| golang.org/x/crypto |
CVE-2026-56854 |
严重 |
v0.54.0 |
0.55.0 |
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56854
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-08-28 16:18 修改: 2026-09-03 16:37
|
| github.com/docker/docker |
CVE-2026-41567 |
高危 |
v28.5.2+incompatible |
|
docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41567
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-06-05 02:17 修改: 2026-09-07 13:19
|
| github.com/docker/docker |
CVE-2026-42306 |
高危 |
v28.5.2+incompatible |
|
github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42306
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-06-12 19:16 修改: 2026-06-17 10:47
|
| github.com/moby/buildkit |
CVE-2026-33747 |
高危 |
v0.25.1 |
0.28.1 |
BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33747
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-03-27 01:16 修改: 2026-06-17 10:38
|
| github.com/moby/buildkit |
CVE-2026-33748 |
高危 |
v0.25.1 |
0.28.1 |
github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33748
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-03-27 15:16 修改: 2026-06-17 10:38
|
| github.com/moby/go-archive |
CVE-2026-17106 |
高危 |
v0.1.0 |
0.3.0 |
github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-17106
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-08-18 19:16 修改: 2026-08-28 15:29
|
| github.com/docker/cli |
CVE-2025-15558 |
高危 |
v28.5.1+incompatible |
29.2.0 |
docker/cli: Docker CLI for Windows: Privilege escalation via malicious plugin binaries
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15558
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-03-04 17:16 修改: 2026-07-15 02:17
|
| golang.org/x/mod |
CVE-2026-56864 |
高危 |
v0.37.0 |
0.40.0 |
A malicious GOSUMDB was capable of serving arbitrary module content no ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56864
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-08-13 22:17 修改: 2026-09-03 16:37
|
| golang.org/x/mod |
CVE-2026-56865 |
高危 |
v0.37.0 |
0.40.0 |
golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56865
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-08-13 22:17 修改: 2026-09-03 16:37
|
| google.golang.org/grpc |
CVE-2026-84304 |
高危 |
v1.82.1 |
1.83.1 |
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-84304
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-09-01 19:17 修改: 2026-09-01 20:17
|
| google.golang.org/grpc |
CVE-2026-84445 |
高危 |
v1.82.1 |
1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e |
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-84445
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| github.com/docker/docker |
CVE-2026-33997 |
中危 |
v28.5.2+incompatible |
29.3.1 |
moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33997
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-03-31 03:15 修改: 2026-09-07 13:19
|
| github.com/docker/docker |
CVE-2026-41568 |
中危 |
v28.5.2+incompatible |
|
github.com/docker/docker: github.com/moby/moby: Moby: Denial of Service via race condition in docker cp mount setup
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41568
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-06-12 19:16 修改: 2026-06-17 10:46
|
| github.com/moby/buildkit |
CVE-2026-61711 |
中危 |
v0.25.1 |
0.31.1 |
github.com/moby/buildkit: BuildKit: Security bypass allows disabling container protections
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-61711
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-08-19 20:17 修改: 2026-08-20 14:17
|
| google.golang.org/grpc |
CVE-2026-84303 |
中危 |
v1.82.1 |
1.83.1 |
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-84303
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-09-01 19:17 修改: 2026-09-02 20:17
|
| github.com/moby/buildkit |
CVE-2026-61712 |
低危 |
v0.25.1 |
0.31.1 |
github.com/moby/buildkit: BuildKit: Denial of Service via unbounded group parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-61712
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-08-19 20:17 修改: 2026-08-21 20:16
|
| golang.org/x/crypto |
GO-2026-5932 |
未知 |
v0.54.0 |
|
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
漏洞详情:
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| golang.org/x/crypto |
CVE-2026-56855 |
未知 |
v0.54.0 |
0.56.0 |
Previously, after a channel has been established, a malicious peer cou ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-56855
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-09-02 20:17 修改: 2026-09-04 16:34
|
| golang.org/x/crypto |
CVE-2026-78662 |
未知 |
v0.54.0 |
0.56.0 |
Previously, a channel registered in the mux's chanList is not usable u ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-78662
镜像层: sha256:e98d92c5504fa9dea28952d65f1249564d7de22a1d123fc78867acde75a796be
发布日期: 2026-09-02 20:17 修改: 2026-09-04 16:33
|