Skip to content

ghcr.io/cyclonedx/cdxgen:master (alma 10.1)

Trivy Image Scan

  • Image: ghcr.io/cyclonedx/cdxgen:master (alma 10.1)
  • Scan date: 2026-02-04

ghcr.io/cyclonedx/cdxgen:master (alma 10.1) (alma)

Package Vulnerability ID Severity Installed Version Fixed Version Links
binutils CVE-2025-11082 MEDIUM 2.41-58.el10.alma.1 2.41-58.el10_1.2.alma.1
binutils CVE-2025-11083 MEDIUM 2.41-58.el10.alma.1 2.41-58.el10_1.2.alma.1
binutils-gold CVE-2025-11082 MEDIUM 2.41-58.el10.alma.1 2.41-58.el10_1.2.alma.1
binutils-gold CVE-2025-11083 MEDIUM 2.41-58.el10.alma.1 2.41-58.el10_1.2.alma.1
glib2 CVE-2025-13601 MEDIUM 2.80.4-10.el10_1 2.80.4-10.el10_1.12
glibc CVE-2026-0861 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc CVE-2026-0915 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-all-langpacks CVE-2026-0861 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-all-langpacks CVE-2026-0915 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-common CVE-2026-0861 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-common CVE-2026-0915 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-devel CVE-2026-0861 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-devel CVE-2026-0915 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-minimal-langpack CVE-2026-0861 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
glibc-minimal-langpack CVE-2026-0915 MEDIUM 2.39-58.el10_1.2.alma.1 2.39-58.el10_1.7.alma.1
gnupg2 CVE-2025-68973 HIGH 2.4.5-2.el10 2.4.5-3.el10_1
gnupg2-smime CVE-2025-68973 HIGH 2.4.5-2.el10 2.4.5-3.el10_1
httpd CVE-2025-58098 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd CVE-2025-65082 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd CVE-2025-66200 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd-core CVE-2025-58098 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd-core CVE-2025-65082 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd-core CVE-2025-66200 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd-filesystem CVE-2025-58098 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd-filesystem CVE-2025-65082 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
httpd-filesystem CVE-2025-66200 HIGH 2.4.63-4.el10 2.4.63-4.el10_1.3
kernel-headers CVE-2025-38499 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.21.1.el10_1
kernel-headers CVE-2025-39806 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-39840 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-39843 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-39905 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-39966 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-39984 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.21.1.el10_1
kernel-headers CVE-2025-40176 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-40240 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-40277 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-68285 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.28.1.el10_1
kernel-headers CVE-2025-68287 HIGH 6.12.0-124.8.1.el10_1 6.12.0-124.27.1.el10_1
kernel-headers CVE-2025-22068 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.16.1.el10_1
kernel-headers CVE-2025-38383 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.29.1.el10_1
kernel-headers CVE-2025-38724 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.16.1.el10_1
kernel-headers CVE-2025-38737 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.20.1.el10_1
kernel-headers CVE-2025-39730 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.13.1.el10_1
kernel-headers CVE-2025-39883 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.16.1.el10_1
kernel-headers CVE-2025-39918 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.16.1.el10_1
kernel-headers CVE-2025-39925 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.20.1.el10_1
kernel-headers CVE-2025-39955 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.13.1.el10_1
kernel-headers CVE-2025-39971 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.16.1.el10_1
kernel-headers CVE-2025-39979 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.20.1.el10_1
kernel-headers CVE-2025-39981 MEDIUM 6.12.0-124.8.1.el10_1 6.12.0-124.20.1.el10_1
75 other vulnerabilities found...
No Misconfigurations found

Java (jar)

Package Vulnerability ID Severity Installed Version Fixed Version Links
commons-io:commons-io CVE-2024-47554 HIGH 2.8.0 2.14.0
commons-lang:commons-lang CVE-2025-48924 MEDIUM 2.6 no fix available
commons-lang:commons-lang CVE-2025-48924 MEDIUM 2.6 no fix available
net.i2p.crypto:eddsa CVE-2020-36843 MEDIUM 0.3.0 no fix available
org.apache.commons:commons-lang3 CVE-2025-48924 MEDIUM 3.12.0 3.18.0
org.apache.commons:commons-lang3 CVE-2025-48924 MEDIUM 3.14.0 3.18.0
org.eclipse.jetty:jetty-http CVE-2024-6763 MEDIUM 9.4.58.v20250814 12.0.12
org.eclipse.jgit:org.eclipse.jgit CVE-2025-4949 MEDIUM 5.13.3.202401111512-r 7.2.1.202505142326-r, 7.1.1.202505221757-r, 7.0.1.202505221510-r, 6.10.1.202505221210-r, 6.0.0.202111291000-r, 5.13.4.202507202350-r
org.msgpack:msgpack-core CVE-2026-21452 HIGH 0.9.10 0.9.11
No Misconfigurations found

Node.js (node-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
diff CVE-2026-24001 LOW 8.0.2 8.0.3, 5.2.2, 4.0.4, 3.5.1
fast-xml-parser CVE-2026-25128 HIGH 5.3.2 5.3.4
glob CVE-2025-64756 HIGH 10.4.5 11.1.0, 10.5.0
glob CVE-2025-64756 HIGH 11.0.3 11.1.0, 10.5.0
jws CVE-2025-65945 HIGH 3.2.2 3.2.3, 4.0.1
jws CVE-2025-65945 HIGH 4.0.0 3.2.3, 4.0.1
jws CVE-2025-65945 HIGH 4.0.0 3.2.3, 4.0.1
lodash CVE-2025-13465 MEDIUM 4.17.21 4.17.23
qs CVE-2025-15284 HIGH 6.14.0 6.14.1
tar CVE-2026-23745 HIGH 6.2.1 7.5.3
tar CVE-2026-23950 HIGH 6.2.1 7.5.4
tar CVE-2026-24842 HIGH 6.2.1 7.5.7
tar CVE-2026-23745 HIGH 7.5.1 7.5.3
tar CVE-2026-23950 HIGH 7.5.1 7.5.4
tar CVE-2026-24842 HIGH 7.5.1 7.5.7
tar CVE-2025-64118 MEDIUM 7.5.1 7.5.2
tar CVE-2026-23745 HIGH 7.5.2 7.5.3
tar CVE-2026-23745 HIGH 7.5.2 7.5.3
tar CVE-2026-23950 HIGH 7.5.2 7.5.4
tar CVE-2026-23950 HIGH 7.5.2 7.5.4
tar CVE-2026-24842 HIGH 7.5.2 7.5.7
tar CVE-2026-24842 HIGH 7.5.2 7.5.7
undici CVE-2026-22036 MEDIUM 7.16.0 7.18.2, 6.23.0
No Misconfigurations found

Python (python-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
filelock CVE-2025-68146 MEDIUM 3.20.0 3.20.1
filelock CVE-2025-68146 MEDIUM 3.20.0 3.20.1
filelock CVE-2026-22701 MEDIUM 3.20.0 3.20.3
filelock CVE-2026-22701 MEDIUM 3.20.0 3.20.3
jaraco.context CVE-2026-23949 HIGH 5.3.0 6.1.0
jaraco.context CVE-2026-23949 HIGH 5.3.0 6.1.0
jaraco.context CVE-2026-23949 HIGH 6.0.1 6.1.0
lief CVE-2025-15504 LOW 0.17.1 0.17.2
orjson CVE-2025-67221 MEDIUM 3.11.4 no fix available
pip CVE-2026-1703 LOW 25.3 26.0
setuptools CVE-2025-47273 HIGH 77.0.3 78.1.1
urllib3 CVE-2025-66418 HIGH 2.5.0 2.6.0
urllib3 CVE-2025-66471 HIGH 2.5.0 2.6.0
urllib3 CVE-2026-21441 HIGH 2.5.0 2.6.3
virtualenv CVE-2026-22702 MEDIUM 20.35.4 20.36.1
virtualenv CVE-2026-22702 MEDIUM 20.35.4 20.36.1
wheel CVE-2026-24049 HIGH 0.45.1 0.46.2
wheel CVE-2026-24049 HIGH 0.45.1 0.46.2
wheel CVE-2026-24049 HIGH 0.45.1 0.46.2
No Misconfigurations found

Ruby (gemspec)

Package Vulnerability ID Severity Installed Version Fixed Version Links
rexml CVE-2025-58767 MEDIUM 3.4.0 >= 3.4.2
uri CVE-2025-61594 MEDIUM 1.0.3 ~> 0.12.5, ~> 0.13.3, >= 1.0.4
No Misconfigurations found

opt/cdxgen/node_modules/.pnpm/@appthreat+atom-parsetools@1.0.12/node_modules/@appthreat/atom-parsetools/plugins/composer/installed.json (composer-vendor)

No Vulnerabilities found
No Misconfigurations found

usr/local/bin/bazel (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-22874 HIGH v1.24.0 1.24.4
stdlib CVE-2025-47907 HIGH v1.24.0 1.23.12, 1.24.6
stdlib CVE-2025-58183 HIGH v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61726 HIGH v1.24.0 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.24.0 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.24.0 1.24.11, 1.25.5
stdlib CVE-2025-0913 MEDIUM v1.24.0 1.23.10, 1.24.4
stdlib CVE-2025-22871 MEDIUM v1.24.0 1.23.8, 1.24.2
stdlib CVE-2025-4673 MEDIUM v1.24.0 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.24.0 1.23.12, 1.24.6
stdlib CVE-2025-47912 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 MEDIUM v1.24.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61727 MEDIUM v1.24.0 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.24.0 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/bin/go (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/bin/gofmt (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/asm (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/cgo (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/compile (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/cover (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found
Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/preprofile (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/vet (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-61726 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.4 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61727 MEDIUM v1.25.4 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.4 1.24.12, 1.25.6
No Misconfigurations found