docker.io/apache/hertzbeat:1.8.0 linux/amd64

docker.io/apache/hertzbeat:1.8.0 - Trivy安全扫描结果 扫描时间: 2026-06-09 08:38
全部漏洞信息
低危漏洞:87 中危漏洞:225 高危漏洞:47 严重漏洞:10

系统OS: ubuntu 24.04 扫描引擎: Trivy 扫描时间: 2026-06-09 08:38

docker.io/apache/hertzbeat:1.8.0 (ubuntu 24.04) (ubuntu)
低危漏洞:71 中危漏洞:177 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
binutils CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

binutils CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

binutils CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

binutils CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

binutils CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

binutils CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

binutils CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

binutils-common CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

binutils-common CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

binutils-common CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

binutils-common CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

binutils-common CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

binutils-common CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

binutils-common CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

binutils-x86-64-linux-gnu CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

binutils-x86-64-linux-gnu CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

binutils-x86-64-linux-gnu CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

binutils-x86-64-linux-gnu CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

binutils-x86-64-linux-gnu CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

binutils-x86-64-linux-gnu CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

binutils-x86-64-linux-gnu CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

bsdutils CVE-2026-27456 中危 1:2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

curl CVE-2025-14017 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14017

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-27 21:29

curl CVE-2026-1965 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1965

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-11 11:15 修改: 2026-03-12 14:11

curl CVE-2026-3783 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3783

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-11 11:16 修改: 2026-03-12 14:10

curl CVE-2026-5545 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5545

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:31

curl CVE-2026-6253 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6253

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:40

curl CVE-2026-6429 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Credential leak via reused proxy connection during HTTP redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6429

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:18

curl CVE-2026-7168 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7168

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:12

dpkg CVE-2026-2219 中危 1.22.6ubuntu6.5 1.22.6ubuntu6.6 It was discovered that dpkg-deb (a component of dpkg, the Debian packa ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2219

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-03-07 09:16 修改: 2026-06-02 19:12

libbinutils CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

libbinutils CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

libbinutils CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

libbinutils CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

libbinutils CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

libbinutils CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

libbinutils CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

libblkid1 CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libc-bin CVE-2026-4046 中危 2.39-0ubuntu8.7 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

libc-bin CVE-2026-4437 中危 2.39-0ubuntu8.7 glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4437

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:41

libc-bin CVE-2026-4438 中危 2.39-0ubuntu8.7 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4438

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:40

libc-bin CVE-2026-5435 中危 2.39-0ubuntu8.7 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-28 13:19 修改: 2026-05-05 17:38

libc-bin CVE-2026-6238 中危 2.39-0ubuntu8.7 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-28 19:37 修改: 2026-05-04 17:57

libc6 CVE-2026-4046 中危 2.39-0ubuntu8.7 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

libc6 CVE-2026-4437 中危 2.39-0ubuntu8.7 glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4437

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:41

libc6 CVE-2026-4438 中危 2.39-0ubuntu8.7 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4438

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:40

libc6 CVE-2026-5435 中危 2.39-0ubuntu8.7 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-28 13:19 修改: 2026-05-05 17:38

libc6 CVE-2026-6238 中危 2.39-0ubuntu8.7 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-28 19:37 修改: 2026-05-04 17:57

libcap2 CVE-2026-4878 中危 1:2.66-5ubuntu2.2 1:2.66-5ubuntu2.4 libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4878

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-09 16:16 修改: 2026-06-04 00:17

libctf-nobfd0 CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

libctf-nobfd0 CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

libctf-nobfd0 CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

libctf-nobfd0 CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

libctf-nobfd0 CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

libctf-nobfd0 CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

libctf-nobfd0 CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

libctf0 CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

libctf0 CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

libctf0 CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

libctf0 CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

libctf0 CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

libctf0 CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

libctf0 CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

libcurl4t64 CVE-2025-14017 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14017

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-27 21:29

libcurl4t64 CVE-2026-1965 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1965

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-11 11:15 修改: 2026-03-12 14:11

libcurl4t64 CVE-2026-3783 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3783

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-11 11:16 修改: 2026-03-12 14:10

libcurl4t64 CVE-2026-5545 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5545

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:31

libcurl4t64 CVE-2026-6253 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6253

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:40

libcurl4t64 CVE-2026-6429 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Credential leak via reused proxy connection during HTTP redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6429

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:18

libcurl4t64 CVE-2026-7168 中危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7168

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:12

libexpat1 CVE-2025-66382 中危 2.6.1-2ubuntu0.3 libexpat: libexpat: Denial of service via crafted file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66382

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-11-28 07:15 修改: 2026-06-02 14:16

libexpat1 CVE-2026-24515 中危 2.6.1-2ubuntu0.3 2.6.1-2ubuntu0.4 libexpat: libexpat null pointer dereference

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24515

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-23 08:16 修改: 2026-06-02 14:16

libexpat1 CVE-2026-25210 中危 2.6.1-2ubuntu0.3 2.6.1-2ubuntu0.4 libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25210

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-30 07:16 修改: 2026-06-02 14:16

libfdisk1 CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libfreetype6 CVE-2026-23865 中危 2.13.2+dfsg-1build3 2.13.2+dfsg-1ubuntu0.1 freetype: Information disclosure or denial of service via specially crafted font files

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-23865

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-02 17:16 修改: 2026-05-01 17:41

libgcrypt20 CVE-2026-41989 中危 1.10.3-2build1 1.10.3-2ubuntu0.1 Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41989

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-23 05:16 修改: 2026-04-27 18:33

libgnutls30t64 CVE-2025-14831 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.5 gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14831

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-02-09 15:16 修改: 2026-05-14 23:16

libgnutls30t64 CVE-2026-33845 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33845

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-30 18:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-33846 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33846

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-04 10:15 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-3832 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3832

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-30 18:16 修改: 2026-06-02 17:16

libgnutls30t64 CVE-2026-3833 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3833

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-30 18:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-42009 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42009

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-18 13:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-42010 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Authentication Bypass via NUL Character in Username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42010

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-07 12:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-42011 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Security bypass due to incorrect name constraint handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42011

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-07 15:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-42012 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42012

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-42013 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42013

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-42014 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: Fix use-after-free in gnutls_pkcs11_token_set_pin

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42014

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

libgnutls30t64 CVE-2026-42015 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42015

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-5260 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 gnutls: gnutls: Information disclosure via heap overread in RSA key exchange

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5260

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-05-26 22:16 修改: 2026-06-02 16:16

libgnutls30t64 CVE-2026-5419 中危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.6 guntls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5419

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-06-01 21:16 修改: 2026-06-02 17:16

libgprofng0 CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

libgprofng0 CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

libgprofng0 CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

libgprofng0 CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

libgprofng0 CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

libgprofng0 CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

libgprofng0 CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

libmount1 CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libnghttp2-14 CVE-2026-27135 中危 1.59.0-1ubuntu0.2 1.59.0-1ubuntu0.3 nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27135

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-18 18:16 修改: 2026-05-13 22:16

libnss-systemd CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

libnss-systemd CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

libpam-systemd CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

libpam-systemd CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

libpng16-16t64 CVE-2026-25646 中危 1.6.43-5ubuntu0.4 1.6.43-5ubuntu0.5 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-02-10 18:16 修改: 2026-02-13 20:43

libpng16-16t64 CVE-2026-33416 中危 1.6.43-5ubuntu0.4 1.6.43-5ubuntu0.6 libpng: libpng: Arbitrary code execution due to use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33416

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 17:16 修改: 2026-04-02 20:28

libpng16-16t64 CVE-2026-33636 中危 1.6.43-5ubuntu0.4 1.6.43-5ubuntu0.6 libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33636

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 17:16 修改: 2026-04-02 18:42

libpng16-16t64 CVE-2026-34757 中危 1.6.43-5ubuntu0.4 1.6.43-5ubuntu0.6 libpng: libpng: Information disclosure and data corruption via use-after-free vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34757

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-09 15:16 修改: 2026-05-13 23:07

libpython3.12-minimal CVE-2025-13462 中危 3.12.3-1ubuntu0.11 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 18:16 修改: 2026-06-05 19:42

libpython3.12-minimal CVE-2026-2297 中危 3.12.3-1ubuntu0.11 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

libpython3.12-stdlib CVE-2025-13462 中危 3.12.3-1ubuntu0.11 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 18:16 修改: 2026-06-05 19:42

libpython3.12-stdlib CVE-2026-2297 中危 3.12.3-1ubuntu0.11 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

libsframe1 CVE-2025-69644 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted binary with malformed DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69644

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-10 20:42

libsframe1 CVE-2025-69645 中危 2.42-4ubuntu2.8 binutils: Binutils objdump: Denial of Service via crafted DWARF debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69645

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 17:08

libsframe1 CVE-2025-69646 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via malformed DWARF debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69646

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-20 16:59

libsframe1 CVE-2025-69647 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF loclists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69647

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:44

libsframe1 CVE-2025-69648 中危 2.42-4ubuntu2.8 binutils: infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69648

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-09 15:15 修改: 2026-03-13 16:43

libsframe1 CVE-2025-69651 中危 2.42-4ubuntu2.8 binutils: Binutils: Denial of Service via crafted ELF binary processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69651

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 18:16 修改: 2026-03-19 13:16

libsframe1 CVE-2025-69652 中危 2.42-4ubuntu2.8 binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69652

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-06 19:16 修改: 2026-03-11 15:49

libsmartcols1 CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

libssh-4 CVE-2026-0964 中危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.3 libssh: Improper sanitation of paths received from SCP servers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0964

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 21:17 修改: 2026-05-19 14:16

libssh-4 CVE-2026-0967 中危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.3 libssh: libssh: Denial of Service via inefficient regular expression processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0967

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 21:17 修改: 2026-05-19 14:16

libssh-4 CVE-2026-0968 中危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.3 libssh: libssh: Denial of Service due to malformed SFTP message

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0968

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 21:17 修改: 2026-05-19 14:16

libssh-4 CVE-2026-3731 中危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.4 libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3731

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-08 11:15 修改: 2026-03-12 19:02

libssl3t64 CVE-2026-31790 中危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

libsystemd-shared CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

libsystemd-shared CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

libsystemd0 CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

libsystemd0 CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

libudev1 CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

libudev1 CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

libuuid1 CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

locales CVE-2026-4046 中危 2.39-0ubuntu8.7 glibc: glibc: Denial of Service via iconv() function with specific character sets

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4046

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-30 18:16 修改: 2026-04-20 22:16

locales CVE-2026-4437 中危 2.39-0ubuntu8.7 glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4437

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:41

locales CVE-2026-4438 中危 2.39-0ubuntu8.7 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4438

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-20 20:16 修改: 2026-04-07 18:40

locales CVE-2026-5435 中危 2.39-0ubuntu8.7 glibc: glibc: Out-of-bounds write via TSIG record processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5435

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-28 13:19 修改: 2026-05-05 17:38

locales CVE-2026-6238 中危 2.39-0ubuntu8.7 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6238

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-28 19:37 修改: 2026-05-04 17:57

mount CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

openssh-client CVE-2026-3497 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 19:16 修改: 2026-06-02 19:43

openssh-client CVE-2026-35385 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:02

openssh-client CVE-2026-35386 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:03

openssh-client CVE-2026-35387 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:05

openssh-client CVE-2026-35388 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:12

openssh-client CVE-2026-35414 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 18:16 修改: 2026-04-10 19:36

openssh-server CVE-2026-3497 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 19:16 修改: 2026-06-02 19:43

openssh-server CVE-2026-35385 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:02

openssh-server CVE-2026-35386 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:03

openssh-server CVE-2026-35387 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:05

openssh-server CVE-2026-35388 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:12

openssh-server CVE-2026-35414 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 18:16 修改: 2026-04-10 19:36

openssh-sftp-server CVE-2026-3497 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3497

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 19:16 修改: 2026-06-02 19:43

openssh-sftp-server CVE-2026-35385 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35385

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:02

openssh-sftp-server CVE-2026-35386 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35386

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:03

openssh-sftp-server CVE-2026-35387 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35387

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:05

openssh-sftp-server CVE-2026-35388 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35388

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 17:16 修改: 2026-04-27 14:12

openssh-sftp-server CVE-2026-35414 中危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.16 OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35414

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-02 18:16 修改: 2026-04-10 19:36

openssl CVE-2026-31790 中危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31790

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

python3-cryptography CVE-2026-26007 中危 41.0.7-4ubuntu0.1 41.0.7-4ubuntu0.3 cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26007

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-02-10 22:17 修改: 2026-02-23 15:40

python3-jwt CVE-2026-32597 中危 2.7.0-1 2.7.0-1ubuntu0.1 pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32597

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-13 19:55 修改: 2026-05-05 18:16

python3.12 CVE-2025-13462 中危 3.12.3-1ubuntu0.11 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 18:16 修改: 2026-06-05 19:42

python3.12 CVE-2026-2297 中危 3.12.3-1ubuntu0.11 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

python3.12-minimal CVE-2025-13462 中危 3.12.3-1ubuntu0.11 cpython: cpython: `tarfile` module misinterprets crafted tar archives leading to data integrity issues

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13462

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-12 18:16 修改: 2026-06-05 19:42

python3.12-minimal CVE-2026-2297 中危 3.12.3-1ubuntu0.11 cpython: CPython: Logging Bypass in Legacy .pyc File Handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2297

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-04 23:16 修改: 2026-05-01 16:16

sed CVE-2026-5958 中危 4.9-2build1 4.9-2ubuntu0.24.04.1 sed: GNU sed TOCTOU race condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5958

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-20 12:16 修改: 2026-05-19 15:17

systemd CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

systemd CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

systemd-dev CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

systemd-dev CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

systemd-resolved CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

systemd-resolved CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

systemd-sysv CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

systemd-sysv CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

systemd-timesyncd CVE-2026-29111 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-29111

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-03-23 22:16 修改: 2026-04-15 16:44

systemd-timesyncd CVE-2026-40225 中危 255.4-1ubuntu8.12 255.4-1ubuntu8.14 systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40225

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-04-27 19:00

tar CVE-2025-45582 中危 1.35+dfsg-3build1 tar: Tar path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-45582

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-07-11 17:15 修改: 2025-11-02 01:15

tar CVE-2026-5704 中危 1.35+dfsg-3build1 tar: tar: Hidden file injection via crafted archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5704

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-06 16:16 修改: 2026-04-22 20:08

util-linux CVE-2026-27456 中危 2.39.3-9ubuntu6.4 util-linux: TOCTOU in the mount program when setting up loop devices

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27456

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-03 22:16 修改: 2026-04-22 16:08

wget CVE-2021-31879 中危 1.21.4-1ubuntu4.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2021-04-29 05:15 修改: 2024-11-21 06:06

libcurl4t64 CVE-2025-0167 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-05 10:15 修改: 2025-07-30 19:41

libcurl4t64 CVE-2025-10148 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:55

libsystemd0 CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libcurl4t64 CVE-2025-14524 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:53

libcurl4t64 CVE-2025-14819 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: libcurl: Improper certificate validation due to cached TLS settings reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14819

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:51

libudev1 CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libcurl4t64 CVE-2025-15079 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: Host verification bypass during SSH transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:50

libgprofng0 CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

libgprofng0 CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

libicu74 CVE-2025-5222 低危 74.2-1ubuntu3.1 icu: Stack buffer overflow in the SRBRoot::addTag function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-5222

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-05-27 21:15 修改: 2026-04-23 00:16

liblzma5 CVE-2026-34743 低危 5.6.1+really5.4.5-1ubuntu0.2 5.6.1+really5.4.5-1ubuntu0.3 xz: XZ Utils: Denial of Service via buffer overflow in index decoding

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34743

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-04-02 19:21 修改: 2026-04-15 17:33

libcurl4t64 CVE-2025-15224 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: libssh key passphrase bypass without agent set

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:47

login CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2024-12-26 09:15 修改: 2026-04-15 00:35

libcurl4t64 CVE-2026-3784 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 curl: curl: Unauthorized access due to improper HTTP proxy connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3784

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-11 11:16 修改: 2026-06-02 14:16

libcurl4t64 CVE-2026-4873 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: curl: Information disclosure due to incorrect TLS connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4873

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:45

libcurl4t64 CVE-2026-5773 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5773

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:13

libnss-systemd CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libcurl4t64 CVE-2026-6276 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6276

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:21

curl CVE-2025-10148 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:55

libpam-systemd CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

openssh-client CVE-2025-61984 低危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-10-06 19:15 修改: 2026-04-15 00:35

openssh-client CVE-2025-61985 低危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-10-06 19:15 修改: 2026-04-15 00:35

libbinutils CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

libbinutils CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

curl CVE-2025-14524 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:53

libctf-nobfd0 CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

libctf-nobfd0 CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

libgcrypt20 CVE-2024-2236 低危 1.10.3-2build1 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2024-03-06 22:15 修改: 2026-04-15 00:35

openssh-server CVE-2025-61984 低危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-10-06 19:15 修改: 2026-04-15 00:35

openssh-server CVE-2025-61985 低危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-10-06 19:15 修改: 2026-04-15 00:35

curl CVE-2025-14819 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: libcurl: Improper certificate validation due to cached TLS settings reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14819

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:51

curl CVE-2025-15079 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: Host verification bypass during SSH transfers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:50

curl CVE-2025-15224 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.7 curl: libssh key passphrase bypass without agent set

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:47

curl CVE-2026-3784 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 curl: curl: Unauthorized access due to improper HTTP proxy connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3784

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-11 11:16 修改: 2026-06-02 14:16

curl CVE-2026-4873 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: curl: Information disclosure due to incorrect TLS connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4873

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:45

curl CVE-2026-5773 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5773

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:13

openssh-sftp-server CVE-2025-61984 低危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61984

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-10-06 19:15 修改: 2026-04-15 00:35

openssh-sftp-server CVE-2025-61985 低危 1:9.6p1-3ubuntu13.14 1:9.6p1-3ubuntu13.15 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61985

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2025-10-06 19:15 修改: 2026-04-15 00:35

curl CVE-2026-6276 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.9 curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6276

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:21

openssl CVE-2026-28387 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

openssl CVE-2026-28388 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

openssl CVE-2026-28389 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

openssl CVE-2026-28390 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

openssl CVE-2026-31789 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

passwd CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2024-12-26 09:15 修改: 2026-04-15 00:35

libctf0 CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

libctf0 CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

libsframe1 CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

libsframe1 CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

binutils CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

binutils-common CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

binutils-x86-64-linux-gnu CVE-2017-13716 低危 2.42-4ubuntu2.8 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2017-08-28 21:29 修改: 2026-05-13 00:24

binutils-x86-64-linux-gnu CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

binutils-common CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

systemd CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libssh-4 CVE-2025-8277 低危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.3 libssh: Memory Exhaustion via Repeated Key Exchange in libssh

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8277

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-09-09 12:15 修改: 2026-05-19 14:16

libssh-4 CVE-2026-0965 低危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.3 libssh: libssh: Denial of Service via improper configuration file handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0965

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 21:17 修改: 2026-05-19 14:16

systemd-dev CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libssh-4 CVE-2026-0966 低危 0.10.6-2ubuntu0.2 0.10.6-2ubuntu0.3 libssh: libssh: Denial of Service via zero-length input in ssh_get_hexa()

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-0966

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-03-26 21:17 修改: 2026-05-19 14:16

libgnutls30t64 CVE-2025-9820 低危 3.8.3-1.1ubuntu3.4 3.8.3-1.1ubuntu3.5 gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9820

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2026-01-26 20:16 修改: 2026-05-12 13:17

systemd-resolved CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libssl3t64 CVE-2026-28387 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28387

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

libssl3t64 CVE-2026-28388 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28388

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

systemd-sysv CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libssl3t64 CVE-2026-28389 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Denial of Service vulnerability in CMS processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28389

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

libssl3t64 CVE-2026-28390 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-28390

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

systemd-timesyncd CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

libssl3t64 CVE-2026-31789 低危 3.0.13-0ubuntu3.7 3.0.13-0ubuntu3.9 openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31789

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2026-04-07 22:16 修改: 2026-05-12 13:17

binutils CVE-2025-1152 低危 2.42-4ubuntu2.8 binutils: GNU Binutils ld xstrdup.c xstrdup memory leak

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-1152

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-10 18:15 修改: 2025-03-03 17:32

curl CVE-2025-0167 低危 8.5.0-2ubuntu10.6 8.5.0-2ubuntu10.8 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:4a8ac3cbbc81a156d05e8f2377f47f65aa86b108b8d1590b91801d426c82621a

发布日期: 2025-02-05 10:15 修改: 2025-07-30 19:41

libsystemd-shared CVE-2026-40228 低危 255.4-1ubuntu8.12 systemd: systemd-journald: Unintended output to user terminals via logger command

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40228

镜像层: sha256:d8c60cd88017ae851b219b291da245796db83b0a1775f1fe89fedc858651f4e4

发布日期: 2026-04-10 16:16 修改: 2026-05-05 02:16

Java (jar)
低危漏洞:16 中危漏洞:48 高危漏洞:47 严重漏洞:10
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
org.apache.tomcat.embed:tomcat-embed-core CVE-2025-24813 严重 10.1.34 11.0.3, 10.1.35, 9.0.99 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24813

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-03-10 17:15 修改: 2025-10-23 14:49

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41293 严重 10.1.34 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41293

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-15 15:57

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43512 严重 10.1.34 9.0.118, 10.1.55, 11.0.22 tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43512

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-15 15:54

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43515 严重 10.1.34 9.0.118, 10.1.55, 11.0.22 Improper Authorization vulnerability when multiple method constraints ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43515

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-15 15:52

org.thymeleaf:thymeleaf CVE-2026-40477 严重 3.1.3.RELEASE 3.1.4.RELEASE thymeleaf: Thymeleaf: Server-Side Template Injection via security bypass in expression execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40477

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-17 22:16 修改: 2026-04-24 16:58

org.thymeleaf:thymeleaf CVE-2026-40478 严重 3.1.3.RELEASE 3.1.4.RELEASE thymeleaf: Thymeleaf: Server-Side Template Injection via expression execution bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40478

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-17 22:16 修改: 2026-04-24 16:58

org.thymeleaf:thymeleaf CVE-2026-41901 严重 3.1.3.RELEASE 3.1.5.RELEASE Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41901

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 23:16 修改: 2026-05-13 16:10

org.thymeleaf:thymeleaf-spring6 CVE-2026-40477 严重 3.1.3.RELEASE 3.1.4.RELEASE thymeleaf: Thymeleaf: Server-Side Template Injection via security bypass in expression execution

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40477

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-17 22:16 修改: 2026-04-24 16:58

org.thymeleaf:thymeleaf-spring6 CVE-2026-40478 严重 3.1.3.RELEASE 3.1.4.RELEASE thymeleaf: Thymeleaf: Server-Side Template Injection via expression execution bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40478

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-17 22:16 修改: 2026-04-24 16:58

org.thymeleaf:thymeleaf-spring6 CVE-2026-41901 严重 3.1.3.RELEASE 3.1.5.RELEASE Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41901

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 23:16 修改: 2026-05-13 16:10

io.netty:netty-codec-http CVE-2026-42587 高危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:20

io.netty:netty-codec-http2 CVE-2025-55163 高危 4.1.117.Final 4.2.4.Final, 4.1.124.Final netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-08-13 15:15 修改: 2025-11-04 22:16

io.netty:netty-codec-http2 CVE-2026-33871 高危 4.1.117.Final 4.1.132.Final, 4.2.11.Final netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33871

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-27 20:16 修改: 2026-03-30 20:10

io.netty:netty-codec-http2 CVE-2026-42587 高危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42587

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:20

io.netty:netty-codec-smtp CVE-2025-59419 高危 4.1.117.Final 4.2.7.Final, 4.1.128.Final io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59419

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-15 16:15 修改: 2026-04-15 00:35

io.netty:netty-handler CVE-2025-24970 高危 4.1.117.Final 4.1.118.Final io.netty:netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-24970

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-02-10 22:15 修改: 2025-09-05 17:20

net.minidev:json-smart CVE-2024-57699 高危 2.5.1 2.5.2 json-smart: Potential DoS via stack exhaustion (incomplete fix for CVE-2023-1370)

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-57699

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-02-05 22:15 修改: 2026-04-15 00:35

org.apache.kafka:kafka-clients CVE-2026-35554 高危 3.7.1 3.9.2, 4.0.2, 4.1.2 Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35554

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-07 14:16 修改: 2026-04-08 21:27

org.apache.thrift:libthrift CVE-2026-43869 高危 0.14.1 0.23.0 Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43869

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-05 08:16 修改: 2026-05-06 18:05

com.google.protobuf:protobuf-java CVE-2024-7254 高危 3.21.11 3.25.5, 4.27.5, 4.28.2 protobuf: StackOverflow vulnerability in Protocol Buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2024-09-19 01:15 修改: 2025-09-26 17:10

com.microsoft.sqlserver:mssql-jdbc CVE-2025-59250 高危 10.2.0 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11 JDBC Driver for SQL Server has improper input validation issue

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59250

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-14 17:16 修改: 2025-10-30 16:35

com.microsoft.sqlserver:mssql-jdbc CVE-2025-59250 高危 10.2.0.jre8 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11 JDBC Driver for SQL Server has improper input validation issue

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-59250

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-14 17:16 修改: 2025-10-30 16:35

commons-beanutils:commons-beanutils CVE-2025-48734 高危 1.9.4 1.11.0 commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48734

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-05-28 14:15 修改: 2025-11-03 20:19

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-48988 高危 10.1.34 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat DoS in multipart upload

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48988

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-06-16 15:15 修改: 2025-11-03 20:19

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-48989 高危 10.1.34 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48989

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-08-13 13:15 修改: 2026-05-12 13:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-52520 高危 10.1.34 11.0.9, 10.1.43, 9.0.107 tomcat: Apache Tomcat denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-52520

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-07-10 19:15 修改: 2025-11-04 22:16

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-53506 高危 10.1.34 9.0.107, 10.1.43, 11.0.9 tomcat: Apache Tomcat denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53506

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-07-10 20:15 修改: 2025-11-04 22:16

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-55752 高危 10.1.34 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55752

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-27 18:15 修改: 2026-05-12 13:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24734 高危 10.1.34 11.0.18, 10.1.52, 9.0.115 tomcat: Apache Tomcat: Certificate revocation bypass due to improper OCSP response validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24734

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-02-17 19:21 修改: 2026-03-11 16:16

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24880 高危 10.1.34 9.0.116, 10.1.52, 11.0.20 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24880

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-09 20:16 修改: 2026-04-14 20:02

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-34483 高危 10.1.34 9.0.116, 10.1.54, 11.0.21 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34483

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-09 20:16 修改: 2026-04-14 12:46

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-34487 高危 10.1.34 9.0.117, 10.1.54, 11.0.21 Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34487

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-09 20:16 修改: 2026-04-14 12:44

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-41284 高危 10.1.34 9.0.118, 10.1.55, 11.0.22 Allocation of Resources Without Limits or Throttling vulnerability in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41284

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-14 18:59

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-42498 高危 10.1.34 9.0.118, 10.1.55, 11.0.22 Exposure of HTTP Authentication Header to unexpected hosts during WebS ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42498

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-14 18:51

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43513 高危 10.1.34 9.0.118, 10.1.55, 11.0.22 Improper Handling of Case Sensitivity vulnerability in LockOutRealm in ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43513

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-15 15:53

org.apache.zookeeper:zookeeper CVE-2026-24281 高危 3.9.3 3.8.6, 3.9.5 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24281

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-07 09:16 修改: 2026-03-10 18:18

org.apache.zookeeper:zookeeper CVE-2026-24308 高危 3.9.3 3.9.5, 3.8.6 Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24308

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-07 09:16 修改: 2026-03-10 18:18

org.lz4:lz4-java CVE-2025-12183 高危 1.8.0 1.8.1 lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12183

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-11-28 16:15 修改: 2026-04-15 00:35

org.lz4:lz4-java CVE-2025-66566 高危 1.8.0 lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66566

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-12-05 18:15 修改: 2026-04-15 00:35

org.msgpack:msgpack-core CVE-2026-21452 高危 0.9.6 0.9.11 MessagePack for Java is a serializer implementation for Java. A denial ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21452

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-01-02 21:16 修改: 2026-02-05 19:21

org.postgresql:postgresql CVE-2026-42198 高危 42.5.5 42.7.11 jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42198

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-29 16:16 修改: 2026-05-01 12:51

org.springframework.ai:spring-ai-client-chat CVE-2026-41712 高危 1.1.1 1.0.7, 1.1.6, 2.0.0-M6 Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41712

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 11:16 修改: 2026-05-12 19:26

org.springframework.ai:spring-ai-client-chat CVE-2026-41713 高危 1.1.1 1.0.7, 1.1.6 Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41713

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 11:16 修改: 2026-05-12 19:25

org.springframework.ai:spring-ai-model CVE-2026-41712 高危 1.1.1 1.0.7, 1.1.6, 2.0.0-M6 Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41712

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 11:16 修改: 2026-05-12 19:26

org.springframework.boot:spring-boot CVE-2025-22235 高危 3.4.2 3.3.11, 3.4.5 org.springframework.boot/spring-boot: Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22235

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-04-28 08:15 修改: 2026-04-15 00:35

org.springframework.boot:spring-boot CVE-2026-40973 高危 3.4.2 4.0.6, 3.5.14 Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-40973

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-28 00:16 修改: 2026-04-30 14:25

org.springframework.boot:spring-boot-starter-actuator CVE-2026-22731 高危 3.4.2 3.5.12, 4.0.4 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22731

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-19 23:16 修改: 2026-04-16 04:30

org.springframework.boot:spring-boot-starter-actuator CVE-2026-22733 高危 3.4.2 4.0.4, 3.5.12 Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22733

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-20 00:16 修改: 2026-04-23 14:24

org.springframework:spring-core CVE-2025-41249 高危 6.2.2 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-41249

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-09-16 11:15 修改: 2026-04-15 00:35

io.grpc:grpc-netty-shaded CVE-2025-55163 高危 1.56.1 1.75.0 netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55163

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-08-13 15:15 修改: 2025-11-04 22:16

io.modelcontextprotocol.sdk:mcp-core CVE-2026-35568 高危 0.17.0 1.0.0 Java-SDK has a DNS Rebinding Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35568

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-07 22:16 修改: 2026-04-14 19:31

io.netty:netty-codec CVE-2026-42583 高危 4.1.117.Final 4.1.133.Final Netty is an asynchronous, event-driven network application framework. ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42583

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:22

io.netty:netty-codec-dns CVE-2026-42579 高危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42579

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 17:16

io.netty:netty-codec-http CVE-2026-33870 高危 4.1.117.Final 4.1.132.Final, 4.2.10.Final io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33870

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-27 20:16 修改: 2026-03-30 20:12

io.netty:netty-codec-http CVE-2026-42584 高危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42584

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:15

xerces:xercesImpl CVE-2012-0881 高危 2.11.0 2.12.0 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)

漏洞详情: https://avd.aquasec.com/nvd/cve-2012-0881

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2017-10-30 16:29 修改: 2025-04-20 01:37

xerces:xercesImpl CVE-2013-4002 高危 2.11.0 2.12.0 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)

漏洞详情: https://avd.aquasec.com/nvd/cve-2013-4002

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2013-07-23 11:03 修改: 2026-04-29 01:13

io.opentelemetry:opentelemetry-api CVE-2026-45292 中危 1.49.0 1.62.0 opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45292

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-28 17:16 修改: 2026-05-29 15:42

io.projectreactor.netty:reactor-netty-http CVE-2025-22227 中危 1.2.2 1.3.0-M5, 1.2.8 io.projectreactor.netty/reactor-netty: Reactor Netty Credential Leak via Redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22227

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-07-16 10:15 修改: 2026-04-15 00:35

net.i2p.crypto:eddsa CVE-2020-36843 中危 0.3.0 The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0 ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-36843

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-03-13 06:15 修改: 2026-04-15 00:35

com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq 中危 2.18.2 2.21.1, 2.18.6 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition

漏洞详情: https://github.com/advisories/GHSA-72hv-8253-57qq

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-02-28 02:01 修改: 2026-04-07 16:30

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-31650 中危 10.1.34 9.0.104, 10.1.40, 11.0.6 tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-31650

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-04-28 20:15 修改: 2025-11-03 20:18

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-49124 中危 10.1.34 11.0.8, 10.1.42, 9.0.106 Apache Tomcat installer for Windows has an untrusted search path vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-49124

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-06-16 15:15 修改: 2025-10-29 12:15

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-49125 中危 10.1.34 11.0.8, 10.1.42, 9.0.106 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-49125

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-06-16 15:15 修改: 2025-11-03 20:19

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-66614 中危 10.1.34 11.0.15, 10.1.50, 9.0.113 tomcat: Client certificate verification bypass due to virtual host mapping

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66614

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-02-17 19:21 修改: 2026-03-11 16:16

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-25854 中危 10.1.34 9.0.116, 10.1.53, 11.0.20 Apache Tomcat: Apache Tomcat: Open Redirect vulnerability via LoadBalancerDrainingValve

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25854

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-09 20:16 修改: 2026-04-14 14:01

org.apache.commons:commons-lang3 CVE-2025-48924 中危 3.17.0 3.18.0 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-07-11 15:15 修改: 2025-11-04 22:16

com.google.guava:guava CVE-2023-2976 中危 30.1-jre 32.0.0-android guava: insecure temporary directory creation

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-2976

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2023-06-14 18:15 修改: 2026-02-25 18:16

org.apache.zookeeper:zookeeper CVE-2025-58457 中危 3.9.3 3.9.4 org.apache.zookeeper/zookeeper: Apache ZooKeeper: Insufficient Permission Check

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58457

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-09-24 10:15 修改: 2025-11-04 22:16

org.bouncycastle:bcpkix-jdk15on CVE-2025-8916 中危 1.68 1.79 org.bouncycastle: BouncyCastle denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8916

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-08-13 10:15 修改: 2026-05-12 13:17

org.bouncycastle:bcpkix-jdk15on CVE-2026-5588 中危 1.68 1.84 bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5588

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-15 10:16 修改: 2026-05-19 00:16

org.bouncycastle:bcprov-jdk15on CVE-2023-33201 中危 1.68 bouncycastle: potential blind LDAP injection attack using a self-signed certificate

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-33201

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2023-07-05 03:15 修改: 2024-11-21 08:05

org.bouncycastle:bcprov-jdk15on CVE-2023-33202 中危 1.68 1.70 bc-java: Out of memory while parsing ASN.1 crafted data in org.bouncycastle.openssl.PEMParser class

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-33202

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2023-11-23 16:15 修改: 2025-08-18 17:15

org.bouncycastle:bcprov-jdk15on CVE-2024-29857 中危 1.68 1.78 org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29857

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2024-05-14 15:17 修改: 2026-04-15 00:35

org.bouncycastle:bcprov-jdk15on CVE-2024-30171 中危 1.68 1.78 bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-30171

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2024-05-14 15:21 修改: 2026-04-15 00:35

org.bouncycastle:bcprov-jdk15on CVE-2024-34447 中危 1.68 1.78 org.bouncycastle: Use of Incorrectly-Resolved Name or Reference

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34447

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2024-05-03 16:15 修改: 2026-04-15 00:35

org.eclipse.angus:smtp CVE-2025-7962 中危 2.0.3 2.0.4 com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-7962

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-07-21 18:15 修改: 2025-11-13 18:36

org.apache.kafka:kafka-clients CVE-2025-27817 中危 3.7.1 3.9.1 org.apache.kafka: Kafka Client Arbitrary File Read SSRF

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-27817

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-06-10 08:15 修改: 2025-07-11 16:58

org.apache.kafka:kafka-clients CVE-2026-33558 中危 3.7.1 3.9.2, 4.0.1 Apache Kafka exposes sensitive information in its DEBUG logs

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33558

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-20 14:16 修改: 2026-04-22 14:16

org.apache.logging.log4j:log4j-core CVE-2025-68161 中危 2.24.3 2.25.3 Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68161

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-12-18 21:15 修改: 2026-01-20 01:15

org.apache.logging.log4j:log4j-core CVE-2026-34477 中危 2.24.3 2.25.4 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34477

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-10 16:16 修改: 2026-05-06 16:49

org.apache.logging.log4j:log4j-core CVE-2026-34478 中危 2.24.3 2.25.4 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34478

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-10 16:16 修改: 2026-04-24 18:10

org.apache.logging.log4j:log4j-core CVE-2026-34480 中危 2.24.3 2.25.4 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34480

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-10 16:16 修改: 2026-04-24 18:21

org.apache.poi:poi-ooxml CVE-2025-31672 中危 4.1.2 5.4.0 org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-31672

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-04-09 12:15 修改: 2025-07-15 19:08

io.netty:netty-codec-http CVE-2025-67735 中危 4.1.117.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-67735

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-12-16 01:15 修改: 2026-01-02 18:50

io.netty:netty-codec-http CVE-2026-41417 中危 4.1.117.Final 4.1.133.Final, 4.2.13.Final netty: Netty: HTTP request smuggling via URI manipulation and CRLF injection

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41417

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-06 22:16 修改: 2026-05-11 14:29

io.netty:netty-codec-http CVE-2026-42580 中危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: Netty: Request smuggling via chunk size parser integer overflow

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42580

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 14:03

io.netty:netty-codec-http CVE-2026-42581 中危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42581

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 13:14

io.netty:netty-codec-http CVE-2026-42585 中危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42585

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:24

org.springframework:spring-web CVE-2025-41234 中危 6.2.2 6.2.8, 6.1.21 springframework: Reflected download attack in Spring Framework with non-ASCII headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-41234

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-06-12 22:15 修改: 2026-04-15 00:35

org.springframework:spring-webflux CVE-2026-22737 中危 6.2.2 7.0.6, 6.2.17 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22737

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-20 00:16 修改: 2026-04-23 14:20

org.springframework:spring-webflux CVE-2026-22745 中危 6.2.2 7.0.7, 6.2.18 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22745

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-29 12:16 修改: 2026-05-04 14:50

org.springframework:spring-webmvc CVE-2025-41242 中危 6.2.2 6.2.10 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerability

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-41242

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-08-18 09:15 修改: 2026-04-15 00:35

org.springframework:spring-webmvc CVE-2026-22737 中危 6.2.2 7.0.6, 6.2.17 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22737

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-20 00:16 修改: 2026-04-23 14:20

org.springframework:spring-webmvc CVE-2026-22745 中危 6.2.2 7.0.7, 6.2.18 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22745

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-29 12:16 修改: 2026-05-04 14:50

io.modelcontextprotocol.sdk:mcp-core CVE-2026-34237 中危 0.17.0 1.0.1, 1.1.1 MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34237

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-31 16:16 修改: 2026-04-03 14:29

ch.qos.logback:logback-core CVE-2025-11226 中危 1.5.16 1.5.19, 1.3.16 ch.qos.logback/logback-core: Conditional abitrary code execution in logback-core

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-11226

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-01 08:15 修改: 2026-04-15 00:35

io.netty:netty-codec CVE-2025-58057 中危 4.1.117.Final 4.1.125.Final netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58057

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-09-04 10:42 修改: 2025-09-08 16:45

io.netty:netty-codec-mqtt CVE-2026-44248 中危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44248

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:15

io.netty:netty-codec-redis CVE-2026-42586 中危 4.1.117.Final 4.2.13.Final, 4.1.133.Final netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42586

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 18:02

commons-lang:commons-lang CVE-2025-48924 中危 2.6 commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48924

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-07-11 15:15 修改: 2025-11-04 22:16

io.netty:netty-common CVE-2025-25193 中危 4.1.117.Final 4.1.118.Final netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-25193

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-02-10 22:15 修改: 2025-06-11 15:36

commons-net:commons-net CVE-2021-37533 中危 3.8.0 3.9.0 apache-commons-net: FTP client trusts the host from PASV response by default

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-37533

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2022-12-03 15:15 修改: 2025-04-24 16:15

xerces:xercesImpl CVE-2020-14338 中危 2.11.0 2.12.0.sp3 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-14338

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2020-09-17 15:15 修改: 2024-11-21 05:03

xerces:xercesImpl CVE-2022-23437 中危 2.11.0 2.12.2 xerces-j2: infinite loop when handling specially crafted XML document payloads

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23437

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2022-01-24 15:15 修改: 2024-11-21 06:48

org.springframework:spring-webflux CVE-2026-22741 低危 6.2.2 7.0.7, 6.2.18 Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22741

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-29 12:16 修改: 2026-05-04 14:51

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-55754 低危 10.1.34 11.0.11, 10.1.45, 9.0.109 org.apache.tomcat/tomcat-juli: tomcat: Apache Tomcat: console manipulation

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-55754

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-27 18:15 修改: 2026-05-12 13:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-61795 低危 10.1.34 11.0.12, 10.1.47, 9.0.110 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61795

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-10-27 18:15 修改: 2026-05-12 13:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-24733 低危 10.1.34 11.0.15, 10.1.50, 9.0.113 tomcat: security constraint bypass with HTTP/0.9

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-24733

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-02-17 19:21 修改: 2026-03-11 16:16

org.springframework:spring-webmvc CVE-2026-22735 低危 6.2.2 7.0.6, 6.2.17 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22735

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-20 00:16 修改: 2026-04-23 14:21

org.springframework:spring-webmvc CVE-2026-22741 低危 6.2.2 7.0.7, 6.2.18 Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22741

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-29 12:16 修改: 2026-05-04 14:51

org.apache.tomcat.embed:tomcat-embed-core CVE-2026-43514 低危 10.1.34 9.0.118, 10.1.55, 11.0.22 Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-43514

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-12 16:16 修改: 2026-05-14 18:46

io.netty:netty-handler-proxy CVE-2026-42578 低危 4.1.117.Final 4.1.133.Final, 4.2.13.Final netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42578

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-05-13 19:17 修改: 2026-05-18 12:54

io.netty:netty-codec-http CVE-2025-58056 低危 4.1.117.Final 4.1.125.Final, 4.2.5.Final netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58056

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-09-03 21:15 修改: 2025-09-08 16:46

org.springframework:spring-context CVE-2025-22233 低危 6.2.2 6.2.7, 6.1.20 CVE-2024-38820 ensured Locale-independent, lowercase conversion for bo ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22233

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-05-16 20:15 修改: 2026-04-15 00:35

ch.qos.logback:logback-core CVE-2026-1225 低危 1.5.16 1.5.25 ch.qos.logback/logback-core: Malicious logback.xml configuration file allows instantiation of arbitrary classes

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1225

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-01-22 10:16 修改: 2026-04-15 00:35

com.google.guava:guava CVE-2020-8908 低危 30.1-jre 32.0.0-android guava: local information disclosure via temporary directory created with unsafe permissions

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-8908

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2020-12-10 23:15 修改: 2026-02-23 21:17

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-31651 低危 10.1.34 9.0.104, 10.1.40, 11.0.6 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-31651

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-04-28 20:15 修改: 2025-11-03 20:18

org.apache.tomcat.embed:tomcat-embed-core CVE-2025-46701 低危 10.1.34 9.0.105, 10.1.41, 11.0.7 tomcat: Apache Tomcat: Security constraint bypass for CGI scripts

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-46701

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2025-05-29 19:15 修改: 2025-11-03 20:19

org.springframework:spring-webflux CVE-2026-22735 低危 6.2.2 7.0.6, 6.2.17 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22735

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-03-20 00:16 修改: 2026-04-23 14:21

org.springframework:spring-webflux CVE-2026-22740 低危 6.2.2 7.0.7, 6.2.18 spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22740

镜像层: sha256:8a8b1ab9f3b00f4bf515a736cdd2b4a207a8f7fddeec33a21d85c85698716257

发布日期: 2026-04-29 12:16 修改: 2026-05-04 14:51

/etc/ssh/ssh_host_ecdsa_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
/etc/ssh/ssh_host_ed25519_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
/etc/ssh/ssh_host_rsa_key ()
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息