nagios affected chainguard nri-nagios
nri-nginx affected wolfi nri-nginx
nri-nginx affected chainguard nri-nginx
nri-rabbitmq affected chainguard nri-rabbitmq
nri-rabbitmq affected wolfi nri-rabbitmq
nri-redis affected wolfi nri-redis
nri-redis affected chainguard nri-redis
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
oauth2-proxy affected chainguard oauth2-proxy
oauth2-proxy affected wolfi oauth2-proxy
opa affected chainguard opa
opa affected wolfi opa
opa-envoy affected wolfi opa-envoy
opa-envoy affected chainguard opa-envoy
opentofu-1.10 affected chainguard opentofu-1.10
opentofu-1.10 affected wolfi opentofu-1.10
opentofu-1.7 affected chainguard opentofu-1.7
opentofu-1.7 affected wolfi opentofu-1.7
opentofu-1.8 affected wolfi opentofu-1.8
opentofu-1.8 affected chainguard opentofu-1.8
opentofu-1.9 affected wolfi opentofu-1.9
opentofu-1.9 affected chainguard opentofu-1.9
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
pg_timetable affected chainguard pg_timetable
pg_timetable affected wolfi pg_timetable
plugin-barman-cloud affected wolfi plugin-barman-cloud
plugin-barman-cloud affected chainguard plugin-barman-cloud
pluto affected chainguard pluto
pluto affected wolfi pluto
polaris affected wolfi polaris
polaris affected chainguard polaris
portieris affected chainguard portieris
portieris affected wolfi portieris
prometheus-3.2 affected wolfi prometheus-3.2
prometheus-3.2 affected chainguard prometheus-3.2
prometheus-3.3 affected wolfi prometheus-3.3
prometheus-3.3 affected chainguard prometheus-3.3
prometheus-3.4 affected chainguard prometheus-3.4
prometheus-3.4 affected wolfi prometheus-3.4
prometheus-3.5 affected wolfi prometheus-3.5
prometheus-3.5 affected chainguard prometheus-3.5
prometheus-operator affected chainguard prometheus-operator
prometheus-operator affected wolfi prometheus-operator
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-default-user-credential-updater affected wolfi rabbitmq-default-user-credential-updater
rabbitmq-default-user-credential-updater affected chainguard rabbitmq-default-user-credential-updater
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rancher-2.10 affected chainguard rancher-2.10
rancher-2.10 affected wolfi rancher-2.10
rancher-2.8 affected chainguard rancher-2.8
rancher-2.8 affected wolfi rancher-2.8
rancher-agent-2.10 affected wolfi rancher-agent-2.10
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.12 affected wolfi rancher-agent-2.12
rancher-agent-2.12 affected chainguard rancher-agent-2.12
rancher-agent-2.8 affected chainguard rancher-agent-2.8
rancher-agent-2.9 affected wolfi rancher-agent-2.9
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-security-scan-0.4 affected chainguard rancher-security-scan-0.4
rancher-security-scan-0.5 affected chainguard rancher-security-scan-0.5
rancher-security-scan-0.6 affected wolfi rancher-security-scan-0.6
rancher-security-scan-0.6 affected chainguard rancher-security-scan-0.6
rancher-system-agent affected chainguard rancher-system-agent
rancher-system-agent affected wolfi rancher-system-agent
rancher-system-upgrade-controller affected wolfi rancher-system-upgrade-controller
rancher-system-upgrade-controller affected chainguard rancher-system-upgrade-controller
ratify affected chainguard ratify
ratify affected wolfi ratify
rclone affected chainguard rclone
rclone affected wolfi rclone
regclient affected wolfi regclient
regclient affected chainguard regclient
render-template affected wolfi render-template
render-template affected chainguard render-template
rke2-runtime-1.31 affected chainguard rke2-runtime-1.31
rootlesskit affected chainguard rootlesskit
rootlesskit affected wolfi rootlesskit
seaweedfs affected wolfi seaweedfs
seaweedfs affected chainguard seaweedfs
spark-operator affected chainguard spark-operator
spark-operator affected wolfi spark-operator
spire-controller-manager affected wolfi spire-controller-manager
spire-controller-manager affected chainguard spire-controller-manager
src affected wolfi src
src affected chainguard src
steampipe affected wolfi steampipe
steampipe affected chainguard steampipe
step-kms-plugin affected wolfi step-kms-plugin
step-kms-plugin affected chainguard step-kms-plugin
swagger affected chainguard swagger
swagger affected wolfi swagger
tekton-chains affected wolfi tekton-chains
tekton-chains affected chainguard tekton-chains
tekton-pipelines-0.59 affected chainguard tekton-pipelines-0.59
tekton-pipelines-0.62 affected chainguard tekton-pipelines-0.62
tekton-pipelines-0.65 affected chainguard tekton-pipelines-0.65
telegraf-1.33 affected wolfi telegraf-1.33
telegraf-1.33 affected chainguard telegraf-1.33
teleport-15 affected chainguard teleport-15
tempo affected wolfi tempo
tempo affected chainguard tempo
terraform affected chainguard terraform
terraform affected wolfi terraform
terraform-1.10 affected chainguard terraform-1.10
terraform-1.12 affected chainguard terraform-1.12
terraform-1.7 affected chainguard terraform-1.7
terraform-1.8 affected chainguard terraform-1.8
terraform-1.9 affected chainguard terraform-1.9
terraform-mcp-server affected wolfi terraform-mcp-server
terraform-mcp-server affected chainguard terraform-mcp-server
terraform-provider-azapi affected chainguard terraform-provider-azapi
terraform-provider-azapi affected wolfi terraform-provider-azapi
tflint affected chainguard tflint
tflint affected wolfi tflint
tfsec affected wolfi tfsec
tfsec affected chainguard tfsec
thanos affected chainguard thanos
thanos affected wolfi thanos
thanos-operator affected chainguard thanos-operator
thanos-operator affected wolfi thanos-operator
thanos-operator-fips affected chainguard thanos-operator-fips
tigera-operator-1.34 affected wolfi tigera-operator-1.34
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-1.38 affected chainguard tigera-operator-1.38
tigera-operator-1.38 affected wolfi tigera-operator-1.38
timescaledb-tune affected chainguard timescaledb-tune
timescaledb-tune affected wolfi timescaledb-tune
tkn affected chainguard tkn
tkn affected wolfi tkn
traefik-2.11 affected chainguard traefik-2.11
traefik-3.4 affected chainguard traefik-3.4
traefik-3.4 affected wolfi traefik-3.4
trivy affected chainguard trivy
trivy affected wolfi trivy
undock affected chainguard undock
undock affected wolfi undock
vault-1.16 affected chainguard vault-1.16
vault-1.18 affected chainguard vault-1.18
vault-1.19 affected chainguard vault-1.19
vault-1.20 affected chainguard vault-1.20
vault-csi-provider affected chainguard vault-csi-provider
vault-csi-provider affected wolfi vault-csi-provider
vitess-20 affected wolfi vitess-20
vitess-20 affected chainguard vitess-20
wait-for-port affected wolfi wait-for-port
wait-for-port affected chainguard wait-for-port
wal-g affected wolfi wal-g
wal-g affected chainguard wal-g
wgcf affected chainguard wgcf
wgcf affected wolfi wgcf
wire-go affected chainguard wire-go
wire-go affected wolfi wire-go
witness affected wolfi witness
witness affected chainguard witness
yunikorn-k8shim affected wolfi yunikorn-k8shim
yunikorn-k8shim affected chainguard yunikorn-k8shim
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

DEBIAN-CVE-2025-47910

Open SourcePoC exploitMEDIUM2025-09-22

DEBIAN-CVE-2025-47910

Affected products

ProductStatusVendorPackageEcosystem
golang-1.25 affected Debian:14 golang-1.25
Upstream advisory

GO-2025-3955

Open SourcePoC exploit2025-09-22

CrossOriginProtection insecure bypass patterns not limited to exact matches in net/http

Affected products

ProductStatusVendorPackageEcosystem
aactl affected chainguard aactl
aactl affected wolfi aactl
amazon-cloudwatch-agent-operator affected wolfi amazon-cloudwatch-agent-operator
amazon-cloudwatch-agent-operator affected chainguard amazon-cloudwatch-agent-operator
apm-server-8.17 affected chainguard apm-server-8.17
argo-events affected wolfi argo-events
argo-events affected chainguard argo-events
aws-application-networking-k8s affected wolfi aws-application-networking-k8s
aws-application-networking-k8s affected chainguard aws-application-networking-k8s
aws-eks-pod-identity-agent affected chainguard aws-eks-pod-identity-agent
aws-eks-pod-identity-agent affected wolfi aws-eks-pod-identity-agent
aws-otel-collector affected chainguard aws-otel-collector
aws-otel-collector affected wolfi aws-otel-collector
aws-privateca-issuer affected chainguard aws-privateca-issuer
aws-privateca-issuer affected wolfi aws-privateca-issuer
azuredisk-csi-1.31 affected chainguard azuredisk-csi-1.31
azure-service-operator affected wolfi azure-service-operator
azure-service-operator affected chainguard azure-service-operator
blob-csi-1.25 affected chainguard blob-csi-1.25
blob-csi-1.26 affected chainguard blob-csi-1.26
bom affected chainguard bom
bom affected wolfi bom
buildkitd affected chainguard buildkitd
buildkitd affected wolfi buildkitd
caddy affected wolfi caddy
caddy affected chainguard caddy
cerbos affected chainguard cerbos
cerbos affected wolfi cerbos
cert-manager-1.18 affected chainguard cert-manager-1.18
cert-manager-cmctl affected chainguard cert-manager-cmctl
cert-manager-cmctl affected wolfi cert-manager-cmctl
cg affected chainguard cg
chartmuseum affected chainguard chartmuseum
chartmuseum affected wolfi chartmuseum
chart-testing affected chainguard chart-testing
chart-testing affected wolfi chart-testing
cilium-cli affected chainguard cilium-cli
cilium-cli affected wolfi cilium-cli
cis-operator-1.2 affected chainguard cis-operator-1.2
cis-operator-1.3 affected chainguard cis-operator-1.3
cis-operator-1.4 affected chainguard cis-operator-1.4
cis-operator-1.4 affected wolfi cis-operator-1.4
clickhouse-operator affected chainguard clickhouse-operator
clickhouse-operator affected wolfi clickhouse-operator
cloud-provider-gcp-cloud-controller-manager affected wolfi cloud-provider-gcp-cloud-controller-manager
cloud-provider-gcp-cloud-controller-manager affected chainguard cloud-provider-gcp-cloud-controller-manager
cloud-provider-vsphere affected chainguard cloud-provider-vsphere
cloud-provider-vsphere affected wolfi cloud-provider-vsphere
cloud-sql-proxy-2.16 affected wolfi cloud-sql-proxy-2.16
cloud-sql-proxy-2.16 affected chainguard cloud-sql-proxy-2.16
cloud-sql-proxy-2.18 affected chainguard cloud-sql-proxy-2.18
cluster-api-1.8 affected chainguard cluster-api-1.8
cluster-api-1.9 affected chainguard cluster-api-1.9
cluster-api-azure-controller affected chainguard cluster-api-azure-controller
cluster-api-azure-controller affected wolfi cluster-api-azure-controller
cluster-api-helm-controller affected wolfi cluster-api-helm-controller
cluster-api-helm-controller affected chainguard cluster-api-helm-controller
cluster-api-provider-vsphere affected wolfi cluster-api-provider-vsphere
cluster-api-provider-vsphere affected chainguard cluster-api-provider-vsphere
cni-plugins affected wolfi cni-plugins
cni-plugins affected chainguard cni-plugins
conftest affected chainguard conftest
conftest affected wolfi conftest
consul-1.21 affected chainguard consul-1.21
consul-k8s-1.1 affected chainguard consul-k8s-1.1
consul-k8s-1.3 affected chainguard consul-k8s-1.3
consul-k8s-1.4 affected chainguard consul-k8s-1.4
consul-k8s-1.5 affected chainguard consul-k8s-1.5
consul-k8s-1.6 affected chainguard consul-k8s-1.6
consul-k8s-1.7 affected chainguard consul-k8s-1.7
containerd-1 affected wolfi containerd-1
containerd-1 affected chainguard containerd-1
containerd-2 affected wolfi containerd-2
containerd-2 affected chainguard containerd-2
contour-1.31 affected chainguard contour-1.31
controller-gen affected wolfi controller-gen
controller-gen affected chainguard controller-gen
cri-tools affected chainguard cri-tools
cri-tools affected wolfi cri-tools
dapr-1.14 affected chainguard dapr-1.14
db-operator affected wolfi db-operator
db-operator affected chainguard db-operator
delve affected wolfi delve
delve affected chainguard delve
dex affected wolfi dex
dex affected chainguard dex
dgraph affected wolfi dgraph
dgraph affected chainguard dgraph
dive affected chainguard dive
dive affected wolfi dive
docker-cli affected chainguard docker-cli
docker-cli affected wolfi docker-cli
docker-cli-buildx affected chainguard docker-cli-buildx
docker-cli-buildx affected wolfi docker-cli-buildx
docker-credential-gcr affected chainguard docker-credential-gcr
docker-credential-gcr affected wolfi docker-credential-gcr
dockerize affected chainguard dockerize
dockerize affected wolfi dockerize
docker-machine-driver-harvester affected chainguard docker-machine-driver-harvester
docker-machine-driver-harvester affected wolfi docker-machine-driver-harvester
dragonfly-operator affected chainguard dragonfly-operator
eck-operator affected chainguard eck-operator
eksctl affected chainguard eksctl
eksctl affected wolfi eksctl
emissary affected chainguard emissary
emissary affected wolfi emissary
envconsul affected chainguard envconsul
envconsul affected wolfi envconsul
falcoctl affected chainguard falcoctl
falcoctl affected wolfi falcoctl
flannel affected wolfi flannel
flannel affected chainguard flannel
flux affected wolfi flux
flux affected chainguard flux
flux-2.5 affected chainguard flux-2.5
flux-2.6 affected chainguard flux-2.6
flux-helm-controller affected chainguard flux-helm-controller
flux-helm-controller affected wolfi flux-helm-controller
flux-operator affected chainguard flux-operator
fulcio affected chainguard fulcio
fulcio affected wolfi fulcio
fzf affected wolfi fzf
fzf affected chainguard fzf
gatekeeper-3.19 affected chainguard gatekeeper-3.19
gcp-compute-persistent-disk-csi-driver-1.12 affected chainguard gcp-compute-persistent-disk-csi-driver-1.12
gcp-compute-persistent-disk-csi-driver-1.15 affected chainguard gcp-compute-persistent-disk-csi-driver-1.15
gcp-compute-persistent-disk-csi-driver-1.16 affected chainguard gcp-compute-persistent-disk-csi-driver-1.16
gcp-compute-persistent-disk-csi-driver-1.18 affected chainguard gcp-compute-persistent-disk-csi-driver-1.18
gcp-compute-persistent-disk-csi-driver-1.19 affected chainguard gcp-compute-persistent-disk-csi-driver-1.19
gcsfuse affected wolfi gcsfuse
gcsfuse affected chainguard gcsfuse
gendesk affected chainguard gendesk
gitleaks affected wolfi gitleaks
gitleaks affected chainguard gitleaks
glow affected chainguard glow
glow affected wolfi glow
gobump affected wolfi gobump
gobump affected chainguard gobump
gobuster affected wolfi gobuster
gobuster affected chainguard gobuster
google-osconfig-agent affected chainguard google-osconfig-agent
gptscript affected chainguard gptscript
gptscript affected wolfi gptscript
grafana-alloy affected chainguard grafana-alloy
grafana-alloy affected wolfi grafana-alloy
grafana-pyroscope-1.13 affected chainguard grafana-pyroscope-1.13
grafana-rollout-operator affected chainguard grafana-rollout-operator
grafana-rollout-operator affected wolfi grafana-rollout-operator
guac affected chainguard guac
guac affected wolfi guac
harbor-2.13 affected chainguard harbor-2.13
harbor-cli affected wolfi harbor-cli
harbor-cli affected chainguard harbor-cli
harbor-registry affected chainguard harbor-registry
harbor-registry affected wolfi harbor-registry
headlamp affected chainguard headlamp
headlamp affected wolfi headlamp
helm-docs affected wolfi helm-docs
helm-docs affected chainguard helm-docs
helm-mapkubeapis affected chainguard helm-mapkubeapis
helm-mapkubeapis affected wolfi helm-mapkubeapis
helm-operator affected chainguard helm-operator
helm-operator affected wolfi helm-operator
helm-push affected wolfi helm-push
helm-push affected chainguard helm-push
helm-set-status affected wolfi helm-set-status
helm-set-status affected chainguard helm-set-status
hubble affected chainguard hubble
hubble affected wolfi hubble
hubble-ui affected wolfi hubble-ui
hubble-ui affected chainguard hubble-ui
ini-file affected chainguard ini-file
ini-file affected wolfi ini-file
ipfs-cluster affected wolfi ipfs-cluster
ipfs-cluster affected chainguard ipfs-cluster
ip-masq-agent affected chainguard ip-masq-agent
ip-masq-agent affected wolfi ip-masq-agent
jitsucom-bulker affected chainguard jitsucom-bulker
jitsucom-bulker affected wolfi jitsucom-bulker
k3d affected wolfi k3d
k3d affected chainguard k3d
k3s affected chainguard k3s
k3s affected wolfi k3s
k3s-1.32 affected chainguard k3s-1.32
k3s-1.32 affected wolfi k3s-1.32
k8s_gateway affected chainguard k8s_gateway
k8s_gateway affected wolfi k8s_gateway
k8sgpt affected wolfi k8sgpt
k8sgpt affected chainguard k8sgpt
kapp affected chainguard kapp
kapp affected wolfi kapp
kapp-controller affected chainguard kapp-controller
kapp-controller affected wolfi kapp-controller
karpenter-1.5 affected chainguard karpenter-1.5
karpenter-1.6 affected chainguard karpenter-1.6
kind affected wolfi kind
kind affected chainguard kind
knative-serving-1.18 affected chainguard knative-serving-1.18
ko affected wolfi ko
ko affected chainguard ko
kor affected chainguard kor
kor affected wolfi kor
kpt affected chainguard kpt
kpt affected wolfi kpt
kube-bench affected wolfi kube-bench
kube-bench affected chainguard kube-bench
kubecolor affected chainguard kubecolor
kubecolor affected wolfi kubecolor
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
kube-logging-operator affected wolfi kube-logging-operator
kube-logging-operator affected chainguard kube-logging-operator
kuberlr affected wolfi kuberlr
kuberlr affected chainguard kuberlr
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-nfs affected wolfi kubernetes-csi-driver-nfs
kubernetes-csi-driver-nfs affected chainguard kubernetes-csi-driver-nfs
kubernetes-csi-external-health-monitor affected chainguard kubernetes-csi-external-health-monitor
kubernetes-csi-external-health-monitor affected wolfi kubernetes-csi-external-health-monitor
kubernetes-csi-external-snapshotter-8.3 affected chainguard kubernetes-csi-external-snapshotter-8.3
kubernetes-dashboard affected chainguard kubernetes-dashboard
kubernetes-dashboard affected wolfi kubernetes-dashboard
kubernetes-dashboard-api affected wolfi kubernetes-dashboard-api
kubernetes-dashboard-api affected chainguard kubernetes-dashboard-api
kubernetes-dashboard-auth affected wolfi kubernetes-dashboard-auth
kubernetes-dashboard-auth affected chainguard kubernetes-dashboard-auth
kubernetes-dashboard-metrics-scraper affected chainguard kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-metrics-scraper affected wolfi kubernetes-dashboard-metrics-scraper
kubernetes-dashboard-web affected chainguard kubernetes-dashboard-web
kubernetes-dashboard-web affected wolfi kubernetes-dashboard-web
kube-state-metrics affected chainguard kube-state-metrics
kube-state-metrics affected wolfi kube-state-metrics
kubo affected chainguard kubo
kubo affected wolfi kubo
kuma-2.10 affected chainguard kuma-2.10
kuma-2.7 affected chainguard kuma-2.7
kuma-2.9 affected chainguard kuma-2.9
kyverno-1.13 affected chainguard kyverno-1.13
kyverno-1.14 affected chainguard kyverno-1.14
kyverno-notation-aws affected chainguard kyverno-notation-aws
kyverno-notation-aws affected wolfi kyverno-notation-aws
lazydocker affected chainguard lazydocker
lazydocker affected wolfi lazydocker
libnvidia-container affected chainguard libnvidia-container
libnvidia-container affected wolfi libnvidia-container
linkerd2-cni-plugin affected chainguard linkerd2-cni-plugin
mesosphere-vsphere-csi affected wolfi mesosphere-vsphere-csi
mesosphere-vsphere-csi affected chainguard mesosphere-vsphere-csi
migrate affected wolfi migrate
migrate affected chainguard migrate
mockgen affected chainguard mockgen
mockgen affected wolfi mockgen
mongo-tools affected chainguard mongo-tools
mongo-tools affected wolfi mongo-tools
monstache affected chainguard monstache
nats-server-config-reloader affected chainguard nats-server-config-reloader
nats-server-config-reloader affected wolfi nats-server-config-reloader
neuvector affected chainguard neuvector
neuvector-sigstore-interface affected chainguard neuvector-sigstore-interface
neuvector-sigstore-interface affected wolfi neuvector-sigstore-interface
nginx-prometheus-exporter affected wolfi nginx-prometheus-exporter
nginx-prometheus-exporter affected chainguard nginx-prometheus-exporter
node-problem-detector-0.8 affected chainguard node-problem-detector-0.8
nodetaint affected wolfi nodetaint
nodetaint affected chainguard nodetaint
nova affected wolfi nova
nova affected chainguard nova
nri-apache affected wolfi nri-apache
nri-apache affected chainguard nri-apache
nri-consul affected chainguard nri-consul
nri-consul affected wolfi nri-consul
nri-f5 affected wolfi nri-f5
nri-f5 affected chainguard nri-f5
nri-haproxy affected chainguard nri-haproxy
nri-haproxy affected wolfi nri-haproxy
nri-memcached affected wolfi nri-memcached
nri-memcached affected chainguard nri-memcached
nri-mongodb affected wolfi nri-mongodb
nri-mongodb affected chainguard nri-mongodb
nri-mysql affected chainguard nri-mysql
nri-mysql affected wolfi nri-mysql
nri-nagios affected chainguard nri-nagios
nri-nagios affected wolfi nri-nagios
nri-nginx affected wolfi nri-nginx
nri-nginx affected chainguard nri-nginx
nri-rabbitmq affected chainguard nri-rabbitmq
nri-rabbitmq affected wolfi nri-rabbitmq
nri-redis affected wolfi nri-redis
nri-redis affected chainguard nri-redis
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
oauth2-proxy affected wolfi oauth2-proxy
oauth2-proxy affected chainguard oauth2-proxy
opa affected wolfi opa
opa affected chainguard opa
opa-envoy affected chainguard opa-envoy
opa-envoy affected wolfi opa-envoy
opentofu-1.10 affected chainguard opentofu-1.10
opentofu-1.10 affected wolfi opentofu-1.10
opentofu-1.8 affected chainguard opentofu-1.8
opentofu-1.9 affected chainguard opentofu-1.9
opentofu-1.9 affected wolfi opentofu-1.9
osv-scanner affected chainguard osv-scanner
osv-scanner affected wolfi osv-scanner
pg_timetable affected chainguard pg_timetable
pg_timetable affected wolfi pg_timetable
plugin-barman-cloud affected chainguard plugin-barman-cloud
pluto affected wolfi pluto
pluto affected chainguard pluto
polaris affected chainguard polaris
polaris affected wolfi polaris
portieris affected chainguard portieris
portieris affected wolfi portieris
prometheus-3.2 affected wolfi prometheus-3.2
prometheus-3.2 affected chainguard prometheus-3.2
prometheus-3.5 affected chainguard prometheus-3.5
prometheus-operator affected wolfi prometheus-operator
prometheus-operator affected chainguard prometheus-operator
rabbitmq-cluster-operator affected chainguard rabbitmq-cluster-operator
rabbitmq-cluster-operator affected wolfi rabbitmq-cluster-operator
rabbitmq-default-user-credential-updater affected chainguard rabbitmq-default-user-credential-updater
rabbitmq-default-user-credential-updater affected wolfi rabbitmq-default-user-credential-updater
rabbitmq-messaging-topology-operator affected chainguard rabbitmq-messaging-topology-operator
rabbitmq-messaging-topology-operator affected wolfi rabbitmq-messaging-topology-operator
rancher-2.10 affected chainguard rancher-2.10
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.12 affected chainguard rancher-agent-2.12
rancher-agent-2.9 affected chainguard rancher-agent-2.9
rancher-security-scan-0.4 affected chainguard rancher-security-scan-0.4
rancher-security-scan-0.5 affected chainguard rancher-security-scan-0.5
rancher-security-scan-0.6 affected chainguard rancher-security-scan-0.6
rancher-system-agent affected chainguard rancher-system-agent
rancher-system-agent affected wolfi rancher-system-agent
rancher-system-upgrade-controller affected wolfi rancher-system-upgrade-controller
rancher-system-upgrade-controller affected chainguard rancher-system-upgrade-controller
ratify affected chainguard ratify
ratify affected wolfi ratify
rclone affected chainguard rclone
rclone affected wolfi rclone
regclient affected chainguard regclient
regclient affected wolfi regclient
render-template affected wolfi render-template
render-template affected chainguard render-template
rke2-runtime-1.31 affected chainguard rke2-runtime-1.31
rootlesskit affected wolfi rootlesskit
rootlesskit affected chainguard rootlesskit
seaweedfs affected wolfi seaweedfs
seaweedfs affected chainguard seaweedfs
spark-operator affected wolfi spark-operator
spark-operator affected chainguard spark-operator
spire-controller-manager affected chainguard spire-controller-manager
spire-controller-manager affected wolfi spire-controller-manager
src affected chainguard src
src affected wolfi src
stdlib affected Go stdlib
steampipe affected wolfi steampipe
steampipe affected chainguard steampipe
step-kms-plugin affected chainguard step-kms-plugin
step-kms-plugin affected wolfi step-kms-plugin
swagger affected chainguard swagger
swagger affected wolfi swagger
tekton-chains affected chainguard tekton-chains
tekton-chains affected wolfi tekton-chains
tekton-pipelines-0.59 affected chainguard tekton-pipelines-0.59
tekton-pipelines-0.62 affected chainguard tekton-pipelines-0.62
tekton-pipelines-0.65 affected chainguard tekton-pipelines-0.65
teleport-15 affected chainguard teleport-15
tempo affected chainguard tempo
tempo affected wolfi tempo
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-1.10 affected chainguard terraform-1.10
terraform-1.12 affected chainguard terraform-1.12
terraform-1.9 affected chainguard terraform-1.9
terraform-mcp-server affected chainguard terraform-mcp-server
terraform-mcp-server affected wolfi terraform-mcp-server
terraform-provider-azapi affected chainguard terraform-provider-azapi
terraform-provider-azapi affected wolfi terraform-provider-azapi
tflint affected wolfi tflint
tflint affected chainguard tflint
tfsec affected chainguard tfsec
tfsec affected wolfi tfsec
thanos affected chainguard thanos
thanos affected wolfi thanos
thanos-operator affected chainguard thanos-operator
thanos-operator affected wolfi thanos-operator
tigera-operator-1.34 affected chainguard tigera-operator-1.34
tigera-operator-1.38 affected chainguard tigera-operator-1.38
timescaledb-tune affected wolfi timescaledb-tune
timescaledb-tune affected chainguard timescaledb-tune
tkn affected wolfi tkn
tkn affected chainguard tkn
traefik-2.11 affected chainguard traefik-2.11
traefik-3.4 affected chainguard traefik-3.4
traefik-3.4 affected wolfi traefik-3.4
trivy affected chainguard trivy
trivy affected wolfi trivy
undock affected chainguard undock
undock affected wolfi undock
vault-1.16 affected chainguard vault-1.16
vault-1.18 affected chainguard vault-1.18
vault-1.19 affected chainguard vault-1.19
vault-1.20 affected chainguard vault-1.20
vault-csi-provider affected chainguard vault-csi-provider
wait-for-port affected chainguard wait-for-port
wait-for-port affected wolfi wait-for-port
wal-g affected wolfi wal-g
wal-g affected chainguard wal-g
wgcf affected chainguard wgcf
wgcf affected wolfi wgcf
wire-go affected wolfi wire-go
wire-go affected chainguard wire-go
witness affected chainguard witness
witness affected wolfi witness
yunikorn-k8shim affected chainguard yunikorn-k8shim
yunikorn-k8shim affected wolfi yunikorn-k8shim
zot affected wolfi zot
zot affected chainguard zot
Upstream advisory

SUSE-SU-2025:20746-1

GooglePoC exploitHIGH2025-09-12

Security update for google-osconfig-agent

Affected products

ProductStatusVendorPackageEcosystem
google-osconfig-agent affected SUSE:Linux Micro 6.1 google-osconfig-agent
Upstream advisory

CVE-2025-56608

Open SourcePoC exploitCRITICAL2025-09-03

The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken ...

CVEs:CVE-2025-56608

Affected products

ProductStatusVendorPackageEcosystem
android_corona_virus_tracker_app_for_india affected donbermoy
Upstream advisory

CVE-2025-56608

GooglePoC exploit2025-09-03

The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes the authentication mechanism vulnerable to replay, spoofing, or brute-force attacks, potentially leading to unauthorized access. The vulnerability corresponds to CWE-327 and aligns with OWASP M5: Insufficient Cryptography and MASVS MSTG-CRYPTO-4.

CVEs:CVE-2025-56608

Upstream advisory

ECHO-6c2b-4775-07f5

Open SourcePoC exploit2025-09-15

ECHO-6c2b-4775-07f5

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

GHSA-hjm5-xgj8-vwj6

Open SourcePoC exploitCRITICAL2025-09-15

mcp-kubernetes-server has a Command Injection vulnerability

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

GHSA-hjm5-xgj8-vwj6

Open SourcePoC exploitCRITICAL2025-09-15

mcp-kubernetes-server has a Command Injection vulnerability

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

CVE-2025-59376

Open SourcePoC exploitMEDIUM2025-09-15

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is ...

CVEs:CVE-2025-59376

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected feisky
Upstream advisory

CVE-2025-59376

Open SourcePoC exploitMEDIUM2025-09-15

mcp-kubernetes-server has a Command Injection vulnerability

CVEs:CVE-2025-59376

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

CVE-2025-59376

Open SourcePoC exploitCRITICAL2025-09-15

mcp-kubernetes-server has a Command Injection vulnerability

CVEs:CVE-2025-59376

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

ECHO-2ad3-2ee4-a992

Open SourcePoC exploit2025-09-15

ECHO-2ad3-2ee4-a992

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

ECHO-6fb1-590b-9dd9

Open SourcePoC exploit2025-09-15

ECHO-6fb1-590b-9dd9

Affected products

ProductStatusVendorPackageEcosystem
golang-1.24 affected Echo golang-1.24
Upstream advisory

RLSA-2025:13940

Open SourcePoC exploitCRITICAL2025-09-08

Important: go-toolset:rhel8 security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

CLSA-2025-1756931716

Open SourcePoC exploit2025-09-03

golang: Fix of CVE-2025-4674

Affected products

ProductStatusVendorPackageEcosystem
golang affected TuxCare:AlmaLinux:9.2 golang
golang-bin affected TuxCare:AlmaLinux:9.2 golang-bin
golang-docs affected TuxCare:AlmaLinux:9.2 golang-docs
golang-misc affected TuxCare:AlmaLinux:9.2 golang-misc
golang-src affected TuxCare:AlmaLinux:9.2 golang-src
golang-tests affected TuxCare:AlmaLinux:9.2 golang-tests
go-toolset affected TuxCare:AlmaLinux:9.2 go-toolset
Upstream advisory

MINI-rc45-4v34-5mgr

Open SourcePoC exploit2025-09-21

MINI-rc45-4v34-5mgr

Affected products

ProductStatusVendorPackageEcosystem
ruby3.2-fluentd-kubernetes-daemonset-1.18 affected MinimOS ruby3.2-fluentd-kubernetes-daemonset-1.18
ruby3.2-fluentd-kubernetes-daemonset-1.18-kinesis affected MinimOS ruby3.2-fluentd-kubernetes-daemonset-1.18-kinesis
Upstream advisory

MINI-qrgc-hv33-22vq

Open SourcePoC exploit2025-09-21

MINI-qrgc-hv33-22vq

Affected products

ProductStatusVendorPackageEcosystem
ruby3.4-fluentd-kubernetes-daemonset-1.18 affected MinimOS ruby3.4-fluentd-kubernetes-daemonset-1.18
ruby3.4-fluentd-kubernetes-daemonset-1.18-kinesis affected MinimOS ruby3.4-fluentd-kubernetes-daemonset-1.18-kinesis
Upstream advisory

MINI-mcq5-4qg9-w4cg

Open SourcePoC exploit2025-09-21

MINI-mcq5-4qg9-w4cg

Affected products

ProductStatusVendorPackageEcosystem
ruby3.3-fluentd-kubernetes-daemonset-1.18 affected MinimOS ruby3.3-fluentd-kubernetes-daemonset-1.18
ruby3.3-fluentd-kubernetes-daemonset-1.18-kinesis affected MinimOS ruby3.3-fluentd-kubernetes-daemonset-1.18-kinesis
Upstream advisory

MINI-j2vw-xgpx-r8c7

Open SourcePoC exploit2025-09-21

MINI-j2vw-xgpx-r8c7

Affected products

ProductStatusVendorPackageEcosystem
ruby3.4-fluentd-kubernetes-daemonset-1.16 affected MinimOS ruby3.4-fluentd-kubernetes-daemonset-1.16
ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis affected MinimOS ruby3.4-fluentd-kubernetes-daemonset-1.16-kinesis
Upstream advisory

MINI-5f99-r283-2wqp

Open SourcePoC exploit2025-09-21

MINI-5f99-r283-2wqp

Affected products

ProductStatusVendorPackageEcosystem
ruby3.3-fluentd-kubernetes-daemonset-1.16 affected MinimOS ruby3.3-fluentd-kubernetes-daemonset-1.16
ruby3.3-fluentd-kubernetes-daemonset-1.16-kinesis affected MinimOS ruby3.3-fluentd-kubernetes-daemonset-1.16-kinesis
Upstream advisory

MINI-5h4w-q34g-h7xr

Open SourcePoC exploit2025-09-21

MINI-5h4w-q34g-h7xr

Affected products

ProductStatusVendorPackageEcosystem
ruby3.2-fluentd-kubernetes-daemonset-1.16 affected MinimOS ruby3.2-fluentd-kubernetes-daemonset-1.16
ruby3.2-fluentd-kubernetes-daemonset-1.16-kinesis affected MinimOS ruby3.2-fluentd-kubernetes-daemonset-1.16-kinesis
Upstream advisory

MINI-32f4-q38f-265p

Open SourcePoC exploit2025-09-21

MINI-32f4-q38f-265p

Affected products

ProductStatusVendorPackageEcosystem
ruby3.4-fluentd-kubernetes-daemonset-1.19 affected MinimOS ruby3.4-fluentd-kubernetes-daemonset-1.19
ruby3.4-fluentd-kubernetes-daemonset-1.19-kinesis affected MinimOS ruby3.4-fluentd-kubernetes-daemonset-1.19-kinesis
Upstream advisory

GHSA-c2f4-jgmc-q2r5

Open SourcePoC exploitHIGH2025-09-17

REXML has DoS condition when parsing malformed XML file

Affected products

ProductStatusVendorPackageEcosystem
gitlab-rails-ce-18.3 affected chainguard gitlab-rails-ce-18.3
gitlab-rails-ce-fips-18.3 affected chainguard gitlab-rails-ce-fips-18.3
jruby-9.4 affected wolfi jruby-9.4
jruby-9.4 affected chainguard jruby-9.4
kube-fluentd-operator affected wolfi kube-fluentd-operator
kube-fluentd-operator affected chainguard kube-fluentd-operator
logstash-8.19 affected chainguard logstash-8.19
logstash-9.1 affected wolfi logstash-9.1
logstash-9.1 affected chainguard logstash-9.1
rexml affected RubyGems rexml
ruby3.1-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.16
ruby3.1-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.1-fluentd-kubernetes-daemonset-1.17
ruby3.1-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.17
ruby3.1-fluentd-kubernetes-daemonset-1.18 affected chainguard ruby3.1-fluentd-kubernetes-daemonset-1.18
ruby3.1-fluentd-kubernetes-daemonset-1.18 affected wolfi ruby3.1-fluentd-kubernetes-daemonset-1.18
ruby3.2-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.16
ruby3.2-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.17
ruby3.2-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.2-fluentd-kubernetes-daemonset-1.17
ruby3.2-fluentd-kubernetes-daemonset-1.18 affected chainguard ruby3.2-fluentd-kubernetes-daemonset-1.18
ruby3.2-fluentd-kubernetes-daemonset-1.18 affected wolfi ruby3.2-fluentd-kubernetes-daemonset-1.18
ruby3.3-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.3-fluentd-kubernetes-daemonset-1.16
ruby3.3-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.3-fluentd-kubernetes-daemonset-1.17
ruby3.3-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.3-fluentd-kubernetes-daemonset-1.17
ruby3.3-fluentd-kubernetes-daemonset-1.18 affected wolfi ruby3.3-fluentd-kubernetes-daemonset-1.18
ruby3.3-fluentd-kubernetes-daemonset-1.18 affected chainguard ruby3.3-fluentd-kubernetes-daemonset-1.18
ruby3.4-fluentd-kubernetes-daemonset-1.16 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.16
ruby3.4-fluentd-kubernetes-daemonset-1.17 affected wolfi ruby3.4-fluentd-kubernetes-daemonset-1.17
ruby3.4-fluentd-kubernetes-daemonset-1.17 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.17
ruby3.4-fluentd-kubernetes-daemonset-1.18 affected chainguard ruby3.4-fluentd-kubernetes-daemonset-1.18
ruby3.4-fluentd-kubernetes-daemonset-1.18 affected wolfi ruby3.4-fluentd-kubernetes-daemonset-1.18
truffleruby affected chainguard truffleruby
Upstream advisory

GHSA-c2f4-jgmc-q2r5

GooglePoC exploitHIGH2025-09-17

REXML has DoS condition when parsing malformed XML file

Affected products

ProductStatusVendorPackageEcosystem
rexml affected RubyGems rexml
Upstream advisory

ECHO-cc1a-f211-d25d

Open SourcePoC exploit2025-09-15

ECHO-cc1a-f211-d25d

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

GHSA-36rr-ww3j-vrjv

Open SourcePoC exploitHIGH2025-09-19

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

Affected products

ProductStatusVendorPackageEcosystem
keras affected PyPI keras
keras affected PyPI
tensorflow-cpu-jupyter affected chainguard tensorflow-cpu-jupyter
tensorflow-cpu-jupyter affected wolfi tensorflow-cpu-jupyter
tensorflow-gpu-jupyter affected chainguard tensorflow-gpu-jupyter
Upstream advisory

GHSA-36rr-ww3j-vrjv

GooglePoC exploitHIGH2025-09-19

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

Affected products

ProductStatusVendorPackageEcosystem
keras affected PyPI keras
Upstream advisory

ASB-A-392852041

GooglePoC exploitHIGH2025-09-01

ASB-A-392852041

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

MINI-82rx-fv6c-q65j

Open SourceCoalition ESS < 30%2025-09-04

MINI-82rx-fv6c-q65j

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

GHSA-4hqq-7q79-932p

Open SourceCoalition ESS < 30%CRITICAL2025-09-15

mcp-kubernetes-server has an OS Command Injection vulnerability

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

GHSA-4hqq-7q79-932p

Open SourceCoalition ESS < 30%CRITICAL2025-09-15

mcp-kubernetes-server has an OS Command Injection vulnerability

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

CVE-2025-59377

Open SourceCoalition ESS < 30%CRITICAL2025-09-15

feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE: this is unrelated to mcp-server-kubernetes and CVE-2025-53355.

CVEs:CVE-2025-59377

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected feisky
Upstream advisory

CVE-2025-59377

Open SourceCoalition ESS < 30%CRITICAL2025-09-15

mcp-kubernetes-server has an OS Command Injection vulnerability

CVEs:CVE-2025-59377

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

CVE-2025-59377

Open SourceCoalition ESS < 30%CRITICAL2025-09-15

mcp-kubernetes-server has an OS Command Injection vulnerability

CVEs:CVE-2025-59377

Affected products

ProductStatusVendorPackageEcosystem
mcp-kubernetes-server affected PyPI mcp-kubernetes-server
Upstream advisory

MINI-pvmv-34xm-fp77

Open SourceCoalition ESS < 30%2025-09-08

MINI-pvmv-34xm-fp77

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

OESA-2025-2318

Open SourceCoalition ESS < 30%CRITICAL2025-09-19

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:22.03-LTS-SP4 kubernetes
Upstream advisory

GO-2025-3915

Open SourceCoalition ESS < 30%2025-09-18

Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes

Affected products

ProductStatusVendorPackageEcosystem
argo-cd-2.13 affected chainguard argo-cd-2.13
argo-cd-2.14 affected chainguard argo-cd-2.14
argo-cd-fips-2.14 affected chainguard argo-cd-fips-2.14
argo-cd-fips-3.0 affected chainguard argo-cd-fips-3.0
argo-cd-fips-3.1 affected chainguard argo-cd-fips-3.1
argocd-image-updater-fips affected chainguard argocd-image-updater-fips
argo-rollouts affected chainguard argo-rollouts
argo-rollouts affected wolfi argo-rollouts
argo-rollouts-fips affected chainguard argo-rollouts-fips
aws-efs-csi-driver-fips affected chainguard aws-efs-csi-driver-fips
azure-container-networking affected chainguard azure-container-networking
azuredisk-csi-1.31 affected chainguard azuredisk-csi-1.31
azuredisk-csi-1.32 affected chainguard azuredisk-csi-1.32
azuredisk-csi-fips-1.31 affected chainguard azuredisk-csi-fips-1.31
azuredisk-csi-fips-1.32 affected chainguard azuredisk-csi-fips-1.32
azuredisk-csi-fips-1.33 affected chainguard azuredisk-csi-fips-1.33
azurefile-csi-1.31 affected chainguard azurefile-csi-1.31
azurefile-csi-1.32 affected chainguard azurefile-csi-1.32
azurefile-csi-fips-1.31 affected chainguard azurefile-csi-fips-1.31
azurefile-csi-fips-1.32 affected chainguard azurefile-csi-fips-1.32
azurefile-csi-fips-1.33 affected chainguard azurefile-csi-fips-1.33
blob-csi-1.23 affected chainguard blob-csi-1.23
blob-csi-1.24 affected chainguard blob-csi-1.24
blob-csi-fips-1.23 affected chainguard blob-csi-fips-1.23
blob-csi-fips-1.24 affected chainguard blob-csi-fips-1.24
blob-csi-fips-1.25 affected chainguard blob-csi-fips-1.25
blob-csi-fips-1.26 affected chainguard blob-csi-fips-1.26
cephcsi affected chainguard cephcsi
cephcsi-fips affected chainguard cephcsi-fips
cluster-autoscaler-1.31 affected chainguard cluster-autoscaler-1.31
cluster-autoscaler-fips-1.31 affected chainguard cluster-autoscaler-fips-1.31
cluster-autoscaler-fips-1.33 affected chainguard cluster-autoscaler-fips-1.33
docker-machine-driver-harvester affected chainguard docker-machine-driver-harvester
docker-machine-driver-harvester affected wolfi docker-machine-driver-harvester
eks-distro-1.31 affected chainguard eks-distro-1.31
eks-distro-1.32 affected chainguard eks-distro-1.32
eks-distro-fips-1.31 affected chainguard eks-distro-fips-1.31
eks-distro-fips-1.32 affected chainguard eks-distro-fips-1.32
emissary affected wolfi emissary
emissary affected chainguard emissary
ip-masq-agent affected wolfi ip-masq-agent
ip-masq-agent affected chainguard ip-masq-agent
k8ssandra-client affected chainguard k8ssandra-client
k8ssandra-client affected wolfi k8ssandra-client
k8ssandra-client-fips affected chainguard k8ssandra-client-fips
kapp affected chainguard kapp
kapp affected wolfi kapp
kapp-fips affected chainguard kapp-fips
kubernetes affected k8s.io k8s.io/kubernetes
kubernetes-1.32 affected wolfi kubernetes-1.32
kubernetes-1.32 affected chainguard kubernetes-1.32
kubernetes-csi-driver-hostpath affected wolfi kubernetes-csi-driver-hostpath
kubernetes-csi-driver-hostpath affected chainguard kubernetes-csi-driver-hostpath
kubernetes-csi-driver-nfs affected chainguard kubernetes-csi-driver-nfs
kubernetes-csi-driver-nfs affected wolfi kubernetes-csi-driver-nfs
kubernetes-csi-driver-nfs-fips affected chainguard kubernetes-csi-driver-nfs-fips
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
local-static-provisioner affected chainguard local-static-provisioner
local-static-provisioner affected wolfi local-static-provisioner
local-static-provisioner-fips affected chainguard local-static-provisioner-fips
longhorn-share-manager-1.8 affected chainguard longhorn-share-manager-1.8
longhorn-share-manager-fips-1.8 affected chainguard longhorn-share-manager-fips-1.8
mesosphere-vsphere-csi affected chainguard mesosphere-vsphere-csi
mesosphere-vsphere-csi affected wolfi mesosphere-vsphere-csi
mesosphere-vsphere-csi-fips affected chainguard mesosphere-vsphere-csi-fips
node-feature-discovery-0.16 affected chainguard node-feature-discovery-0.16
node-feature-discovery-fips-0.16 affected chainguard node-feature-discovery-fips-0.16
node-feature-discovery-fips-0.17 affected chainguard node-feature-discovery-fips-0.17
nodetaint affected chainguard nodetaint
nodetaint affected wolfi nodetaint
rancher-2.10 affected chainguard rancher-2.10
rancher-2.11 affected chainguard rancher-2.11
rancher-2.12 affected chainguard rancher-2.12
rancher-agent-2.10 affected chainguard rancher-agent-2.10
rancher-agent-2.11 affected chainguard rancher-agent-2.11
rancher-agent-2.12 affected chainguard rancher-agent-2.12
rancher-system-agent affected chainguard rancher-system-agent
rancher-system-agent affected wolfi rancher-system-agent
rancher-webhook-0.6 affected wolfi rancher-webhook-0.6
rancher-webhook-0.6 affected chainguard rancher-webhook-0.6
rancher-webhook-fips-0.6 affected chainguard rancher-webhook-fips-0.6
vcluster affected chainguard vcluster
vcluster affected wolfi vcluster
yunikorn-k8shim affected wolfi yunikorn-k8shim
yunikorn-k8shim affected chainguard yunikorn-k8shim
yunikorn-k8shim-fips affected chainguard yunikorn-k8shim-fips
Upstream advisory

OESA-2025-2284

Open SourceCoalition ESS < 30%CRITICAL2025-09-12

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:22.03-LTS-SP3 kubernetes
Upstream advisory

OESA-2025-2283

Open SourceCoalition ESS < 30%CRITICAL2025-09-12

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:20.03-LTS-SP4 kubernetes
Upstream advisory

OESA-2025-2282

Open SourceCoalition ESS < 30%CRITICAL2025-09-12

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:24.03-LTS-SP2 kubernetes
Upstream advisory

OESA-2025-2281

Open SourceCoalition ESS < 30%CRITICAL2025-09-12

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:24.03-LTS-SP1 kubernetes
Upstream advisory

OESA-2025-2280

Open SourceCoalition ESS < 30%CRITICAL2025-09-12

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:24.03-LTS kubernetes
Upstream advisory

GO-2025-3922

Open SourceCoalition ESS < 30%2025-09-17

Memory leaks when decoding a corrupted multiple LZMA archives in github.com/ulikunitz/xz

Affected products

ProductStatusVendorPackageEcosystem
atlantis-fips affected chainguard atlantis-fips
cg affected chainguard cg
chainctl affected chainguard chainctl
cloudbeat-9.0 affected chainguard cloudbeat-9.0
cloudbeat-fips-8.17 affected chainguard cloudbeat-fips-8.17
cloudbeat-fips-9.0 affected chainguard cloudbeat-fips-9.0
conftest-fips affected chainguard conftest-fips
crossplane-provider-terraform affected chainguard crossplane-provider-terraform
drone affected chainguard drone
drone-fips affected chainguard drone-fips
envoy-gateway affected wolfi envoy-gateway
envoy-gateway affected chainguard envoy-gateway
envoy-gateway-fips affected chainguard envoy-gateway-fips
filebrowser affected chainguard filebrowser
filebrowser affected wolfi filebrowser
gitea-fips affected chainguard gitea-fips
gitleaks affected chainguard gitleaks
gitleaks affected wolfi gitleaks
gitness affected wolfi gitness
gitness affected chainguard gitness
google-osconfig-agent affected chainguard google-osconfig-agent
gotenberg affected chainguard gotenberg
gptscript affected wolfi gptscript
gptscript affected chainguard gptscript
grafana-alloy affected chainguard grafana-alloy
grafana-alloy affected wolfi grafana-alloy
grafana-alloy-fips affected chainguard grafana-alloy-fips
grype-db affected chainguard grype-db
grype-fips affected chainguard grype-fips
guac affected wolfi guac
guac affected chainguard guac
k8s-image-swapper affected chainguard k8s-image-swapper
k8s-image-swapper-fips affected chainguard k8s-image-swapper-fips
k9s affected wolfi k9s
k9s affected chainguard k9s
k9s-fips affected chainguard k9s-fips
kubescape-operator affected chainguard kubescape-operator
kubescape-operator affected wolfi kubescape-operator
kubescape-operator-fips affected chainguard kubescape-operator-fips
mattermost-10.12 affected chainguard mattermost-10.12
mattermost-fips-10.10 affected chainguard mattermost-fips-10.10
mattermost-fips-10.11 affected chainguard mattermost-fips-10.11
mattermost-fips-10.12 affected chainguard mattermost-fips-10.12
mattermost-fips-10.5 affected chainguard mattermost-fips-10.5
mattermost-fips-10.9 affected chainguard mattermost-fips-10.9
nsc affected wolfi nsc
nsc affected chainguard nsc
nsc-fips affected chainguard nsc-fips
nuclei affected chainguard nuclei
nuclei affected wolfi nuclei
opentofu-1.10 affected chainguard opentofu-1.10
opentofu-1.10 affected wolfi opentofu-1.10
opentofu-1.8 affected chainguard opentofu-1.8
opentofu-1.9 affected chainguard opentofu-1.9
opentofu-1.9 affected wolfi opentofu-1.9
opentofu-fips-1.10 affected chainguard opentofu-fips-1.10
opentofu-fips-1.8 affected chainguard opentofu-fips-1.8
opentofu-fips-1.9 affected chainguard opentofu-fips-1.9
packer affected chainguard packer
packer-fips affected chainguard packer-fips
podman affected chainguard podman
podman affected wolfi podman
prometheus-podman-exporter affected chainguard prometheus-podman-exporter
prometheus-podman-exporter-fips affected chainguard prometheus-podman-exporter-fips
rancher-fleet affected chainguard rancher-fleet
rancher-fleet affected wolfi rancher-fleet
rancher-fleet-fips affected chainguard rancher-fleet-fips
regclient-fips affected chainguard regclient-fips
skopeo-fips affected chainguard skopeo-fips
steampipe affected chainguard steampipe
steampipe affected wolfi steampipe
syft-fips affected chainguard syft-fips
terraform affected wolfi terraform
terraform affected chainguard terraform
terraform-1.10 affected chainguard terraform-1.10
terraform-1.11 affected chainguard terraform-1.11
terraform-1.12 affected chainguard terraform-1.12
terraform-1.13 affected chainguard terraform-1.13
terraform-1.9 affected chainguard terraform-1.9
terraform-fips-1.11 affected chainguard terraform-fips-1.11
terraform-fips-1.13 affected chainguard terraform-fips-1.13
terragrunt affected chainguard terragrunt
terragrunt affected wolfi terragrunt
tflint affected wolfi tflint
tflint affected chainguard tflint
trivy affected wolfi trivy
trivy affected chainguard trivy
trivy-fips affected chainguard trivy-fips
trivy-operator affected wolfi trivy-operator
trivy-operator affected chainguard trivy-operator
trivy-operator-fips affected chainguard trivy-operator-fips
trufflehog affected chainguard trufflehog
trufflehog affected wolfi trufflehog
trufflehog-fips affected chainguard trufflehog-fips
ulikunitz/xz affected github.com github.com/ulikunitz/xz
undock affected chainguard undock
undock affected wolfi undock
vault-1.16 affected chainguard vault-1.16
vcluster affected chainguard vcluster
vcluster affected wolfi vcluster
vcluster-fips affected chainguard vcluster-fips
xeol affected wolfi xeol
xeol affected chainguard xeol
xeol-fips affected chainguard xeol-fips
zarf affected chainguard zarf
zarf affected wolfi zarf
zot affected chainguard zot
zot affected wolfi zot
Upstream advisory

GO-2025-3942

Open SourceCoalition ESS < 30%2025-09-17

CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion in github.com/coredns/coredns

Affected products

ProductStatusVendorPackageEcosystem
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
cloudflared-fips affected chainguard cloudflared-fips
coredns/coredns affected github.com github.com/coredns/coredns
eks-distro-1.29 affected chainguard eks-distro-1.29
eks-distro-1.30 affected chainguard eks-distro-1.30
eks-distro-1.31 affected chainguard eks-distro-1.31
eks-distro-1.32 affected chainguard eks-distro-1.32
eks-distro-1.33 affected chainguard eks-distro-1.33
eks-distro-1.34 affected chainguard eks-distro-1.34
eks-distro-fips-1.29 affected chainguard eks-distro-fips-1.29
eks-distro-fips-1.30 affected chainguard eks-distro-fips-1.30
eks-distro-fips-1.31 affected chainguard eks-distro-fips-1.31
eks-distro-fips-1.32 affected chainguard eks-distro-fips-1.32
eks-distro-fips-1.33 affected chainguard eks-distro-fips-1.33
eks-distro-fips-1.34 affected chainguard eks-distro-fips-1.34
juicefs-1.2 affected chainguard juicefs-1.2
juicefs-1.3 affected chainguard juicefs-1.3
juicefs-1.3 affected wolfi juicefs-1.3
k8s_gateway affected wolfi k8s_gateway
k8s_gateway affected chainguard k8s_gateway
k8s_gateway-fips affected chainguard k8s_gateway-fips
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
Upstream advisory

GHSA-93mf-426m-g6x9

Open SourceCoalition ESS < 30%CRITICAL2025-09-09

CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion

Affected products

ProductStatusVendorPackageEcosystem
cloudflared affected chainguard cloudflared
cloudflared affected wolfi cloudflared
cloudflared-fips affected chainguard cloudflared-fips
coredns/coredns affected github.com github.com/coredns/coredns
eks-distro-1.29 affected chainguard eks-distro-1.29
eks-distro-1.30 affected chainguard eks-distro-1.30
eks-distro-1.31 affected chainguard eks-distro-1.31
eks-distro-1.32 affected chainguard eks-distro-1.32
eks-distro-1.33 affected chainguard eks-distro-1.33
eks-distro-1.34 affected chainguard eks-distro-1.34
eks-distro-fips-1.29 affected chainguard eks-distro-fips-1.29
eks-distro-fips-1.30 affected chainguard eks-distro-fips-1.30
eks-distro-fips-1.31 affected chainguard eks-distro-fips-1.31
eks-distro-fips-1.32 affected chainguard eks-distro-fips-1.32
eks-distro-fips-1.33 affected chainguard eks-distro-fips-1.33
eks-distro-fips-1.34 affected chainguard eks-distro-fips-1.34
juicefs-1.2 affected chainguard juicefs-1.2
juicefs-1.3 affected chainguard juicefs-1.3
juicefs-1.3 affected wolfi juicefs-1.3
k8s_gateway affected chainguard k8s_gateway
k8s_gateway affected wolfi k8s_gateway
k8s_gateway-fips affected chainguard k8s_gateway-fips
kubernetes-dns-node-cache affected chainguard kubernetes-dns-node-cache
kubernetes-dns-node-cache affected wolfi kubernetes-dns-node-cache
kubernetes-dns-node-cache-fips affected chainguard kubernetes-dns-node-cache-fips
Upstream advisory

GHSA-93mf-426m-g6x9

GoogleCoalition ESS < 30%CRITICAL2025-09-09

CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion

Affected products

ProductStatusVendorPackageEcosystem
coredns/coredns affected github.com github.com/coredns/coredns
Upstream advisory

ECHO-4e0e-8b9e-064d

Open SourceCoalition ESS < 30%2025-09-15

ECHO-4e0e-8b9e-064d

Affected products

ProductStatusVendorPackageEcosystem
golang-1.23 affected Echo golang-1.23
golang-1.24 affected Echo golang-1.24
Upstream advisory

ASB-A-429908202

GoogleCoalition ESS < 30%2025-09-01

ASB-A-429908202

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-429908205

GoogleCoalition ESS < 30%2025-09-01

ASB-A-429908205

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-429908203

GoogleCoalition ESS < 30%2025-09-01

ASB-A-429908203

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-48534

Open SourceCoalition ESS < 30%HIGH2025-09-02

In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed f...

CVEs:CVE-2025-48534

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36894

Open SourceCoalition ESS < 30%HIGH2025-09-03

In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-397744732

GoogleCoalition ESS < 30%MEDIUM2025-09-01

PUB-A-397744732

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-36896

Open SourceCoalition ESS < 30%CRITICAL2025-09-03

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

CVEs:CVE-2025-36896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36904

Open SourceCoalition ESS < 30%CRITICAL2025-09-03

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

CVEs:CVE-2025-36904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-394765106

GoogleCoalition ESS < 30%CRITICAL2025-09-01

PUB-A-394765106

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-396458384

GoogleCoalition ESS < 30%CRITICAL2025-09-01

PUB-A-396458384

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-vvfj-2jqx-52jm

Open SourceCoalition ESS < 30%HIGH2025-09-26

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

Affected products

ProductStatusVendorPackageEcosystem
jupyterlab affected PyPI jupyterlab
jupyterlab affected PyPI jupyterlab
kubeflow-pipelines-visualization-server affected chainguard kubeflow-pipelines-visualization-server
kubeflow-pipelines-visualization-server affected wolfi kubeflow-pipelines-visualization-server
tensorflow-cpu-jupyter affected chainguard tensorflow-cpu-jupyter
tensorflow-cpu-jupyter affected wolfi tensorflow-cpu-jupyter
tensorflow-gpu-jupyter affected chainguard tensorflow-gpu-jupyter
Upstream advisory

GHSA-vvfj-2jqx-52jm

GoogleCoalition ESS < 30%HIGH2025-09-26

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

Affected products

ProductStatusVendorPackageEcosystem
jupyterlab affected PyPI jupyterlab
Upstream advisory

PUB-A-392596931

GoogleCoalition ESS < 30%2025-09-01

PUB-A-392596931

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ECHO-cf03-9570-1659

Open SourceCoalition ESS < 30%2025-09-15

ECHO-cf03-9570-1659

Affected products

ProductStatusVendorPackageEcosystem
golang-1.24 affected Echo golang-1.24
Upstream advisory

CVE-2025-48581

Open SourceCoalition ESS < 30%HIGH2025-09-02

In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2025-48581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Android affected Google
Upstream advisory

PUB-A-384692949

GoogleCoalition ESS < 30%2025-09-01

PUB-A-384692949

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-416527351

GoogleCoalition ESS < 30%2025-09-01

ASB-A-416527351

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-396454072

GoogleCoalition ESS < 30%2025-09-01

PUB-A-396454072

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-48535

Open SourceCoalition ESS < 30%HIGH2025-09-02

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with ...

CVEs:CVE-2025-48535

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-396463432

GoogleCoalition ESS < 30%2025-09-01

PUB-A-396463432

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-383348101

GoogleCoalition ESS < 30%2025-09-01

ASB-A-383348101

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-416682620

GoogleCoalition ESS < 30%2025-09-01

ASB-A-416682620

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-32327

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2025-32327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-0089

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-0089

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48548

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User i...

CVEs:CVE-2025-48548

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48527

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2025-48527

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48552

Open SourceCoalition ESS < 30%HIGH2025-09-02

In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...

CVEs:CVE-2025-48552

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48544

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-48544

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48550

Open SourceCoalition ESS < 30%HIGH2025-09-02

In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2025-48550

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48531

Open SourceCoalition ESS < 30%HIGH2025-09-02

In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2025-48531

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26464

Open SourceCoalition ESS < 30%HIGH2025-09-02

In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2025-26464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48522

Open SourceCoalition ESS < 30%HIGH2025-09-02

In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2025-48522

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48540

Open SourceCoalition ESS < 30%HIGH2025-09-02

In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2025-48540

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32323

Open SourceCoalition ESS < 30%HIGH2025-09-02

In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to improper input validation. This could lead to local escalation of privilege with no additional executi...

CVEs:CVE-2025-32323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32349

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-32349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48545

Open SourceCoalition ESS < 30%HIGH2025-09-02

In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not n...

CVEs:CVE-2025-48545

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36899

Open SourceCoalition ESS < 30%HIGH2025-09-03

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48526

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional execut...

CVEs:CVE-2025-48526

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48528

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-48528

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48537

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2025-48537

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-421029630

GoogleCoalition ESS < 30%NONE2025-09-01

PUB-A-421029630

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-32333

Open SourceCoalition ESS < 30%HIGH2025-09-02

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2025-32333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26419

Open SourceCoalition ESS < 30%LOW2025-09-04

In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2025-26419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36908

Open SourceCoalition ESS < 30%HIGH2025-09-03

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2025-36908

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32345

Open SourceCoalition ESS < 30%HIGH2025-09-02

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privi...

CVEs:CVE-2025-32345

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48523

Open SourceCoalition ESS < 30%HIGH2025-09-02

In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...

CVEs:CVE-2025-48523

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-419014045

GoogleCoalition ESS < 30%HIGH2025-09-01

PUB-A-419014045

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-26431

Open SourceCoalition ESS < 30%HIGH2025-09-04

In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee...

CVEs:CVE-2025-26431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32332

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-32332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48556

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...

CVEs:CVE-2025-48556

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-319147124

GoogleCoalition ESS < 30%HIGH2025-09-01

ASB-A-319147124

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-48541

Open SourceCoalition ESS < 30%HIGH2025-09-02

In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2025-48541

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48562

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2025-48562

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48563

Open SourceCoalition ESS < 30%HIGH2025-09-02

In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2025-48563

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26439

Open SourceCoalition ESS < 30%HIGH2025-09-04

In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead of the system component due to a logic error in the code. This could lead to local escalation of privilege with no...

CVEs:CVE-2025-26439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36902

Open SourceCoalition ESS < 30%HIGH2025-09-03

In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2025-36902

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32347

Open SourceCoalition ESS < 30%HIGH2025-09-02

In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2025-32347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32350

Open SourceCoalition ESS < 30%HIGH2025-09-02

In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User ...

CVEs:CVE-2025-32350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-379878759

GoogleCoalition ESS < 30%HIGH2025-09-01

PUB-A-379878759

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-49731

Open SourceCoalition ESS < 30%MEDIUM2025-09-04

In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new Pixel Watch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileg...

CVEs:CVE-2024-49731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36907

Open SourceCoalition ESS < 30%HIGH2025-09-03

In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege via USB fastboot, after a bootloader unlock, with no additional execution pr...

CVEs:CVE-2025-36907

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48529

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2025-48529

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-418774137

GoogleCoalition ESS < 30%HIGH2025-09-01

PUB-A-418774137

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-36900

Open SourceCoalition ESS < 30%HIGH2025-09-03

In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-36900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-36906

Open SourceCoalition ESS < 30%HIGH2025-09-03

In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2025-36906

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48538

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. U...

CVEs:CVE-2025-48538

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48554

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction ...

CVEs:CVE-2025-48554

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-289810779

GoogleCoalition ESS < 30%HIGH2025-09-01

PUB-A-289810779

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-419541948

GoogleCoalition ESS < 30%HIGH2025-09-01

PUB-A-419541948

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-32322

Open SourceCoalition ESS < 30%HIGH2025-09-04

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recording capabilities due to improper input validation. This could lead to local escalation of privilege with...

CVEs:CVE-2025-32322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-40664

Open SourceCoalition ESS < 30%MEDIUM2025-09-04

In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. ...

CVEs:CVE-2024-40664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-0076

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2025-0076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48524

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-48524

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48532

Open SourceCoalition ESS < 30%HIGH2025-09-02

In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2025-48532

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-32346

Open SourceCoalition ESS < 30%HIGH2025-09-02

In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2025-32346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-22414

Open SourceCoalition ESS < 30%HIGH2025-09-04

In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2025-22414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-22415

Open SourceCoalition ESS < 30%MEDIUM2025-09-04

In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-22415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48542

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2025-48542

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48558

Open SourceCoalition ESS < 30%HIGH2025-09-02

In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app due to Implicit intent hijacking. This could lead to local escalation of privilege with no additional execution privileges needed. U...

CVEs:CVE-2025-48558

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-48560

Open SourceCoalition ESS < 30%MEDIUM2025-09-02

In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-48560

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MINI-mrq9-4cwf-x8w8

Open SourceEPSS <= 49%2025-09-08

MINI-mrq9-4cwf-x8w8

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

MINI-v829-phv8-wpw2

Open SourceEPSS <= 49%2025-09-08

MINI-v829-phv8-wpw2

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.34 affected MinimOS kube-apiserver-fips-1.34
kube-apiserver-fips-1.34-compat affected MinimOS kube-apiserver-fips-1.34-compat
kube-controller-manager-fips-1.34 affected MinimOS kube-controller-manager-fips-1.34
kube-controller-manager-fips-1.34-compat affected MinimOS kube-controller-manager-fips-1.34-compat
kubectl-fips-1.34 affected MinimOS kubectl-fips-1.34
kubectl-fips-1.34-compat affected MinimOS kubectl-fips-1.34-compat
kube-proxy-fips-1.34 affected MinimOS kube-proxy-fips-1.34
kube-proxy-fips-1.34-compat affected MinimOS kube-proxy-fips-1.34-compat
kubernetes-fips-1.34 affected MinimOS kubernetes-fips-1.34
kube-scheduler-fips-1.34 affected MinimOS kube-scheduler-fips-1.34
kube-scheduler-fips-1.34-compat affected MinimOS kube-scheduler-fips-1.34-compat
Upstream advisory

MINI-9fwj-xccx-vq48

Open SourceEPSS <= 49%2025-09-08

MINI-9fwj-xccx-vq48

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

MINI-338h-vwfx-f4qq

Open SourceEPSS <= 49%2025-09-08

MINI-338h-vwfx-f4qq

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.33 affected MinimOS kube-apiserver-fips-1.33
kube-apiserver-fips-1.33-compat affected MinimOS kube-apiserver-fips-1.33-compat
kube-controller-manager-fips-1.33 affected MinimOS kube-controller-manager-fips-1.33
kube-controller-manager-fips-1.33-compat affected MinimOS kube-controller-manager-fips-1.33-compat
kubectl-fips-1.33 affected MinimOS kubectl-fips-1.33
kubectl-fips-1.33-compat affected MinimOS kubectl-fips-1.33-compat
kubelet-fips-1.33 affected MinimOS kubelet-fips-1.33
kubelet-fips-1.33-compat affected MinimOS kubelet-fips-1.33-compat
kube-proxy-fips-1.33 affected MinimOS kube-proxy-fips-1.33
kube-proxy-fips-1.33-compat affected MinimOS kube-proxy-fips-1.33-compat
kubernetes-fips-1.33 affected MinimOS kubernetes-fips-1.33
kube-scheduler-fips-1.33 affected MinimOS kube-scheduler-fips-1.33
kube-scheduler-fips-1.33-compat affected MinimOS kube-scheduler-fips-1.33-compat
Upstream advisory

MINI-chh6-9r7f-cr93

Open SourceEPSS <= 49%2025-09-04

MINI-chh6-9r7f-cr93

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.34 affected MinimOS kube-apiserver-1.34
kube-apiserver-1.34-compat affected MinimOS kube-apiserver-1.34-compat
kube-controller-manager-1.34 affected MinimOS kube-controller-manager-1.34
kube-controller-manager-1.34-compat affected MinimOS kube-controller-manager-1.34-compat
kubectl-1.34 affected MinimOS kubectl-1.34
kubectl-1.34-advanced-compat affected MinimOS kubectl-1.34-advanced-compat
kubectl-1.34-compat affected MinimOS kubectl-1.34-compat
kube-proxy-1.34 affected MinimOS kube-proxy-1.34
kube-proxy-1.34-compat affected MinimOS kube-proxy-1.34-compat
kubernetes-1.34 affected MinimOS kubernetes-1.34
kube-scheduler-1.34 affected MinimOS kube-scheduler-1.34
kube-scheduler-1.34-compat affected MinimOS kube-scheduler-1.34-compat
Upstream advisory

MINI-xmvv-gv73-3gx7

Open SourceEPSS <= 49%2025-09-08

MINI-xmvv-gv73-3gx7

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

MINI-q4xh-cpcc-56pg

Open SourceEPSS <= 49%2025-09-08

MINI-q4xh-cpcc-56pg

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.34 affected MinimOS kube-apiserver-fips-1.34
kube-apiserver-fips-1.34-compat affected MinimOS kube-apiserver-fips-1.34-compat
kube-controller-manager-fips-1.34 affected MinimOS kube-controller-manager-fips-1.34
kube-controller-manager-fips-1.34-compat affected MinimOS kube-controller-manager-fips-1.34-compat
kubectl-fips-1.34 affected MinimOS kubectl-fips-1.34
kubectl-fips-1.34-compat affected MinimOS kubectl-fips-1.34-compat
kube-proxy-fips-1.34 affected MinimOS kube-proxy-fips-1.34
kube-proxy-fips-1.34-compat affected MinimOS kube-proxy-fips-1.34-compat
kubernetes-fips-1.34 affected MinimOS kubernetes-fips-1.34
kube-scheduler-fips-1.34 affected MinimOS kube-scheduler-fips-1.34
kube-scheduler-fips-1.34-compat affected MinimOS kube-scheduler-fips-1.34-compat
Upstream advisory

MINI-c55g-f72m-hx82

Open SourceEPSS <= 49%2025-09-08

MINI-c55g-f72m-hx82

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.33 affected MinimOS kube-apiserver-fips-1.33
kube-apiserver-fips-1.33-compat affected MinimOS kube-apiserver-fips-1.33-compat
kube-controller-manager-fips-1.33 affected MinimOS kube-controller-manager-fips-1.33
kube-controller-manager-fips-1.33-compat affected MinimOS kube-controller-manager-fips-1.33-compat
kubectl-fips-1.33 affected MinimOS kubectl-fips-1.33
kubectl-fips-1.33-compat affected MinimOS kubectl-fips-1.33-compat
kube-proxy-fips-1.33 affected MinimOS kube-proxy-fips-1.33
kube-proxy-fips-1.33-compat affected MinimOS kube-proxy-fips-1.33-compat
kubernetes-fips-1.33 affected MinimOS kubernetes-fips-1.33
kube-scheduler-fips-1.33 affected MinimOS kube-scheduler-fips-1.33
kube-scheduler-fips-1.33-compat affected MinimOS kube-scheduler-fips-1.33-compat
Upstream advisory

MINI-4v93-5qqj-xj55

Open SourceEPSS <= 49%2025-09-08

MINI-4v93-5qqj-xj55

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

MINI-cvjg-w5f9-8qhw

Open SourceEPSS <= 49%2025-09-04

MINI-cvjg-w5f9-8qhw

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.34 affected MinimOS kube-apiserver-1.34
kube-apiserver-1.34-compat affected MinimOS kube-apiserver-1.34-compat
kube-controller-manager-1.34 affected MinimOS kube-controller-manager-1.34
kube-controller-manager-1.34-compat affected MinimOS kube-controller-manager-1.34-compat
kubectl-1.34 affected MinimOS kubectl-1.34
kubectl-1.34-advanced-compat affected MinimOS kubectl-1.34-advanced-compat
kubectl-1.34-compat affected MinimOS kubectl-1.34-compat
kube-proxy-1.34 affected MinimOS kube-proxy-1.34
kube-proxy-1.34-compat affected MinimOS kube-proxy-1.34-compat
kubernetes-1.34 affected MinimOS kubernetes-1.34
kube-scheduler-1.34 affected MinimOS kube-scheduler-1.34
kube-scheduler-1.34-compat affected MinimOS kube-scheduler-1.34-compat
Upstream advisory

ECHO-9c50-798a-c0af

GoogleEPSS <= 49%2025-09-15

ECHO-9c50-798a-c0af

Affected products

ProductStatusVendorPackageEcosystem
google-perftools affected Echo google-perftools
Upstream advisory

MINI-79g4-crww-xvmf

Open SourceEPSS <= 49%2025-09-08

MINI-79g4-crww-xvmf

Affected products

ProductStatusVendorPackageEcosystem
kubectl-fips-1.31 affected MinimOS kubectl-fips-1.31
kubernetes-fips-1.31 affected MinimOS kubernetes-fips-1.31
Upstream advisory

MINI-32hf-q5hx-xrw6

Open SourceEPSS <= 49%2025-09-08

MINI-32hf-q5hx-xrw6

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.33 affected MinimOS kube-apiserver-fips-1.33
kube-apiserver-fips-1.33-compat affected MinimOS kube-apiserver-fips-1.33-compat
kube-controller-manager-fips-1.33 affected MinimOS kube-controller-manager-fips-1.33
kube-controller-manager-fips-1.33-compat affected MinimOS kube-controller-manager-fips-1.33-compat
kubectl-fips-1.33 affected MinimOS kubectl-fips-1.33
kubectl-fips-1.33-compat affected MinimOS kubectl-fips-1.33-compat
kubelet-fips-1.33 affected MinimOS kubelet-fips-1.33
kubelet-fips-1.33-compat affected MinimOS kubelet-fips-1.33-compat
kube-proxy-fips-1.33 affected MinimOS kube-proxy-fips-1.33
kube-proxy-fips-1.33-compat affected MinimOS kube-proxy-fips-1.33-compat
kubernetes-fips-1.33 affected MinimOS kubernetes-fips-1.33
kube-scheduler-fips-1.33 affected MinimOS kube-scheduler-fips-1.33
kube-scheduler-fips-1.33-compat affected MinimOS kube-scheduler-fips-1.33-compat
Upstream advisory

MINI-fwrq-q638-jjgh

Open SourceEPSS <= 49%2025-09-08

MINI-fwrq-q638-jjgh

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-fips-1.32 affected MinimOS kube-apiserver-fips-1.32
kube-controller-manager-fips-1.32 affected MinimOS kube-controller-manager-fips-1.32
kubectl-fips-1.32 affected MinimOS kubectl-fips-1.32
kube-proxy-fips-1.32 affected MinimOS kube-proxy-fips-1.32
kubernetes-fips-1.32 affected MinimOS kubernetes-fips-1.32
kube-scheduler-fips-1.32 affected MinimOS kube-scheduler-fips-1.32
Upstream advisory

MINI-xxch-9vj6-g8vp

Open SourceEPSS <= 49%2025-09-04

MINI-xxch-9vj6-g8vp

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.34 affected MinimOS kube-apiserver-1.34
kube-apiserver-1.34-compat affected MinimOS kube-apiserver-1.34-compat
kube-controller-manager-1.34 affected MinimOS kube-controller-manager-1.34
kube-controller-manager-1.34-compat affected MinimOS kube-controller-manager-1.34-compat
kubectl-1.34 affected MinimOS kubectl-1.34
kubectl-1.34-advanced-compat affected MinimOS kubectl-1.34-advanced-compat
kubectl-1.34-compat affected MinimOS kubectl-1.34-compat
kube-proxy-1.34 affected MinimOS kube-proxy-1.34
kube-proxy-1.34-compat affected MinimOS kube-proxy-1.34-compat
kubernetes-1.34 affected MinimOS kubernetes-1.34
kube-scheduler-1.34 affected MinimOS kube-scheduler-1.34
kube-scheduler-1.34-compat affected MinimOS kube-scheduler-1.34-compat
Upstream advisory

RUSTSEC-2025-0066

GoogleAll remaining2025-09-09

The `google-apis-rs` project is now unmaintained

Affected products

ProductStatusVendorPackageEcosystem
google-apis-common affected crates.io google-apis-common
Upstream advisory

GHSA-h9m7-rmhq-pfgr

Open SourceAll remaining2025-09-08

Malware in proto-tinker-wc

Affected products

ProductStatusVendorPackageEcosystem
proto-tinker-wc affected npm proto-tinker-wc
Upstream advisory

PUB-A-377489833

GoogleAll remainingNONE2025-09-01

PUB-A-377489833

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-394583415

GoogleAll remainingHIGH2025-09-01

PUB-A-394583415

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-407082766

GoogleAll remainingHIGH2025-09-01

PUB-A-407082766

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-412418039

GoogleAll remainingHIGH2025-09-01

PUB-A-412418039

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.