docker.io/goharbor/nginx-photon:v2.15.1 linux/amd64

docker.io/goharbor/nginx-photon:v2.15.1 - Trivy安全扫描结果 扫描时间: 2026-06-10 09:17
全部漏洞信息
低危漏洞:1 中危漏洞:13 高危漏洞:19 严重漏洞:7

系统OS: photon 5.0 扫描引擎: Trivy 扫描时间: 2026-06-10 09:17

docker.io/goharbor/nginx-photon:v2.15.1 (photon 5.0) (photon)
低危漏洞:1 中危漏洞:13 高危漏洞:19 严重漏洞:7
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
glibc CVE-2026-5450 严重 2.36-23.1.ph5 2.43-3.ph5 glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5450

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-04-20 21:16 修改: 2026-04-23 15:33

glibc-iconv CVE-2026-5450 严重 2.36-23.1.ph5 2.43-3.ph5 glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5450

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-04-20 21:16 修改: 2026-04-23 15:33

glibc-libs CVE-2026-5450 严重 2.36-23.1.ph5 2.43-3.ph5 glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5450

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-04-20 21:16 修改: 2026-04-23 15:33

gnutls BDSA-2026-8632 严重 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls BDSA-2026-8687 严重 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls CVE-2026-33845 严重 3.7.10-8.ph5 3.8.13-1.ph5 gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33845

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-04-30 18:16 修改: 2026-06-02 16:16

gnutls CVE-2026-42010 严重 3.7.10-8.ph5 3.8.13-1.ph5 gnutls: gnutls: Authentication Bypass via NUL Character in Username

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42010

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-05-07 12:16 修改: 2026-06-02 16:16

glibc CVE-2026-5928 高危 2.36-23.1.ph5 2.43-3.ph5 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5928

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-04-20 21:16 修改: 2026-04-23 15:33

curl CVE-2026-6276 高危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6276

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:21

glibc-iconv CVE-2026-5928 高危 2.36-23.1.ph5 2.43-3.ph5 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5928

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-04-20 21:16 修改: 2026-04-23 15:33

curl-libs CVE-2026-5773 高危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5773

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:13

glibc-libs CVE-2026-5928 高危 2.36-23.1.ph5 2.43-3.ph5 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5928

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-04-20 21:16 修改: 2026-04-23 15:33

curl-libs CVE-2026-6276 高危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6276

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:21

expat-libs CVE-2026-41080 高危 2.7.5-1.ph5 2.8.0-1.ph5 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41080

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-04-16 17:16 修改: 2026-04-27 07:16

expat-libs CVE-2026-45186 高危 2.7.5-1.ph5 2.8.1-1.ph5 libexpat: denial of service via crafted XML input

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45186

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-10 07:16 修改: 2026-05-14 17:20

curl CVE-2026-5773 高危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5773

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:13

gnutls BDSA-2026-8634 高危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls BDSA-2026-8636 高危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls BDSA-2026-8649 高危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls BDSA-2026-8691 高危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls BDSA-2026-8694 高危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

gnutls CVE-2026-33846 高危 3.7.10-8.ph5 3.8.13-1.ph5 gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33846

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-05-04 10:15 修改: 2026-06-02 16:16

gnutls CVE-2026-3833 高危 3.7.10-8.ph5 3.8.13-1.ph5 gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3833

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-04-30 18:16 修改: 2026-06-02 16:16

gnutls CVE-2026-42011 高危 3.7.10-8.ph5 3.8.13-1.ph5 gnutls: gnutls: Security bypass due to incorrect name constraint handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42011

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 2026-05-07 15:16 修改: 2026-06-02 16:16

libssh2 BDSA-2026-9020 高危 1.11.0-4.ph5 1.11.1-3.ph5

漏洞详情:

镜像层: sha256:ff7b01873518ca998eb8fb59b6878c1347d88407f5736b51b718a2f213d9f08b

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

ncurses-libs CVE-2025-69720 高危 6.5-1.ph5 6.5-2.ph5 ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69720

镜像层: sha256:ff7b01873518ca998eb8fb59b6878c1347d88407f5736b51b718a2f213d9f08b

发布日期: 2026-03-19 15:16 修改: 2026-06-02 14:16

curl-libs CVE-2026-6429 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Credential leak via reused proxy connection during HTTP redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6429

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:18

curl-libs CVE-2026-7168 中危 8.19.0-1.ph5 8.20.0-1.ph5 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7168

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:12

curl CVE-2026-5545 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5545

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:31

curl CVE-2026-6253 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6253

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:40

curl CVE-2026-6429 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Credential leak via reused proxy connection during HTTP redirects

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6429

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:18

curl CVE-2026-7168 中危 8.19.0-1.ph5 8.20.0-1.ph5 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-7168

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 14:12

curl BDSA-2026-9096 中危 8.19.0-1.ph5 8.20.0-1.ph5

漏洞详情:

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl CVE-2026-4873 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: curl: Information disclosure due to incorrect TLS connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4873

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:45

curl-libs BDSA-2026-9096 中危 8.19.0-1.ph5 8.20.0-1.ph5

漏洞详情:

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl-libs CVE-2026-4873 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: curl: Information disclosure due to incorrect TLS connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4873

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:45

gnutls BDSA-2026-8696 中危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00

curl-libs CVE-2026-5545 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5545

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-13 19:31

curl-libs CVE-2026-6253 中危 8.19.0-1.ph5 8.19.0-2.ph5 curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6253

镜像层: sha256:4916eae353cb9c8252001b942b08e3ae90a9999a20b410a1e706677e27246570

发布日期: 2026-05-13 13:01 修改: 2026-05-14 13:40

gnutls BDSA-2026-8695 低危 3.7.10-8.ph5 3.8.13-1.ph5

漏洞详情:

镜像层: sha256:3bd66c8f40cda63380e17d1fc874070910e850669b9164f2711f9f303886e4aa

发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00