docker.io/1panel/cordys-crm:v1.7.1 linux/amd64

docker.io/1panel/cordys-crm:v1.7.1 - Trivy安全扫描结果 扫描时间: 2026-06-29 15:48
全部漏洞信息
低危漏洞:44 中危漏洞:126 高危漏洞:106 严重漏洞:20

系统OS: alpine 3.21.4 扫描引擎: Trivy 扫描时间: 2026-06-29 15:48

docker.io/1panel/cordys-crm:v1.7.1 (alpine 3.21.4) (alpine)
低危漏洞:35 中危漏洞:73 高危漏洞:72 严重漏洞:15
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
gnutls CVE-2026-33845 严重 3.8.8-r0 3.8.13-r0 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33845

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-30 18:16 修改: 2026-06-26 08:16

gnutls CVE-2026-42010 严重 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Authentication Bypass via NUL Character in Username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42010

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-07 12:16 修改: 2026-06-26 11:16

libcrypto3 CVE-2026-31789 严重 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

libssl3 CVE-2026-31789 严重 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

mariadb CVE-2026-44170 严重 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44170

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 13:20

mariadb CVE-2026-44172 严重 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44172

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mariadb-client CVE-2026-44170 严重 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44170

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 13:20

mariadb-client CVE-2026-44172 严重 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44172

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mariadb-common CVE-2026-44170 严重 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44170

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 13:20

mariadb-common CVE-2026-44172 严重 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44172

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mysql CVE-2026-44170 严重 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44170

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 13:20

mysql CVE-2026-44172 严重 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44172

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mysql-client CVE-2026-44170 严重 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44170

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 13:20

mysql-client CVE-2026-44172 严重 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44172

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

openssl CVE-2026-31789 严重 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

gpg-agent CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

gpg-wks-server CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

gpgsm CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

gpgv CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

gnupg-gpgconf CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

libcrypto3 CVE-2025-15467 高危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15467

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 08:37

libcrypto3 CVE-2025-69421 高危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69421

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libcrypto3 CVE-2026-28387 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libcrypto3 CVE-2026-28388 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libcrypto3 CVE-2026-28389 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libcrypto3 CVE-2026-28390 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libexpat CVE-2025-59375 高危 2.7.0-r0 2.7.2-r0 firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59375

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-09-15 03:15 修改: 2026-06-17 09:46

libexpat CVE-2026-25210 高危 2.7.0-r0 2.7.4-r0 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25210

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-30 07:16 修改: 2026-06-17 10:24

libexpat CVE-2026-45186 高危 2.7.0-r0 2.8.1-r0 libexpat: denial of service via crafted XML input

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45186

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-10 07:16 修改: 2026-06-17 10:51

libpng CVE-2025-64720 高危 1.6.47-r0 1.6.53-r0 libpng: LIBPNG buffer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-64720

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-11-25 00:15 修改: 2026-06-17 09:55

libpng CVE-2025-65018 高危 1.6.47-r0 1.6.53-r0 libpng: LIBPNG heap buffer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-65018

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-11-25 00:15 修改: 2026-06-17 09:55

libpng CVE-2025-66293 高危 1.6.47-r0 1.6.53-r0 libpng: LIBPNG out-of-bounds read in png_image_read_composite

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66293

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-03 21:15 修改: 2026-06-17 09:56

libpng CVE-2026-22695 高危 1.6.47-r0 1.6.54-r0 libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22695

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-12 23:15 修改: 2026-06-17 10:20

libpng CVE-2026-22801 高危 1.6.47-r0 1.6.54-r0 libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22801

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-12 23:15 修改: 2026-06-17 10:20

libpng CVE-2026-25646 高危 1.6.47-r0 1.6.55-r0 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25646

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-02-10 18:16 修改: 2026-06-17 10:25

gnupg-keyboxd CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

libssl3 CVE-2025-15467 高危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15467

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 08:37

libssl3 CVE-2025-69421 高危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69421

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libssl3 CVE-2026-28387 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-28388 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-28389 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libssl3 CVE-2026-28390 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

libxml2 CVE-2026-6732 高危 2.13.9-r0 2.13.9-r1 libxml2: libxml2: Denial of Service via crafted XSD-validated document

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6732

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-04-23 23:16 修改: 2026-06-17 11:01

gnupg-utils CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

gnupg-wks-client CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

mariadb CVE-2026-44168 高危 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44168

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-18 15:19

mariadb CVE-2026-44171 高危 11.4.8-r0 11.4.11-r0 mariadb: mbstream: Unauthorized file creation via path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44171

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mariadb CVE-2026-48163 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via improper parameter validation during SST

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48163

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

mariadb CVE-2026-48165 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48165

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

gnupg CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

gnupg-dirmngr CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

mariadb-client CVE-2026-44168 高危 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44168

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-18 15:19

mariadb-client CVE-2026-44171 高危 11.4.8-r0 11.4.11-r0 mariadb: mbstream: Unauthorized file creation via path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44171

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mariadb-client CVE-2026-48163 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via improper parameter validation during SST

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48163

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

mariadb-client CVE-2026-48165 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48165

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

gnutls CVE-2025-32988 高危 3.8.8-r0 3.8.12-r0 gnutls: Vulnerability in GnuTLS otherName SAN export

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32988

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-07-10 08:15 修改: 2026-06-25 05:16

gnutls CVE-2025-32990 高危 3.8.8-r0 3.8.12-r0 gnutls: Vulnerability in GnuTLS certtool template parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32990

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-07-10 10:15 修改: 2026-06-25 05:16

mariadb-common CVE-2026-44168 高危 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44168

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-18 15:19

mariadb-common CVE-2026-44171 高危 11.4.8-r0 11.4.11-r0 mariadb: mbstream: Unauthorized file creation via path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44171

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mariadb-common CVE-2026-48163 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via improper parameter validation during SST

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48163

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

mariadb-common CVE-2026-48165 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48165

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

musl CVE-2026-40200 高危 1.2.5-r9 1.2.5-r11 musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40200

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-10 17:17 修改: 2026-06-17 10:44

musl-utils CVE-2026-40200 高危 1.2.5-r9 1.2.5-r11 musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40200

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-10 17:17 修改: 2026-06-17 10:44

gnutls CVE-2026-1584 高危 3.8.8-r0 3.8.12-r0 gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1584

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-09 18:16 修改: 2026-06-17 10:16

gnutls CVE-2026-33846 高危 3.8.8-r0 3.8.13-r0 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33846

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-04 10:15 修改: 2026-06-26 08:16

mysql CVE-2026-44168 高危 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44168

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-18 15:19

mysql CVE-2026-44171 高危 11.4.8-r0 11.4.11-r0 mariadb: mbstream: Unauthorized file creation via path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44171

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mysql CVE-2026-48163 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via improper parameter validation during SST

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48163

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

mysql CVE-2026-48165 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48165

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

gnutls CVE-2026-3833 高危 3.8.8-r0 3.8.13-r0 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3833

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-30 18:16 修改: 2026-06-26 08:16

gnutls CVE-2026-42009 高危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42009

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-18 13:16 修改: 2026-06-26 08:16

mysql-client CVE-2026-44168 高危 11.4.8-r0 11.4.11-r0 mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44168

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-18 15:19

mysql-client CVE-2026-44171 高危 11.4.8-r0 11.4.11-r0 mariadb: mbstream: Unauthorized file creation via path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44171

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

mysql-client CVE-2026-48163 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via improper parameter validation during SST

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48163

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

mysql-client CVE-2026-48165 高危 11.4.8-r0 11.4.12-r0 mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48165

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:54

nghttp2-libs CVE-2026-27135 高危 1.64.0-r0 1.68.1 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27135

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-03-18 18:16 修改: 2026-06-17 10:26

gpg CVE-2025-68973 高危 2.4.7-r0 2.4.9-r0 GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68973

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-28 17:16 修改: 2026-06-17 09:59

openssl CVE-2025-15467 高危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15467

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 08:37

openssl CVE-2025-69421 高危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69421

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2026-28387 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-28388 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-28389 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

openssl CVE-2026-28390 高危 3.3.4-r0 3.3.7-r0 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:28

p11-kit CVE-2026-2100 高危 0.25.5-r2 0.26.2-r0 p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2100

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-26 21:17 修改: 2026-06-22 20:16

p11-kit-trust CVE-2026-2100 高危 0.25.5-r2 0.26.2-r0 p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2100

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-26 21:17 修改: 2026-06-22 20:16

sqlite-libs CVE-2025-6965 高危 3.48.0-r2 3.48.0-r3 sqlite: Integer Truncation in SQLite

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6965

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-07-15 14:15 修改: 2026-06-26 16:36

zlib CVE-2026-22184 高危 1.3.1-r2 1.3.2-r0 zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22184

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-07 21:16 修改: 2026-06-17 10:19

libssl3 CVE-2025-9230 中危 3.3.4-r0 3.3.5-r0 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9230

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

libssl3 CVE-2025-9231 中危 3.3.4-r0 3.3.5-r0 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9231

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

libssl3 CVE-2026-31790 中危 3.3.4-r0 3.3.7-r0 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

gpg-wks-server CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

curl CVE-2025-5399 中危 8.12.1-r1 8.14.1-r0 curl: libcurl: WebSocket endless loop

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5399

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-06-07 08:15 修改: 2026-06-17 09:47

gpgsm CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

gnupg-wks-client CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

gpgv CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

curl CVE-2025-9086 中危 8.12.1-r1 8.14.1-r2 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-09-12 06:15 修改: 2026-06-17 10:08

busybox CVE-2024-58251 中危 1.37.0-r12 1.37.0-r14 In netstat in BusyBox through 1.37.0, local users can launch of networ ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-58251

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-04-23 18:16 修改: 2026-06-17 08:14

mariadb CVE-2026-3494 中危 11.4.8-r0 11.4.10-r0 MariaDB: MariaDB: Information disclosure due to unlogged SQL statements with comments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3494

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-03-03 20:16 修改: 2026-06-17 10:43

mariadb CVE-2026-44169 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44169

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 16:24

mariadb CVE-2026-44173 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44173

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

gnupg CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

busybox-binsh CVE-2024-58251 中危 1.37.0-r12 1.37.0-r14 In netstat in BusyBox through 1.37.0, local users can launch of networ ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-58251

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-04-23 18:16 修改: 2026-06-17 08:14

gnupg-dirmngr CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

c-ares CVE-2025-62408 中危 1.34.5-r0 1.34.6-r0 c-ares: c-ares: Denial of Service due to query termination after maximum attempts

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-62408

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-12-08 22:15 修改: 2026-06-17 09:51

gnupg-gpgconf CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

libcrypto3 CVE-2025-69419 中危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69419

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

mariadb-client CVE-2026-3494 中危 11.4.8-r0 11.4.10-r0 MariaDB: MariaDB: Information disclosure due to unlogged SQL statements with comments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3494

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-03-03 20:16 修改: 2026-06-17 10:43

mariadb-client CVE-2026-44169 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44169

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 16:24

mariadb-client CVE-2026-44173 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44173

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

libcrypto3 CVE-2025-9230 中危 3.3.4-r0 3.3.5-r0 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9230

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

libcrypto3 CVE-2025-9231 中危 3.3.4-r0 3.3.5-r0 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9231

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

libcrypto3 CVE-2026-31790 中危 3.3.4-r0 3.3.7-r0 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

libcurl CVE-2025-4947 中危 8.12.1-r1 8.14.0-r0 libcurl: curl: QUIC certificate check skip with wolfSSL

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4947

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-05-28 07:15 修改: 2026-06-17 09:34

libcurl CVE-2025-5025 中危 8.12.1-r1 8.14.0-r0 curl: libcurl: QUIC Certificate Pinning Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5025

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-05-28 07:15 修改: 2026-06-17 09:47

libcurl CVE-2025-5399 中危 8.12.1-r1 8.14.1-r0 curl: libcurl: WebSocket endless loop

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5399

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-06-07 08:15 修改: 2026-06-17 09:47

mariadb-common CVE-2026-3494 中危 11.4.8-r0 11.4.10-r0 MariaDB: MariaDB: Information disclosure due to unlogged SQL statements with comments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3494

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-03-03 20:16 修改: 2026-06-17 10:43

mariadb-common CVE-2026-44169 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44169

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 16:24

mariadb-common CVE-2026-44173 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44173

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

libcurl CVE-2025-9086 中危 8.12.1-r1 8.14.1-r2 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-09-12 06:15 修改: 2026-06-17 10:08

musl CVE-2026-6042 中危 1.2.5-r9 1.2.5-r10 musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6042

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-10 09:16 修改: 2026-06-17 11:00

curl CVE-2025-4947 中危 8.12.1-r1 8.14.0-r0 libcurl: curl: QUIC certificate check skip with wolfSSL

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4947

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-05-28 07:15 修改: 2026-06-17 09:34

musl-utils CVE-2026-6042 中危 1.2.5-r9 1.2.5-r10 musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6042

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-04-10 09:16 修改: 2026-06-17 11:00

gnutls CVE-2024-12243 中危 3.8.8-r0 3.8.12-r0 gnutls: GnuTLS Impacted by Inefficient DER Decoding in libtasn1 Leading to Remote DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-12243

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-02-10 16:15 修改: 2026-06-17 06:59

gnutls CVE-2025-14831 中危 3.8.8-r0 3.8.12-r0 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14831

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-02-09 15:16 修改: 2026-06-25 04:17

libexpat CVE-2026-32776 中危 2.7.0-r0 2.7.5-r0 libexpat: libexpat: Denial of Service due to NULL pointer dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32776

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36

libexpat CVE-2026-32777 中危 2.7.0-r0 2.7.5-r0 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32777

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36

libexpat CVE-2026-32778 中危 2.7.0-r0 2.7.5-r0 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32778

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36

gnutls CVE-2025-32989 中危 3.8.8-r0 3.8.12-r0 gnutls: Vulnerability in GnuTLS SCT extension parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-32989

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-07-10 08:15 修改: 2026-06-25 05:16

mysql CVE-2026-3494 中危 11.4.8-r0 11.4.10-r0 MariaDB: MariaDB: Information disclosure due to unlogged SQL statements with comments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3494

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-03-03 20:16 修改: 2026-06-17 10:43

mysql CVE-2026-44169 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44169

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 16:24

mysql CVE-2026-44173 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44173

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

gnutls CVE-2025-6395 中危 3.8.8-r0 3.8.12-r0 gnutls: NULL pointer dereference in _gnutls_figure_common_ciphersuite()

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-6395

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-07-10 16:15 修改: 2026-06-25 05:16

gnutls CVE-2026-42011 中危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Security bypass due to incorrect name constraint handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42011

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-07 15:16 修改: 2026-06-26 08:16

gnutls CVE-2026-42012 中危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42012

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-26 22:16 修改: 2026-06-26 08:16

gnutls CVE-2026-42013 中危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42013

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-26 22:16 修改: 2026-06-26 08:16

gnutls CVE-2026-42014 中危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42014

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-06-16 02:16 修改: 2026-06-26 08:16

libpng CVE-2025-64505 中危 1.6.47-r0 1.6.53-r0 libpng: LIBPNG heap buffer overflow via malformed palette index

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-64505

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-11-25 00:15 修改: 2026-06-17 09:54

mysql-client CVE-2026-3494 中危 11.4.8-r0 11.4.10-r0 MariaDB: MariaDB: Information disclosure due to unlogged SQL statements with comments

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3494

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-03-03 20:16 修改: 2026-06-17 10:43

mysql-client CVE-2026-44169 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44169

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 16:24

mysql-client CVE-2026-44173 中危 11.4.8-r0 11.4.11-r0 mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44173

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-06-12 18:16 修改: 2026-06-17 10:50

libpng CVE-2025-64506 中危 1.6.47-r0 1.6.53-r0 libpng: LIBPNG heap buffer over-read

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-64506

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-11-25 00:15 修改: 2026-06-17 09:54

libpng CVE-2026-33416 中危 1.6.47-r0 1.6.56-r0 libpng: libpng: Arbitrary code execution due to use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33416

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-26 17:16 修改: 2026-06-17 10:37

libpng CVE-2026-33636 中危 1.6.47-r0 1.6.56-r0 libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33636

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-03-26 17:16 修改: 2026-06-17 10:37

libpng CVE-2026-34757 中危 1.6.47-r0 1.6.57-r0 libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34757

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-09 15:16 修改: 2026-06-17 10:39

gnutls CVE-2026-42015 中危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42015

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-26 22:16 修改: 2026-06-26 08:16

gnutls CVE-2026-5260 中危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5260

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-05-26 22:16 修改: 2026-06-26 08:16

gnupg-keyboxd CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

gpg CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

openssl CVE-2025-69419 中危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69419

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-9230 中危 3.3.4-r0 3.3.5-r0 openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9230

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

openssl CVE-2025-9231 中危 3.3.4-r0 3.3.5-r0 openssl: Timing side-channel in SM2 algorithm on 64 bit ARM

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9231

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

openssl CVE-2026-31790 中危 3.3.4-r0 3.3.7-r0 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:34

curl CVE-2025-5025 中危 8.12.1-r1 8.14.0-r0 curl: libcurl: QUIC Certificate Pinning Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5025

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-05-28 07:15 修改: 2026-06-17 09:47

gpg-agent CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

gnupg-utils CVE-2025-68972 中危 2.4.7-r0 2.4.9-r0 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-12-27 23:15 修改: 2026-06-17 09:59

sqlite-libs CVE-2025-29088 中危 3.48.0-r2 3.48.0-r4 sqlite: Denial of Service in SQLite

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-29088

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-04-10 14:15 修改: 2026-06-17 09:05

ssl_client CVE-2024-58251 中危 1.37.0-r12 1.37.0-r14 In netstat in BusyBox through 1.37.0, local users can launch of networ ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-58251

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-04-23 18:16 修改: 2026-06-17 08:14

xz-libs CVE-2026-34743 中危 5.6.3-r1 5.8.3-r0 xz: XZ Utils: Denial of Service via buffer overflow in index decoding

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34743

镜像层: sha256:51cdc0ecdf19a37c7d407d6feaf613c4b0ec877f239ed9806ec0593e57e94a05

发布日期: 2026-04-02 19:21 修改: 2026-06-17 10:39

libssl3 CVE-2025-69419 中危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69419

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

zlib CVE-2026-27171 中危 1.3.1-r2 1.3.2-r0 zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27171

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-02-18 04:16 修改: 2026-06-17 10:26

libssl3 CVE-2025-66199 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66199

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:56

libssl3 CVE-2025-68160 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68160

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:58

libssl3 CVE-2025-69418 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69418

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libssl3 CVE-2025-69420 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via malformed TimeStamp Response

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69420

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libssl3 CVE-2025-9232 低危 3.3.4-r0 3.3.5-r0 openssl: Out-of-bounds read in HTTP client no_proxy handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9232

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

libssl3 CVE-2026-22795 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22795

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

libssl3 CVE-2026-22796 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22796

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

libtasn1 CVE-2025-13151 低危 4.20.0-r0 4.21.0-r0 libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13151

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-07 22:15 修改: 2026-06-17 08:33

gnutls CVE-2026-3832 低危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3832

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-30 18:16 修改: 2026-06-24 17:16

gnutls CVE-2026-5419 低危 3.8.8-r0 3.8.13-r0 gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5419

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-06-01 21:16 修改: 2026-06-26 08:16

busybox-binsh CVE-2025-46394 低危 1.37.0-r12 1.37.0-r14 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-46394

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-04-23 16:15 修改: 2026-06-17 09:26

libcurl CVE-2025-10148 低危 8.12.1-r1 8.14.1-r2 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-09-12 06:15 修改: 2026-06-17 08:27

busybox CVE-2025-46394 低危 1.37.0-r12 1.37.0-r14 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-46394

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-04-23 16:15 修改: 2026-06-17 09:26

curl CVE-2025-10148 低危 8.12.1-r1 8.14.1-r2 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-09-12 06:15 修改: 2026-06-17 08:27

libcrypto3 CVE-2025-15468 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15468

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 08:37

libcrypto3 CVE-2025-66199 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66199

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:56

libcrypto3 CVE-2025-68160 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68160

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:58

libcrypto3 CVE-2025-69418 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69418

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-15468 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15468

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 08:37

openssl CVE-2025-66199 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66199

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:56

openssl CVE-2025-68160 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68160

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 09:58

openssl CVE-2025-69418 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69418

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-69420 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via malformed TimeStamp Response

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69420

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

openssl CVE-2025-9232 低危 3.3.4-r0 3.3.5-r0 openssl: Out-of-bounds read in HTTP client no_proxy handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9232

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

openssl CVE-2026-22795 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22795

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

openssl CVE-2026-22796 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22796

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

libexpat CVE-2026-24515 低危 2.7.0-r0 2.7.4-r0 libexpat: libexpat null pointer dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24515

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-23 08:16 修改: 2026-06-17 10:23

libexpat CVE-2026-41080 低危 2.7.0-r0 2.8.1-r0 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41080

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-04-16 17:16 修改: 2026-06-17 10:46

libcrypto3 CVE-2025-69420 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via malformed TimeStamp Response

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69420

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:00

libcrypto3 CVE-2025-9232 低危 3.3.4-r0 3.3.5-r0 openssl: Out-of-bounds read in HTTP client no_proxy handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9232

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-09-30 14:15 修改: 2026-06-17 10:08

libcrypto3 CVE-2026-22795 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22795

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

ssl_client CVE-2025-46394 低危 1.37.0-r12 1.37.0-r14 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hid ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-46394

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2025-04-23 16:15 修改: 2026-06-17 09:26

libcrypto3 CVE-2026-22796 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22796

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 10:20

gnutls CVE-2025-9820 低危 3.8.8-r0 3.8.12-r0 gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9820

镜像层: sha256:94e18af2b1ac7c7668372eac68d6300c5fe78968668fe8d0700542fbd0c7401b

发布日期: 2026-01-26 20:16 修改: 2026-06-25 08:16

libssl3 CVE-2025-15468 低危 3.3.4-r0 3.3.6-r0 openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15468

镜像层: sha256:7003d23cc2176ec98ba2f8b3b4b9b5f144ef370e39bfcf6275a92b5064bc9261

发布日期: 2026-01-27 16:16 修改: 2026-06-17 08:37

Java (jar)
低危漏洞:6 中危漏洞:13 高危漏洞:21 严重漏洞:3
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41293 严重 10.1.54 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41293

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43512 严重 10.1.54 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43512

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43515 严重 10.1.54 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: tomcat: Improper Authorization allows security bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43515

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

com.fasterxml.jackson.core:jackson-databind CVE-2026-54513 高危 2.21.2 2.18.8, 2.21.4, 3.1.4 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00

io.modelcontextprotocol.sdk:mcp-core CVE-2026-35568 高危 0.17.0 1.0.0 Java-SDK has a DNS Rebinding Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35568

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-04-07 22:16 修改: 2026-06-17 10:40

io.netty:netty-codec CVE-2026-42583 高危 4.1.132.Final 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-codec-dns CVE-2026-42579 高危 4.1.132.Final 4.2.13.Final, 4.1.133.Final netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-13 19:17 修改: 2026-06-17 10:48

io.netty:netty-handler CVE-2026-44249 高危 4.1.132.Final 4.2.15.Final, 4.1.135.Final netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44249

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-11 22:16 修改: 2026-06-17 10:50

io.netty:netty-handler CVE-2026-45416 高危 4.1.132.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45416

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-handler CVE-2026-50010 高危 4.1.132.Final 4.2.15.Final, 4.1.135.Final netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-50010

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:57

io.netty:netty-resolver-dns CVE-2026-45674 高危 4.1.132.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45674

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

io.netty:netty-resolver-dns CVE-2026-47691 高危 4.1.132.Final 4.2.15.Final, 4.1.135.Final io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47691

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-12 16:16 修改: 2026-06-17 10:54

org.apache.shiro:shiro-core CVE-2026-49268 高危 2.1.0 2.2.1, 3.0.0-alpha-2 A remote attacker can inject LDAP special characters into the Distingu ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-49268

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-17 14:17 修改: 2026-06-18 14:45

com.fasterxml.jackson.core:jackson-databind CVE-2026-54512 高危 2.19.2 2.18.8, 3.1.4, 2.21.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01

com.fasterxml.jackson.core:jackson-databind CVE-2026-54513 高危 2.19.2 2.18.8, 2.21.4, 3.1.4 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54513

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:00

com.fasterxml.jackson.core:jackson-databind CVE-2026-54512 高危 2.21.2 2.18.8, 3.1.4, 2.21.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54512

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 21:17 修改: 2026-06-27 21:01

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41284 高危 10.1.54 9.0.118, 10.1.55, 11.0.22 Allocation of Resources Without Limits or Throttling vulnerability in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41284

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-42498 高危 10.1.54 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42498

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:47

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43513 高危 10.1.54 9.0.118, 10.1.55, 11.0.22 Improper Handling of Case Sensitivity vulnerability in LockOutRealm in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43513

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

org.bouncycastle:bcprov-jdk18on CVE-2026-5598 高危 1.82 1.84 bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5598

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-04-15 10:16 修改: 2026-06-17 10:59

org.eclipse.jetty:jetty-http CVE-2026-2332 高危 12.0.29 12.1.7, 12.0.33 org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2332

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-04-14 12:16 修改: 2026-06-17 10:30

org.eclipse.jetty:jetty-server CVE-2026-1605 高危 12.0.29 12.1.6, 12.0.32 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1605

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-03-05 10:15 修改: 2026-06-17 10:16

org.springframework.ai:spring-ai-model CVE-2026-41712 高危 1.1.2 1.0.7, 1.1.6, 2.0.0-M6 Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41712

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-05-12 11:16 修改: 2026-06-17 10:47

org.springframework.boot:spring-boot CVE-2026-40973 高危 3.5.7 4.0.6, 3.5.14 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40973

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-04-28 00:16 修改: 2026-06-17 10:45

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.19.2 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

com.fasterxml.jackson.core:jackson-databind CVE-2026-54514 中危 2.19.2 2.18.8, 2.21.4, 3.1.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55

com.fasterxml.jackson.core:jackson-databind CVE-2026-54514 中危 2.21.2 2.18.8, 2.21.4, 3.1.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54514

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:55

com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 中危 2.21.2 3.1.4, 2.18.9, 2.21.5 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14

com.fasterxml.jackson.core:jackson-databind CVE-2026-54516 中危 2.21.2 2.21.4, 3.1.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54516

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:52

com.fasterxml.jackson.core:jackson-databind CVE-2026-54517 中危 2.21.2 2.21.4, 3.1.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54517

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 21:17 修改: 2026-06-27 20:51

org.bouncycastle:bcprov-jdk18on CVE-2026-0636 中危 1.82 1.84 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0636

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-04-15 10:16 修改: 2026-06-17 10:11

com.fasterxml.jackson.core:jackson-databind CVE-2026-54518 中危 2.21.2 2.21.4 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54518

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-23 22:16 修改: 2026-06-27 20:49

io.netty:netty-resolver-dns CVE-2026-45673 中危 4.1.132.Final 4.2.15.Final, 4.1.135.Final netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45673

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-06-12 15:16 修改: 2026-06-17 10:52

com.fasterxml.jackson.core:jackson-databind CVE-2026-54515 中危 2.19.2 3.1.4, 2.18.9, 2.21.5 jackson-databind contains the general-purpose data-binding functionali ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54515

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-06-23 21:17 修改: 2026-06-25 16:14

io.modelcontextprotocol.sdk:mcp-core CVE-2026-34237 中危 0.17.0 1.0.1, 1.1.1, 0.18.3 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34237

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-03-31 16:16 修改: 2026-06-17 10:38

org.springframework:spring-webflux CVE-2026-22737 中危 6.2.12 7.0.6, 6.2.17 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22737

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-03-20 00:16 修改: 2026-06-17 10:20

org.springframework:spring-webflux CVE-2026-22745 中危 6.2.12 7.0.7, 6.2.18 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22745

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-04-29 12:16 修改: 2026-06-17 10:20

org.eclipse.jetty:jetty-http CVE-2025-11143 低危 12.0.29 12.0.31, 12.1.5 org.eclipse.jetty/jetty-http: org.eclipse.jetty: Security bypass due to differential URI parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11143

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-03-05 10:15 修改: 2026-06-17 08:29

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43514 低危 10.1.54 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43514

镜像层: sha256:79a9e1f9a2b132986b019db5031caf2b457427b0025ba7cd7046183f261b7f53

发布日期: 2026-05-12 16:16 修改: 2026-06-17 10:49

ch.qos.logback:logback-core CVE-2026-1225 低危 1.5.20 1.5.25 ch.qos.logback/logback-core: Malicious logback.xml configuration file allows instantiation of arbitrary classes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1225

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-01-22 10:16 修改: 2026-06-17 10:15

org.springframework:spring-webflux CVE-2026-22735 低危 6.2.12 7.0.6, 6.2.17 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22735

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-03-20 00:16 修改: 2026-06-17 10:20

org.springframework:spring-webflux CVE-2026-22740 低危 6.2.12 7.0.7, 6.2.18 spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22740

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-04-29 12:16 修改: 2026-06-17 10:20

org.springframework:spring-webflux CVE-2026-22741 低危 6.2.12 7.0.7, 6.2.18 Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22741

镜像层: sha256:1472b0b2996c87293f0227b6d4314e35fa7b5146b9549f38038b24bcf68311fc

发布日期: 2026-04-29 12:16 修改: 2026-06-17 10:20

usr/local/bin/validator_linux_amd64 (gobinary)
低危漏洞:3 中危漏洞:40 高危漏洞:13 严重漏洞:2
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
stdlib CVE-2024-24790 严重 v1.21.6 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24790

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-06-05 16:15 修改: 2026-06-17 07:14

stdlib CVE-2025-68121 严重 v1.21.6 1.24.13, 1.25.7, 1.26.0-rc.3 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68121

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-02-05 18:16 修改: 2026-06-17 09:58

stdlib CVE-2023-45288 高危 v1.21.6 1.21.9, 1.22.2 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45288

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-04-04 21:15 修改: 2026-06-17 06:28

stdlib CVE-2024-34156 高危 v1.21.6 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-09-06 21:15 修改: 2026-06-17 07:33

stdlib CVE-2025-61726 高危 v1.21.6 1.24.12, 1.25.6 golang: net/url: Memory exhaustion in query parameter parsing in net/url

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61726

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-01-28 20:16 修改: 2026-06-17 09:50

stdlib CVE-2025-61729 高危 v1.21.6 1.24.11, 1.25.5 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61729

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-12-02 19:15 修改: 2026-06-17 09:50

stdlib CVE-2026-25679 高危 v1.21.6 1.25.8, 1.26.1 net/url: Incorrect parsing of IPv6 host literals in net/url

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25679

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-03-06 22:16 修改: 2026-06-17 10:25

stdlib CVE-2026-32280 高危 v1.21.6 1.25.9, 1.26.2 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32280

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-04-08 02:16 修改: 2026-06-17 10:35

stdlib CVE-2026-32281 高危 v1.21.6 1.25.9, 1.26.2 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32281

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-04-08 02:16 修改: 2026-06-17 10:35

stdlib CVE-2026-32283 高危 v1.21.6 1.25.9, 1.26.2 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32283

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-04-08 02:16 修改: 2026-06-17 10:35

stdlib CVE-2026-33811 高危 v1.21.6 1.25.10, 1.26.3 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33811

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:38

stdlib CVE-2026-33814 高危 v1.21.6 1.25.10, 1.26.3 net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33814

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:38

stdlib CVE-2026-39820 高危 v1.21.6 1.25.10, 1.26.3 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39820

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:42

stdlib CVE-2026-39836 高危 v1.21.6 1.25.10, 1.26.3 ELSA-2026-22121: golang security update (IMPORTANT)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39836

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:42

stdlib CVE-2026-42499 高危 v1.21.6 1.25.10, 1.26.3 Pathological inputs could cause DoS through consumePhrase when parsing ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42499

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:47

stdlib CVE-2023-45289 中危 v1.21.6 1.21.8, 1.22.1 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45289

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-03-05 23:15 修改: 2026-06-17 06:28

stdlib CVE-2023-45290 中危 v1.21.6 1.21.8, 1.22.1 golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45290

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-03-05 23:15 修改: 2026-06-17 06:28

stdlib CVE-2024-24783 中危 v1.21.6 1.21.8, 1.22.1 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24783

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-03-05 23:15 修改: 2026-06-17 07:14

stdlib CVE-2024-24784 中危 v1.21.6 1.21.8, 1.22.1 golang: net/mail: comments in display names are incorrectly handled

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24784

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-03-05 23:15 修改: 2026-06-17 07:14

stdlib CVE-2024-24785 中危 v1.21.6 1.21.8, 1.22.1 golang: html/template: errors returned from MarshalJSON methods may break template escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24785

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-03-05 23:15 修改: 2026-06-17 07:14

stdlib CVE-2024-24789 中危 v1.21.6 1.21.11, 1.22.4 golang: archive/zip: Incorrect handling of certain ZIP files

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24789

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-06-05 16:15 修改: 2026-06-17 07:14

stdlib CVE-2024-24791 中危 v1.21.6 1.21.12, 1.22.5 net/http: Denial of service due to improper 100-continue handling in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-24791

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-07-02 22:15 修改: 2026-06-17 07:14

stdlib CVE-2024-34155 中危 v1.21.6 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-09-06 21:15 修改: 2026-06-17 07:33

stdlib CVE-2024-34158 中危 v1.21.6 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2024-09-06 21:15 修改: 2026-06-17 07:33

stdlib CVE-2024-45336 中危 v1.21.6 1.22.11, 1.23.5, 1.24.0-rc.2 golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45336

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-01-28 02:15 修改: 2026-06-17 07:54

stdlib CVE-2025-0913 中危 v1.21.6 1.23.10, 1.24.4 Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0913

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-06-11 18:15 修改: 2026-06-17 08:27

stdlib CVE-2025-22866 中危 v1.21.6 1.22.12, 1.23.6, 1.24.0-rc.3 crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22866

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-02-06 17:15 修改: 2026-06-17 08:50

stdlib CVE-2025-22870 中危 v1.21.6 1.23.7, 1.24.1 golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22870

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-03-12 19:15 修改: 2026-06-17 08:50

stdlib CVE-2025-22871 中危 v1.21.6 1.23.8, 1.24.2 net/http: Request smuggling due to acceptance of invalid chunked data in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22871

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-04-08 20:15 修改: 2026-06-17 08:50

stdlib CVE-2025-22873 中危 v1.21.6 1.23.9, 1.24.3 os: os: Information disclosure via path traversal using specially crafted filenames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22873

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-02-04 23:15 修改: 2026-06-17 08:50

stdlib CVE-2025-4673 中危 v1.21.6 1.23.10, 1.24.4 net/http: Sensitive headers not cleared on cross-origin redirect in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4673

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-06-11 17:15 修改: 2026-06-17 09:33

stdlib CVE-2025-47906 中危 v1.21.6 1.23.12, 1.24.6 os/exec: Unexpected paths returned from LookPath in os/exec

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47906

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-09-18 19:15 修改: 2026-06-17 09:28

stdlib CVE-2025-47907 中危 v1.21.6 1.23.12, 1.24.6 database/sql: Postgres Scan Race Condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47907

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-08-07 16:15 修改: 2026-06-17 09:28

stdlib CVE-2025-47912 中危 v1.21.6 1.24.8, 1.25.2 net/url: Insufficient validation of bracketed IPv6 hostnames in net/url

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47912

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:28

stdlib CVE-2025-58183 中危 v1.21.6 1.24.8, 1.25.2 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58183

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:44

stdlib CVE-2025-58185 中危 v1.21.6 1.24.8, 1.25.2 encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58185

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:44

stdlib CVE-2025-58187 中危 v1.21.6 1.24.9, 1.25.3 crypto/x509: Quadratic complexity when checking name constraints in crypto/x509

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58187

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:44

stdlib CVE-2025-58188 中危 v1.21.6 1.24.8, 1.25.2 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58188

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:44

stdlib CVE-2025-58189 中危 v1.21.6 1.24.8, 1.25.2 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58189

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:44

stdlib CVE-2025-61723 中危 v1.21.6 1.24.8, 1.25.2 encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61723

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:50

stdlib CVE-2025-61724 中危 v1.21.6 1.24.8, 1.25.2 net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61724

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:50

stdlib CVE-2025-61725 中危 v1.21.6 1.24.8, 1.25.2 net/mail: Excessive CPU consumption in ParseAddress in net/mail

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61725

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:50

stdlib CVE-2025-61727 中危 v1.21.6 1.24.11, 1.25.5 golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61727

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-12-03 20:16 修改: 2026-06-17 09:50

stdlib CVE-2025-61728 中危 v1.21.6 1.24.12, 1.25.6 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61728

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-01-28 20:16 修改: 2026-06-17 09:50

stdlib CVE-2025-61730 中危 v1.21.6 1.24.12, 1.25.6 crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61730

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-01-28 20:16 修改: 2026-06-17 09:50

stdlib CVE-2026-27142 中危 v1.21.6 1.25.8, 1.26.1 html/template: URLs in meta content attribute actions are not escaped in html/template

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27142

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-03-06 22:16 修改: 2026-06-17 10:26

stdlib CVE-2026-27145 中危 v1.21.6 1.25.11, 1.26.4 *x509.Certificate).VerifyHostname previously called matchHostnames in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27145

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-06-02 23:16 修改: 2026-06-17 10:26

stdlib CVE-2026-32282 中危 v1.21.6 1.25.9, 1.26.2 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32282

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-04-08 02:16 修改: 2026-06-17 10:35

stdlib CVE-2026-32288 中危 v1.21.6 1.25.9, 1.26.2 archive/tar: golang: Go's archive/tar package: Denial of Service via maliciously-crafted archive

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32288

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-04-08 02:16 修改: 2026-06-17 10:35

stdlib CVE-2026-32289 中危 v1.21.6 1.25.9, 1.26.2 html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32289

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-04-08 02:16 修改: 2026-06-17 10:35

stdlib CVE-2026-39823 中危 v1.21.6 1.25.10, 1.26.3 html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39823

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:42

stdlib CVE-2026-39825 中危 v1.21.6 1.25.10, 1.26.3 net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39825

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:42

stdlib CVE-2026-39826 中危 v1.21.6 1.25.10, 1.26.3 html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39826

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-05-07 20:16 修改: 2026-06-17 10:42

stdlib CVE-2026-42504 中危 v1.21.6 1.25.11, 1.26.4 Decoding a maliciously-crafted MIME header containing many invalid enc ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42504

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-06-02 23:16 修改: 2026-06-17 10:47

stdlib CVE-2026-42507 中危 v1.21.6 1.25.11, 1.26.4 net/textproto: golang: Golang net/textproto: Misleading error messages via input injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42507

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-06-02 23:16 修改: 2026-06-17 10:47

stdlib CVE-2024-45341 低危 v1.21.6 1.22.11, 1.23.5, 1.24.0-rc.2 golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45341

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-01-28 02:15 修改: 2026-06-17 07:54

stdlib CVE-2025-58186 低危 v1.21.6 1.24.8, 1.25.2 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58186

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2025-10-29 23:16 修改: 2026-06-17 09:44

stdlib CVE-2026-27139 低危 v1.21.6 1.25.8, 1.26.1 os: FileInfo can escape from a Root in golang os module

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27139

镜像层: sha256:67955842943849ab53cd6b712fd6e409ea283f6330850347851a687ff842669e

发布日期: 2026-03-06 22:16 修改: 2026-06-17 10:26

检测到您正在使用广告拦截插件,本站为公益站点,依赖广告维持运转 🙏 查看如何关闭 ×