Skip to content

ghcr.io/cyclonedx/cdxgen:master (alma 10.0)

Trivy Image Scan

  • Image: ghcr.io/cyclonedx/cdxgen:master (alma 10.0)
  • Scan date: 2025-11-19

ghcr.io/cyclonedx/cdxgen:master (alma 10.0) (alma)

Package Vulnerability ID Severity Installed Version Fixed Version Links
aspnetcore-runtime-9.0 CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
aspnetcore-runtime-9.0 CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
aspnetcore-runtime-9.0 CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
aspnetcore-targeting-pack-9.0 CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
aspnetcore-targeting-pack-9.0 CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
aspnetcore-targeting-pack-9.0 CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-apphost-pack-9.0 CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-apphost-pack-9.0 CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-apphost-pack-9.0 CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-host CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-host CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-host CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-hostfxr-9.0 CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-hostfxr-9.0 CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-hostfxr-9.0 CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-runtime-9.0 CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-runtime-9.0 CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-runtime-9.0 CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-sdk-9.0 CVE-2025-55247 HIGH 9.0.110-1.el10_0 9.0.111-1.el10_0
dotnet-sdk-9.0 CVE-2025-55248 HIGH 9.0.110-1.el10_0 9.0.111-1.el10_0
dotnet-sdk-9.0 CVE-2025-55315 HIGH 9.0.110-1.el10_0 9.0.111-1.el10_0
dotnet-targeting-pack-9.0 CVE-2025-55247 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-targeting-pack-9.0 CVE-2025-55248 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-targeting-pack-9.0 CVE-2025-55315 HIGH 9.0.9-1.el10_0 9.0.10-1.el10_0
dotnet-templates-9.0 CVE-2025-55247 HIGH 9.0.110-1.el10_0 9.0.111-1.el10_0
dotnet-templates-9.0 CVE-2025-55248 HIGH 9.0.110-1.el10_0 9.0.111-1.el10_0
dotnet-templates-9.0 CVE-2025-55315 HIGH 9.0.110-1.el10_0 9.0.111-1.el10_0
expat CVE-2025-59375 HIGH 2.7.1-1.el10_0 2.7.1-1.el10_0.3
gnutls CVE-2025-32988 MEDIUM 3.8.9-9.el10 3.8.9-9.el10_0.14
gnutls CVE-2025-32989 MEDIUM 3.8.9-9.el10 3.8.9-9.el10_0.14
gnutls CVE-2025-32990 MEDIUM 3.8.9-9.el10 3.8.9-9.el10_0.14
gnutls CVE-2025-6395 MEDIUM 3.8.9-9.el10 3.8.9-9.el10_0.14
kernel-headers CVE-2025-38332 HIGH 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-38392 HIGH 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-38500 HIGH 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-22026 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.38.1.el10_0
kernel-headers CVE-2025-22068 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-37810 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.34.1.el10_0
kernel-headers CVE-2025-38351 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.40.1.el10_0
kernel-headers CVE-2025-38396 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.37.1.el10_0
kernel-headers CVE-2025-38463 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-38498 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-38523 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.37.1.el10_0
kernel-headers CVE-2025-38527 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.37.1.el10_0
kernel-headers CVE-2025-38550 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.33.1.el10_0
kernel-headers CVE-2025-38556 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.39.1.el10_0
kernel-headers CVE-2025-38566 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.34.1.el10_0
kernel-headers CVE-2025-38571 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.40.1.el10_0
kernel-headers CVE-2025-38572 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.40.1.el10_0
kernel-headers CVE-2025-38614 MEDIUM 6.12.0-55.32.1.el10_0 6.12.0-55.40.1.el10_0
13 other vulnerabilities found...
No Misconfigurations found

Java (jar)

Package Vulnerability ID Severity Installed Version Fixed Version Links
commons-io:commons-io CVE-2024-47554 HIGH 2.8.0 2.14.0
commons-lang:commons-lang CVE-2025-48924 MEDIUM 2.6 no fix available
commons-lang:commons-lang CVE-2025-48924 MEDIUM 2.6 no fix available
commons-lang:commons-lang CVE-2025-48924 MEDIUM 2.6 no fix available
net.i2p.crypto:eddsa CVE-2020-36843 MEDIUM 0.3.0 no fix available
org.apache.commons:commons-lang3 CVE-2025-48924 MEDIUM 3.12.0 3.18.0
org.apache.commons:commons-lang3 CVE-2025-48924 MEDIUM 3.14.0 3.18.0
org.eclipse.jetty:jetty-http CVE-2024-6763 MEDIUM 9.4.58.v20250814 12.0.12
org.eclipse.jgit:org.eclipse.jgit CVE-2025-4949 MEDIUM 5.13.3.202401111512-r 7.2.1.202505142326-r, 7.1.1.202505221757-r, 7.0.1.202505221510-r, 6.10.1.202505221210-r
No Misconfigurations found

Node.js (node-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
glob CVE-2025-64756 HIGH 10.4.5 11.1.0, 10.5.0
glob CVE-2025-64756 HIGH 10.4.5 11.1.0, 10.5.0
glob CVE-2025-64756 HIGH 11.0.3 11.1.0, 10.5.0
got CVE-2022-33987 MEDIUM 9.6.0 12.1.0, 11.8.5
js-yaml CVE-2025-64718 MEDIUM 3.13.1 4.1.1, 3.14.2
js-yaml CVE-2025-64718 MEDIUM 3.14.1 4.1.1, 3.14.2
js-yaml CVE-2025-64718 MEDIUM 4.1.0 4.1.1, 3.14.2
js-yaml CVE-2025-64718 MEDIUM 4.1.0 4.1.1, 3.14.2
js-yaml CVE-2025-64718 MEDIUM 4.1.0 4.1.1, 3.14.2
tar-fs CVE-2025-59343 HIGH 3.1.0 3.1.1, 2.1.4, 1.16.6
tmp CVE-2025-54798 LOW 0.0.33 0.2.4
validator CVE-2025-56200 MEDIUM 13.15.15 13.15.20
No Misconfigurations found

Python (python-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
pip CVE-2025-8869 MEDIUM 25.2 25.3
setuptools CVE-2025-47273 HIGH 77.0.3 78.1.1
uv GHSA-pqhf-p39g-3x64 MEDIUM 0.8.17 0.9.6
uv GHSA-w476-p2h3-79g9 LOW 0.8.17 0.9.5
No Misconfigurations found

Ruby (gemspec)

Package Vulnerability ID Severity Installed Version Fixed Version Links
rexml CVE-2025-58767 MEDIUM 3.4.0 >= 3.4.2
uri CVE-2025-61594 UNKNOWN 1.0.3 ~> 0.12.5, ~> 0.13.3, >= 1.0.4
No Misconfigurations found

opt/cdxgen/node_modules/.pnpm/@appthreat+atom-parsetools@1.0.8/node_modules/@appthreat/atom-parsetools/plugins/composer/installed.json (composer-vendor)

No Vulnerabilities found
No Misconfigurations found

usr/local/bin/bazel (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-22874 HIGH v1.24.0 1.24.4
stdlib CVE-2025-47907 HIGH v1.24.0 1.23.12, 1.24.6
stdlib CVE-2025-58183 HIGH v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.24.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-0913 MEDIUM v1.24.0 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.24.0 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.24.0 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.24.0 1.23.12, 1.24.6
stdlib CVE-2025-47912 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.24.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/bin/go (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/bin/gofmt (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/asm (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/cgo (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/compile (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/cover (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found
Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/preprofile (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/vet (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-58183 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 HIGH v1.25.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 HIGH v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-47910 MEDIUM v1.25.0 1.25.1
stdlib CVE-2025-47912 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.25.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.25.0 1.24.8, 1.25.2
No Misconfigurations found