Skip to content

ghcr.io/cyclonedx/cdxgen:master (alma 10.1)

Trivy Image Scan

  • Image: ghcr.io/cyclonedx/cdxgen:master (alma 10.1)
  • Scan date: 2026-04-24

ghcr.io/cyclonedx/cdxgen:master (alma 10.1) (alma)

Package Vulnerability ID Severity Installed Version Fixed Version Links
capstone CVE-2025-67873 HIGH 5.0.1-6.el10 5.0.1-7.el10_1
capstone CVE-2025-68114 HIGH 5.0.1-6.el10 5.0.1-7.el10_1
kernel-headers CVE-2025-38109 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
kernel-headers CVE-2026-23144 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
kernel-headers CVE-2026-23171 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
kernel-headers CVE-2026-23191 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
kernel-headers CVE-2026-23193 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
kernel-headers CVE-2026-23204 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
kernel-headers CVE-2026-23209 MEDIUM 6.12.0-124.47.1.el10_1 6.12.0-124.49.1.el10_1
libarchive CVE-2026-4424 HIGH 3.7.7-5.el10_1 3.7.7-8.el10_1
libnghttp2 CVE-2026-27135 HIGH 1.64.0-2.el10 1.64.0-2.el10_1.1
nginx-filesystem CVE-2026-27651 HIGH 2:1.26.3-2.el10_1 2:1.26.3-2.el10_1.1
nginx-filesystem CVE-2026-27654 HIGH 2:1.26.3-2.el10_1 2:1.26.3-2.el10_1.1
nginx-filesystem CVE-2026-27784 HIGH 2:1.26.3-2.el10_1 2:1.26.3-2.el10_1.1
nginx-filesystem CVE-2026-32647 HIGH 2:1.26.3-2.el10_1 2:1.26.3-2.el10_1.1
No Misconfigurations found

Java (jar)

Package Vulnerability ID Severity Installed Version Fixed Version Links
com.fasterxml.jackson.core:jackson-core GHSA-72hv-8253-57qq MEDIUM 2.15.1 2.21.1, 2.18.6
commons-io:commons-io CVE-2024-47554 HIGH 2.8.0 2.14.0
commons-lang:commons-lang CVE-2025-48924 MEDIUM 2.6 no fix available
org.apache.commons:commons-lang3 CVE-2025-48924 MEDIUM 3.12.0 3.18.0
org.bouncycastle:bcpg-jdk18on CVE-2026-3505 HIGH 1.81 1.84
org.bouncycastle:bcprov-jdk18on CVE-2026-0636 MEDIUM 1.81 1.84
org.codehaus.plexus:plexus-utils CVE-2025-67030 HIGH 3.3.1 4.0.3, 3.6.1
org.codehaus.plexus:plexus-utils CVE-2025-67030 HIGH 3.4.1 4.0.3, 3.6.1
org.codehaus.plexus:plexus-utils CVE-2025-67030 HIGH 3.5.1 4.0.3, 3.6.1
org.codehaus.plexus:plexus-utils CVE-2025-67030 HIGH 3.6.0 4.0.3, 3.6.1
org.eclipse.jetty:jetty-http CVE-2026-2332 HIGH 9.4.58.v20250814 12.1.7, 12.0.33, 11.0.28, 10.0.28, 9.4.60
org.eclipse.jetty:jetty-http CVE-2024-6763 MEDIUM 9.4.58.v20250814 12.0.12
org.msgpack:msgpack-core CVE-2026-21452 HIGH 0.9.10 0.9.11
No Misconfigurations found

Node.js (node-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
brace-expansion CVE-2026-33750 MEDIUM 5.0.3 5.0.5, 3.0.2, 2.0.3, 1.1.13
fast-xml-parser CVE-2026-41650 MEDIUM 5.5.11 5.7.0
lodash CVE-2026-4800 HIGH 4.17.23 4.18.0
lodash CVE-2026-2950 MEDIUM 4.17.23 4.18.0
minimatch CVE-2026-27903 HIGH 10.2.2 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
minimatch CVE-2026-27904 HIGH 10.2.2 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
picomatch CVE-2026-33671 HIGH 4.0.3 4.0.4, 3.0.2, 2.3.2
picomatch CVE-2026-33672 MEDIUM 4.0.3 4.0.4, 3.0.2, 2.3.2
tar CVE-2026-29786 HIGH 7.5.9 7.5.10
tar CVE-2026-31802 HIGH 7.5.9 7.5.11
uuid GHSA-w5hq-g745-h8pq MEDIUM 13.0.0 14.0.0
uuid GHSA-w5hq-g745-h8pq MEDIUM 8.3.2 14.0.0
yaml CVE-2026-33532 MEDIUM 2.4.1 2.8.3, 1.10.3
No Misconfigurations found

Python (python-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
poetry CVE-2026-41140 LOW 2.3.3 2.3.4
uv GHSA-pjjw-68hj-v9mw LOW 0.11.5 0.11.6
No Misconfigurations found

Ruby (gemspec)

Package Vulnerability ID Severity Installed Version Fixed Version Links
json CVE-2026-33210 CRITICAL 2.18.0 ~> 2.15.2.1, ~> 2.17.1.2, >= 2.19.2
zlib CVE-2026-27820 MEDIUM 3.2.2 ~> 3.0.1, ~> 3.1.2, >= 3.2.3
No Misconfigurations found

opt/cdxgen/node_modules/.pnpm/@appthreat+atom-parsetools@1.1.3/node_modules/@appthreat/atom-parsetools/plugins/composer/installed.json (composer-vendor)

No Vulnerabilities found
No Misconfigurations found

opt/cdxgen/node_modules/.pnpm/@cdxgen+cdxgen-plugins-bin-linux-amd64@2.0.3/node_modules/@cdxgen/cdxgen-plugins-bin-linux-amd64/plugins/sourcekitten/sbom-trivy-postbuild.cdx.json (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream GHSA-xmrv-pmrh-hhx2 MEDIUM v1.7.3 1.7.8
github.com/aws/aws-sdk-go-v2/service/s3 GHSA-xmrv-pmrh-hhx2 MEDIUM v1.92.0 1.97.3
github.com/cloudflare/circl CVE-2026-1229 LOW v1.6.1 1.6.3
github.com/docker/cli CVE-2025-15558 HIGH v29.0.3+incompatible 29.2.0
github.com/docker/docker CVE-2026-34040 HIGH v28.5.2+incompatible 29.3.1
github.com/docker/docker CVE-2026-33997 MEDIUM v28.5.2+incompatible 29.3.1
github.com/go-git/go-git/v5 CVE-2026-25934 MEDIUM v5.16.3 5.16.5
github.com/go-git/go-git/v5 CVE-2026-34165 MEDIUM v5.16.3 5.17.1
github.com/go-git/go-git/v5 GHSA-3xc5-wrhm-f963 MEDIUM v5.16.3 5.18.0
github.com/go-git/go-git/v5 CVE-2026-33762 LOW v5.16.3 5.17.1
github.com/go-jose/go-jose/v4 CVE-2026-34986 HIGH v4.1.2 4.1.4
github.com/hashicorp/go-getter CVE-2026-4660 HIGH v1.8.3 1.8.6
github.com/moby/buildkit CVE-2026-33747 HIGH v0.26.2 0.28.1
github.com/moby/buildkit CVE-2026-33748 HIGH v0.26.2 0.28.1
github.com/moby/spdystream CVE-2026-35469 HIGH v0.5.0 0.5.1
github.com/sigstore/cosign/v2 CVE-2026-22703 MEDIUM v2.2.4 2.6.2
github.com/sigstore/rekor CVE-2026-23831 MEDIUM v1.4.3 1.5.0
github.com/sigstore/rekor CVE-2026-24117 MEDIUM v1.4.3 1.5.0
github.com/sigstore/sigstore CVE-2026-24137 MEDIUM v1.9.5 1.10.4
github.com/sigstore/timestamp-authority CVE-2025-66564 HIGH v1.2.2 2.0.3
go.opentelemetry.io/otel/sdk CVE-2026-24051 HIGH v1.38.0 1.40.0
go.opentelemetry.io/otel/sdk CVE-2026-39883 HIGH v1.38.0 1.43.0
google.golang.org/grpc CVE-2026-33186 CRITICAL v1.76.0 1.79.3
helm.sh/helm/v3 CVE-2026-35206 MEDIUM v3.19.2 3.20.2
No Misconfigurations found

opt/pypi/bin/uv (rustbinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
rand GHSA-cq8v-f236-94qc LOW 0.8.5 0.9.3, 0.10.1, 0.8.6
rand GHSA-cq8v-f236-94qc LOW 0.9.2 0.9.3, 0.10.1, 0.8.6
rustls-webpki GHSA-965h-392x-2mh5 LOW 0.103.10 0.103.12, 0.104.0-alpha.6
rustls-webpki GHSA-xgp8-3hg3-c2mh LOW 0.103.10 0.103.12, 0.104.0-alpha.6
No Misconfigurations found

opt/pypi/bin/uvx (rustbinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
rand GHSA-cq8v-f236-94qc LOW 0.8.5 0.9.3, 0.10.1, 0.8.6
rand GHSA-cq8v-f236-94qc LOW 0.9.2 0.9.3, 0.10.1, 0.8.6
rustls-webpki GHSA-965h-392x-2mh5 LOW 0.103.10 0.103.12, 0.104.0-alpha.6
rustls-webpki GHSA-xgp8-3hg3-c2mh LOW 0.103.10 0.103.12, 0.104.0-alpha.6
No Misconfigurations found

usr/local/bin/bazel (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-68121 CRITICAL v1.24.0 1.24.13, 1.25.7, 1.26.0-rc.3
stdlib CVE-2025-22874 HIGH v1.24.0 1.24.4
stdlib CVE-2025-47907 HIGH v1.24.0 1.23.12, 1.24.6
stdlib CVE-2025-58183 HIGH v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61726 HIGH v1.24.0 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.24.0 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.24.0 1.24.11, 1.25.5
stdlib CVE-2026-25679 HIGH v1.24.0 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.24.0 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.24.0 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.24.0 1.25.9, 1.26.2
stdlib CVE-2025-0913 MEDIUM v1.24.0 1.23.10, 1.24.4
stdlib CVE-2025-22870 MEDIUM v1.24.0 1.23.7, 1.24.1
stdlib CVE-2025-22871 MEDIUM v1.24.0 1.23.8, 1.24.2
stdlib CVE-2025-22873 MEDIUM v1.24.0 1.23.9, 1.24.3
stdlib CVE-2025-4673 MEDIUM v1.24.0 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.24.0 1.23.12, 1.24.6
stdlib CVE-2025-47912 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58186 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58187 MEDIUM v1.24.0 1.24.9, 1.25.3
stdlib CVE-2025-58188 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.24.0 1.24.8, 1.25.2
stdlib CVE-2025-61727 MEDIUM v1.24.0 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.24.0 1.24.12, 1.25.6
stdlib CVE-2026-27142 MEDIUM v1.24.0 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.24.0 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.24.0 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.24.0 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.24.0 1.25.8, 1.26.1
No Misconfigurations found

usr/local/go/bin/go (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/bin/gofmt (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/asm (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/cgo (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/compile (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/cover (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/fix (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found
Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/preprofile (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/local/go/pkg/tool/linux_amd64/vet (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found