ghcr.io/dask/dask-notebook:latest linux/amd64

ghcr.io/dask/dask-notebook:latest - Trivy安全扫描结果 扫描时间: 2026-01-23 11:25
全部漏洞信息
低危漏洞:31 中危漏洞:35 高危漏洞:7 严重漏洞:0

系统OS: ubuntu 24.04 扫描引擎: Trivy 扫描时间: 2026-01-23 11:25

ghcr.io/dask/dask-notebook:latest (ubuntu 24.04) (ubuntu)
低危漏洞:31 中危漏洞:13 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
git CVE-2024-52005 中危 1:2.43.0-1ubuntu7.3 git: The sideband payload is passed unfiltered to the terminal in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52005

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-01-15 18:15 修改: 2025-12-18 16:00

git-man CVE-2024-52005 中危 1:2.43.0-1ubuntu7.3 git: The sideband payload is passed unfiltered to the terminal in git

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52005

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-01-15 18:15 修改: 2025-12-18 16:00

gpgv CVE-2025-68972 中危 2.4.4-2ubuntu17.4 gnupg: GnuPG: Signature bypass via form feed character in signed messages

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-68972

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-12-27 23:15 修改: 2026-01-09 20:08

libde265-0 CVE-2024-38949 中危 1.0.15-1build3 Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38949

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2024-06-26 20:15 修改: 2025-06-06 17:15

libde265-0 CVE-2024-38950 中危 1.0.15-1build3 Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38950

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2024-06-26 20:15 修改: 2025-06-06 17:15

libexpat1 CVE-2025-66382 中危 2.6.1-2ubuntu0.3 libexpat: libexpat: Denial of service via crafted file processing

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66382

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-11-28 07:15 修改: 2025-12-19 16:05

libpam-modules CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpam-modules-bin CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpam-runtime CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpam0g CVE-2025-8941 中危 1.5.3-5ubuntu5.5 linux-pam: Incomplete fix for CVE-2025-6020

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8941

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-08-13 15:15 修改: 2025-11-20 21:16

libpixman-1-0 CVE-2023-37769 中危 0.42.2-1build1 stress-test master commit e4c878 was discovered to contain a FPE vulne ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-37769

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2023-07-17 20:15 修改: 2024-11-21 08:12

tar CVE-2025-45582 中危 1.35+dfsg-3build1 tar: Tar path traversal

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-45582

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2025-07-11 17:15 修改: 2025-11-02 01:15

wget CVE-2021-31879 中危 1.21.4-1ubuntu4.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:bfc1a3ec736eaeb1a8af4094b0777d3a2116065c1e5588add69018de9bc45164

发布日期: 2021-04-29 05:15 修改: 2024-11-21 06:06

libcairo2 CVE-2018-18064 低危 1.18.0-3build1 cairo: Stack-based buffer overflow via parsing of crafted WebKitGTK+ document

漏洞详情: https://avd.aquasec.com/nvd/cve-2018-18064

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2018-10-08 18:29 修改: 2024-11-21 03:55

libcairo2 CVE-2019-6461 低危 1.18.0-3build1 cairo: assertion problem in _cairo_arc_in_direction in cairo-arc.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2019-6461

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2019-01-16 18:29 修改: 2024-11-21 04:46

libcurl3t64-gnutls CVE-2025-0167 低危 8.5.0-2ubuntu10.6 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-02-05 10:15 修改: 2025-07-30 19:41

libcurl3t64-gnutls CVE-2025-10148 低危 8.5.0-2ubuntu10.6 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:55

libcurl3t64-gnutls CVE-2025-14524 低危 8.5.0-2ubuntu10.6 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:53

libcurl3t64-gnutls CVE-2025-14819 低危 8.5.0-2ubuntu10.6 When doing TLS related transfers with reused easy or multi handles and ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14819

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:51

libcurl3t64-gnutls CVE-2025-15079 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and setting t ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:50

libcurl3t64-gnutls CVE-2025-15224 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and asked to ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:47

libcurl3t64-gnutls CVE-2025-9086 低危 8.5.0-2ubuntu10.6 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:58

libcurl4t64 CVE-2025-0167 低危 8.5.0-2ubuntu10.6 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-02-05 10:15 修改: 2025-07-30 19:41

libcurl4t64 CVE-2025-10148 低危 8.5.0-2ubuntu10.6 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:55

libcurl4t64 CVE-2025-14524 低危 8.5.0-2ubuntu10.6 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:53

libcurl4t64 CVE-2025-14819 低危 8.5.0-2ubuntu10.6 When doing TLS related transfers with reused easy or multi handles and ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14819

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:51

libcurl4t64 CVE-2025-15079 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and setting t ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:50

libcurl4t64 CVE-2025-15224 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and asked to ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:47

libcurl4t64 CVE-2025-9086 低危 8.5.0-2ubuntu10.6 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:58

curl CVE-2025-14524 低危 8.5.0-2ubuntu10.6 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14524

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:53

curl CVE-2025-14819 低危 8.5.0-2ubuntu10.6 When doing TLS related transfers with reused easy or multi handles and ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-14819

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:51

curl CVE-2025-15079 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and setting t ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15079

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:50

libgcrypt20 CVE-2024-2236 低危 1.10.3-2build1 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2024-03-06 22:15 修改: 2025-04-02 17:15

libharfbuzz0b CVE-2026-22693 低危 8.3.0-2build2 harfbuzz: Null Pointer Dereference in harfbuzz

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-22693

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-10 06:15 修改: 2026-01-13 14:03

curl CVE-2025-15224 低危 8.5.0-2ubuntu10.6 When doing SSH-based transfers using either SCP or SFTP, and asked to ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-15224

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2026-01-08 10:15 修改: 2026-01-20 14:47

curl CVE-2025-9086 低危 8.5.0-2ubuntu10.6 curl: libcurl: Curl out of bounds read for cookie path

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-9086

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:58

coreutils CVE-2016-2781 低危 9.4-3ubuntu6.1 coreutils: Non-privileged session can escape to the parent session in chroot

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2781

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2017-02-07 15:59 修改: 2025-06-09 16:15

curl CVE-2025-0167 低危 8.5.0-2ubuntu10.6 When asked to use a `.netrc` file for credentials **and** to follow HT ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0167

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-02-05 10:15 修改: 2025-07-30 19:41

curl CVE-2025-10148 低危 8.5.0-2ubuntu10.6 curl: predictable WebSocket mask

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-10148

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2025-09-12 06:15 修改: 2026-01-20 14:55

login CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

passwd CVE-2024-56433 低危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

gpgv CVE-2022-3219 低危 2.4.4-2ubuntu17.4 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:123a078714d5ea9382d4d9f550753aefce8b34ec5ae11ae8273038d3bcbb943f

发布日期: 2023-02-23 20:15 修改: 2025-03-12 21:15

libcairo2 CVE-2017-7475 低危 1.18.0-3build1 cairo: NULL pointer dereference with a crafted font file

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-7475

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2017-05-19 20:29 修改: 2025-04-20 01:37

x11-common CVE-2023-5574 低危 1:7.7+23ubuntu3 xorg-x11-server: Use-after-free bug in DamageDestroy

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5574

镜像层: sha256:8cace7a442bdd833fdf1040d7a9f8e1518093ec0beced24b740c89f8fec23c66

发布日期: 2023-10-25 20:15 修改: 2024-11-21 08:42

Node.js (node-pkg)
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
Python (python-pkg)
低危漏洞:0 中危漏洞:1 高危漏洞:2 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
jaraco.context CVE-2026-23949 高危 5.3.0 6.1.0 jaraco.context: jaraco.context: Path traversal via malicious tar archives

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-23949

镜像层: sha256:8dde4d4f3861b32f2812b78324b4d422e7d3fe6bed20337d79e371de13b8d8d7

发布日期: 2026-01-20 01:15 修改: 2026-01-20 01:15

nbconvert CVE-2025-53000 高危 7.16.6 nbconvert: nbconvert: Arbitrary code execution via malicious SVG to PDF conversion on Windows

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-53000

镜像层: sha256:be8c7752de847436ec47922ca628f1625c0f20e8556b3945e2a0182c7d8dfa55

发布日期: 2025-12-17 21:16 修改: 2026-01-02 15:03

bokeh CVE-2026-21883 中危 3.8.1 3.8.2 Bokeh: Bokeh: Information disclosure and unauthorized actions via flawed WebSocket origin validation

漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21883

镜像层: sha256:be8c7752de847436ec47922ca628f1625c0f20e8556b3945e2a0182c7d8dfa55

发布日期: 2026-01-08 02:15 修改: 2026-01-08 18:08

usr/local/bin/kubectl (gobinary)
低危漏洞:0 中危漏洞:21 高危漏洞:5 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
golang.org/x/oauth2 CVE-2025-22868 高危 v0.21.0 0.27.0 golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22868

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-02-26 08:14 修改: 2025-05-01 19:27

stdlib CVE-2024-34156 高危 1.22.5 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34156

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2024-09-06 21:15 修改: 2024-11-21 09:18

stdlib CVE-2025-47907 高危 1.22.5 1.23.12, 1.24.6 database/sql: Postgres Scan Race Condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47907

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-08-07 16:15 修改: 2025-11-04 22:16

stdlib CVE-2025-58183 高危 1.22.5 1.24.8, 1.25.2 golang: archive/tar: Unbounded allocation when parsing GNU sparse map

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58183

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-61729 高危 1.22.5 1.24.11, 1.25.5 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61729

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-12-02 19:15 修改: 2025-12-19 18:25

golang.org/x/net CVE-2025-22872 中危 v0.26.0 0.38.0 golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22872

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-04-16 18:16 修改: 2025-05-16 23:15

golang.org/x/net CVE-2025-22870 中危 v0.26.0 0.36.0 golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22870

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-03-12 19:15 修改: 2025-05-09 20:15

stdlib CVE-2024-34155 中危 1.22.5 1.22.7, 1.23.1 go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34155

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2024-09-06 21:15 修改: 2024-11-21 09:18

stdlib CVE-2024-34158 中危 1.22.5 1.22.7, 1.23.1 go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34158

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2024-09-06 21:15 修改: 2024-11-21 09:18

stdlib CVE-2024-45336 中危 1.22.5 1.22.11, 1.23.5, 1.24.0-rc.2 golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45336

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-01-28 02:15 修改: 2025-02-21 18:15

stdlib CVE-2024-45341 中危 1.22.5 1.22.11, 1.23.5, 1.24.0-rc.2 golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45341

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-01-28 02:15 修改: 2025-02-21 18:15

stdlib CVE-2025-0913 中危 1.22.5 1.23.10, 1.24.4 Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-0913

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-06-11 18:15 修改: 2025-08-08 14:53

stdlib CVE-2025-22866 中危 1.22.5 1.22.12, 1.23.6, 1.24.0-rc.3 crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22866

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-02-06 17:15 修改: 2025-02-21 18:15

stdlib CVE-2025-22871 中危 1.22.5 1.23.8, 1.24.2 net/http: Request smuggling due to acceptance of invalid chunked data in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-22871

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-04-08 20:15 修改: 2025-04-18 15:15

stdlib CVE-2025-4673 中危 1.22.5 1.23.10, 1.24.4 net/http: Sensitive headers not cleared on cross-origin redirect in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-4673

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-06-11 17:15 修改: 2025-06-12 16:06

stdlib CVE-2025-47906 中危 1.22.5 1.23.12, 1.24.6 os/exec: Unexpected paths returned from LookPath in os/exec

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47906

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-09-18 19:15 修改: 2025-11-04 22:16

stdlib CVE-2025-47912 中危 1.22.5 1.24.8, 1.25.2 net/url: Insufficient validation of bracketed IPv6 hostnames in net/url

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47912

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-58185 中危 1.22.5 1.24.8, 1.25.2 encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58185

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-58186 中危 1.22.5 1.24.8, 1.25.2 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58186

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-58187 中危 1.22.5 1.24.9, 1.25.3 crypto/x509: Quadratic complexity when checking name constraints in crypto/x509

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58187

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-20 23:15

stdlib CVE-2025-58188 中危 1.22.5 1.24.8, 1.25.2 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58188

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-58189 中危 1.22.5 1.24.8, 1.25.2 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-58189

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-61723 中危 1.22.5 1.24.8, 1.25.2 encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61723

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-61724 中危 1.22.5 1.24.8, 1.25.2 net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61724

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-11-04 22:16

stdlib CVE-2025-61725 中危 1.22.5 1.24.8, 1.25.2 net/mail: Excessive CPU consumption in ParseAddress in net/mail

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61725

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-10-29 23:16 修改: 2025-12-09 18:15

stdlib CVE-2025-61727 中危 1.22.5 1.24.11, 1.25.5 golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-61727

镜像层: sha256:94ac595ba285f99f22f5f51c9452ffad1187713d39b1881e061105a5a8ef6e85

发布日期: 2025-12-03 20:16 修改: 2025-12-18 20:15