ghcr.io/astral-sh/uv:0.11.6 linux/amd64

ghcr.io/astral-sh/uv:0.11.6 - Trivy安全扫描结果 扫描时间: 2026-08-31 22:04
全部漏洞信息
低危漏洞:10 中危漏洞:10 高危漏洞:4 严重漏洞:0

系统OS: 扫描引擎: Trivy 扫描时间: 2026-08-31 22:04

uv (rustbinary)
低危漏洞:5 中危漏洞:5 高危漏洞:2 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
quinn-proto GHSA-4w2j-m93h-cj5j 高危 0.11.14 0.11.15 Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

漏洞详情: https://github.com/advisories/GHSA-4w2j-m93h-cj5j

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-07-24 14:07 修改: 2026-07-24 14:07

rustls-webpki GHSA-82j2-j2ch-gfr8 高危 0.103.10 0.103.13, 0.104.0-alpha.7 rustls-webpki: Denial of service via panic on malformed CRL BIT STRING

漏洞详情: https://github.com/advisories/GHSA-82j2-j2ch-gfr8

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-24 16:20 修改: 2026-04-24 16:20

astral-tokio-tar GHSA-3cv2-h65g-fgmm 中危 0.6.0 0.6.2 astral-tokio-tar has a PAX Header Desynchronization issue

漏洞详情: https://github.com/advisories/GHSA-3cv2-h65g-fgmm

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-29 19:08 修改: 2026-05-29 19:08

rkyv GHSA-vfvv-c25p-m7mm 中危 0.8.15 0.8.16 rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution

漏洞详情: https://github.com/advisories/GHSA-vfvv-c25p-m7mm

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-15 18:09 修改: 2026-05-15 18:09

astral-tokio-tar GHSA-fp55-jw48-c537 中危 0.6.0 0.6.1 astral-tokio-tar is Vulnerable to PAX Header Desynchronization

漏洞详情: https://github.com/advisories/GHSA-fp55-jw48-c537

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-06 17:26 修改: 2026-05-06 17:26

tar GHSA-3pv8-6f4r-ffg2 中危 0.4.45 0.4.46 tar has a PAX header desynchronization issue

漏洞详情: https://github.com/advisories/GHSA-3pv8-6f4r-ffg2

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-29 19:16 修改: 2026-05-29 19:16

uv GHSA-4gg8-gxpx-9rph 中危 0.11.6 0.11.15 uv is vulnerable to arbitrary file write through entry point names

漏洞详情: https://github.com/advisories/GHSA-4gg8-gxpx-9rph

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-29 19:26 修改: 2026-05-29 19:26

rand GHSA-cq8v-f236-94qc 低危 0.8.5 0.9.3, 0.10.1, 0.8.6 Rand is unsound with a custom logger using rand::rng()

漏洞详情: https://github.com/advisories/GHSA-cq8v-f236-94qc

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-14 01:03 修改: 2026-04-22 20:13

rustls-webpki GHSA-965h-392x-2mh5 低危 0.103.10 0.103.12, 0.104.0-alpha.6 webpki: Name constraints for URI names were incorrectly accepted

漏洞详情: https://github.com/advisories/GHSA-965h-392x-2mh5

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-16 21:16 修改: 2026-04-16 21:16

rustls-webpki GHSA-xgp8-3hg3-c2mh 低危 0.103.10 0.103.12, 0.104.0-alpha.6 webpki: Name constraints were accepted for certificates asserting a wildcard name

漏洞详情: https://github.com/advisories/GHSA-xgp8-3hg3-c2mh

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-16 21:17 修改: 2026-04-16 21:17

rand GHSA-cq8v-f236-94qc 低危 0.9.2 0.9.3, 0.10.1, 0.8.6 Rand is unsound with a custom logger using rand::rng()

漏洞详情: https://github.com/advisories/GHSA-cq8v-f236-94qc

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-14 01:03 修改: 2026-04-22 20:13

astral-tokio-tar GHSA-xx64-wwv2-hcqq 低危 0.6.0 0.6.1 astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks

漏洞详情: https://github.com/advisories/GHSA-xx64-wwv2-hcqq

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-06 17:26 修改: 2026-05-06 17:26

uvx (rustbinary)
低危漏洞:5 中危漏洞:5 高危漏洞:2 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
quinn-proto GHSA-4w2j-m93h-cj5j 高危 0.11.14 0.11.15 Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

漏洞详情: https://github.com/advisories/GHSA-4w2j-m93h-cj5j

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-07-24 14:07 修改: 2026-07-24 14:07

rustls-webpki GHSA-82j2-j2ch-gfr8 高危 0.103.10 0.103.13, 0.104.0-alpha.7 rustls-webpki: Denial of service via panic on malformed CRL BIT STRING

漏洞详情: https://github.com/advisories/GHSA-82j2-j2ch-gfr8

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-24 16:20 修改: 2026-04-24 16:20

astral-tokio-tar GHSA-3cv2-h65g-fgmm 中危 0.6.0 0.6.2 astral-tokio-tar has a PAX Header Desynchronization issue

漏洞详情: https://github.com/advisories/GHSA-3cv2-h65g-fgmm

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-29 19:08 修改: 2026-05-29 19:08

rkyv GHSA-vfvv-c25p-m7mm 中危 0.8.15 0.8.16 rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution

漏洞详情: https://github.com/advisories/GHSA-vfvv-c25p-m7mm

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-15 18:09 修改: 2026-05-15 18:09

astral-tokio-tar GHSA-fp55-jw48-c537 中危 0.6.0 0.6.1 astral-tokio-tar is Vulnerable to PAX Header Desynchronization

漏洞详情: https://github.com/advisories/GHSA-fp55-jw48-c537

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-06 17:26 修改: 2026-05-06 17:26

tar GHSA-3pv8-6f4r-ffg2 中危 0.4.45 0.4.46 tar has a PAX header desynchronization issue

漏洞详情: https://github.com/advisories/GHSA-3pv8-6f4r-ffg2

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-29 19:16 修改: 2026-05-29 19:16

uv GHSA-4gg8-gxpx-9rph 中危 0.11.6 0.11.15 uv is vulnerable to arbitrary file write through entry point names

漏洞详情: https://github.com/advisories/GHSA-4gg8-gxpx-9rph

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-29 19:26 修改: 2026-05-29 19:26

rand GHSA-cq8v-f236-94qc 低危 0.8.5 0.9.3, 0.10.1, 0.8.6 Rand is unsound with a custom logger using rand::rng()

漏洞详情: https://github.com/advisories/GHSA-cq8v-f236-94qc

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-14 01:03 修改: 2026-04-22 20:13

rustls-webpki GHSA-965h-392x-2mh5 低危 0.103.10 0.103.12, 0.104.0-alpha.6 webpki: Name constraints for URI names were incorrectly accepted

漏洞详情: https://github.com/advisories/GHSA-965h-392x-2mh5

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-16 21:16 修改: 2026-04-16 21:16

rustls-webpki GHSA-xgp8-3hg3-c2mh 低危 0.103.10 0.103.12, 0.104.0-alpha.6 webpki: Name constraints were accepted for certificates asserting a wildcard name

漏洞详情: https://github.com/advisories/GHSA-xgp8-3hg3-c2mh

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-16 21:17 修改: 2026-04-16 21:17

rand GHSA-cq8v-f236-94qc 低危 0.9.2 0.9.3, 0.10.1, 0.8.6 Rand is unsound with a custom logger using rand::rng()

漏洞详情: https://github.com/advisories/GHSA-cq8v-f236-94qc

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-04-14 01:03 修改: 2026-04-22 20:13

astral-tokio-tar GHSA-xx64-wwv2-hcqq 低危 0.6.0 0.6.1 astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks

漏洞详情: https://github.com/advisories/GHSA-xx64-wwv2-hcqq

镜像层: sha256:fd690ad8777a3e5e2b6b43dae51f51268dcda30fff622c754a3ac2f2fe804ff1

发布日期: 2026-05-06 17:26 修改: 2026-05-06 17:26

检测到您正在使用广告拦截插件,本站为公益站点,依赖广告维持运转 🙏 查看如何关闭 ×