Skip to content

Zero CVE Daily Report #371

Description

@github-actions

Zero CVE Daily Report

Generated: 2026-07-25T05:27:09.449Z

Status

  • Total findings: 194
  • Fixed by Go dependency remediation: 10
  • Remaining findings: 184
  • Scanner errors: 0
  • Rolling PR branch: automation/zero-cve
  • Scanned images: 8gears.container-registry.com/8gcr/harbor-core:latest, 8gears.container-registry.com/8gcr/harbor-jobservice:latest, 8gears.container-registry.com/8gcr/harbor-registryctl:latest, 8gears.container-registry.com/8gcr/harbor-exporter:latest, 8gears.container-registry.com/8gcr/harbor-portal:latest, 8gears.container-registry.com/8gcr/harbor-registry:latest, 8gears.container-registry.com/8gcr/trivy-adapter:latest

Vulnerabilities

Vulnerability Package Present version Fixed version Fixed
CVE-2026-40468
Integer overflow vulnerability has been found in "builtin.c" program f ...
gawk 1:5.2.1-2+b1 -
CVE-2026-40469
gawk: gawk: Denial of Service due to integer overflow
gawk 1:5.2.1-2+b1 -
CVE-2025-66035
angular: Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs
@angular/common 16.2.12 21.0.1
CVE-2026-50170
@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
@angular/common 16.2.12 22.0.0-rc.2
CVE-2026-50171
@angular/common: Angular @angular/common: Denial of Service via malformed digitsInfo parameter
@angular/common 16.2.12 22.0.0-rc.2
CVE-2026-54266
@angular/common: Weak 32-Bit Cache Key Hashing in HttpTransferCache Leading to Cross-Request Data Leakage and State Poisoning
@angular/common 16.2.12 22.0.1
CVE-2026-54268
@angular/common: Angular @angular/common: Denial of Service via crafted date format string
@angular/common 16.2.12 22.0.1
CVE-2025-66412
angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes
@angular/compiler 16.2.12 21.0.2
CVE-2026-22610
angular: Angular: Cross-site scripting vulnerability in Template Compiler
@angular/compiler 16.2.12 21.1.0-rc.0
CVE-2026-22610
angular: Angular: Cross-site scripting vulnerability in Template Compiler
@angular/core 16.2.12 21.1.0-rc.0
CVE-2026-27970
@angular/core: Angular: Cross-site scripting via compromised translation files
@angular/core 16.2.12 21.2.0
CVE-2026-54267
@angular/core: Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
@angular/core 16.2.12 22.0.1
CVE-2026-42264
axios: Axios: Prototype pollution allows information disclosure and request manipulation
axios 1.15.1 1.15.2
CVE-2026-44486
axios: Axios: Information disclosure of proxy credentials via HTTP redirects
axios 1.15.1 1.16.0
CVE-2026-44487
axios: Axios: Information disclosure of proxy credentials via redirect flows
axios 1.15.1 1.16.0
CVE-2026-44488
axios: Axios: Denial of Service due to unenforced request and response size limits
axios 1.15.1 1.16.0
CVE-2026-44492
axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
axios 1.15.1 1.16.0
CVE-2026-44494
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
axios 1.15.1 1.16.0
CVE-2026-44495
axios: Axios: Information disclosure due to prototype pollution vulnerability
axios 1.15.1 1.15.2
CVE-2026-44496
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
axios 1.15.1 1.16.0
CVE-2026-13149
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
brace-expansion 5.0.5 5.0.7
CVE-2026-14257
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
brace-expansion 5.0.5 5.0.8
CVE-2026-33630
c-ares: c-ares: Use-after-free / double-free in query-completion handling
c-ares 1.34.6-r0 1.34.8-r0
CVE-2026-13676
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
fast-uri 3.0.1 4.0.1
CVE-2026-16221
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...
fast-uri 3.0.1 4.1.1
CVE-2026-6321
fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
fast-uri 3.0.1 3.1.1
CVE-2026-6322
fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
fast-uri 3.0.1 3.1.2
CVE-2026-12143
form-data: form-data: Form field override via CRLF injection
form-data 4.0.5 4.0.6
CVE-2026-40467
Use After Free vulnerability has been found in "io.c" program file of ...
gawk 1:5.2.1-2+b1 -
CVE-2026-40553
Buffer overflow vulnerability has been found in "extension/readdir.c" ...
gawk 1:5.2.1-2+b1 -
CVE-2026-33540
github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL
github.com/distribution/distribution v2.8.2+incompatible -
CVE-2026-35172
github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion
github.com/distribution/distribution v2.8.2+incompatible -
GHSA-hrxh-6v49-42gf
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpc v1.81.1 1.82.1
GHSA-hrxh-6v49-42gf
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpc v1.79.3 1.82.1
GHSA-hrxh-6v49-42gf
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpc v1.80.0 1.82.1
GHSA-hrxh-6v49-42gf
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpc v1.81.0 1.82.1
CVE-2026-29063
immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
immutable 3.8.2 5.1.5
CVE-2026-59879
Immutable.js provides many Persistent Immutable data structures. Prior ...
immutable 3.8.2 5.1.8
CVE-2026-59880
Immutable.js provides many Persistent Immutable data structures. Prior ...
immutable 3.8.2 5.1.8
CVE-2026-59869
js-yaml: js-yaml: Denial of Service via crafted YAML documents
js-yaml 4.1.1 4.3.0
CVE-2026-59869
js-yaml: js-yaml: Denial of Service via crafted YAML documents
js-yaml 4.1.0 4.3.0
CVE-2026-54369
acl: Symlink traversal privilege escalation via libacl functions
libacl1 2.3.2-2+b1 -
CVE-2026-4878
libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
libcap2 1:2.75-10+b8 1:2.75-10+deb13u1
CVE-2026-11352
curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-11586
curl: curl: Denial of Service via WebSocket PING flood
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-12064
curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-8286
curl: curl: Insecure connection establishment due to TLS configuration mismatch
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-8925
curl: curl: Double-free vulnerability in SASL authentication
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-8927
curl: Information disclosure due to uncleared proxy authentication state
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-8932
libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-9079
libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-9080
libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-9545
libcurl: libcurl: Information disclosure via cached SSL session and early data
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-9546
libcurl: libcurl: Information disclosure due to persistent Referer header
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-9547
curl: curl: Man-in-the-middle attack via SSH host key bypass
libcurl 8.20.0-r1 8.21.0-r0
CVE-2026-45447
openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
libssl3t64 3.5.5-1~deb13u2 3.5.6-1~deb13u2
CVE-2025-69720
ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
libtinfo6 6.5+20250216-2 -
CVE-2026-45447
openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
openssl-provider-legacy 3.5.5-1~deb13u2 3.5.6-1~deb13u2
CVE-2026-50151
oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
oras.land/oras-go/v2 v2.6.0 2.6.1
CVE-2026-50163
oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks
oras.land/oras-go/v2 v2.6.0 -
CVE-2026-33671
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns
picomatch 2.3.1 4.0.4
CVE-2026-45623
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
postcss 8.4.47 8.5.12
GHSA-r28c-9q8g-f849
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
postcss 8.4.47 8.5.18
CVE-2026-39822
os: golang: Go os.Root: Symlink following vulnerability allows directory traversal
stdlib v1.26.4 1.27.0-rc.2
CVE-2026-50557
@angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
@angular/compiler 16.2.12 22.0.0-rc.2
CVE-2026-54265
@angular/compiler: Angular: Two-Way Property Binding Sanitization Bypass (XSS)
@angular/compiler 16.2.12 22.0.1
CVE-2026-50557
@angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
@angular/core 16.2.12 22.0.0-rc.2
CVE-2026-52725
@angular/core: @angular/core: Cross-Site Scripting (XSS) via dynamic component creation bypass
@angular/core 16.2.12 22.0.0-rc.2
CVE-2025-69873
ajv: ReDoS via $data reference
ajv 8.17.1 8.18.0
CVE-2026-42044
axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
axios 1.15.1 1.15.2
CVE-2026-44490
axios: Axios: Information disclosure and denial of service due to prototype pollution
axios 1.15.1 1.16.0
GHSA-42h9-826w-cgv3
Axios: Excessive recursion in formDataToJSON can cause denial of service
axios 1.15.1 1.18.0
GHSA-7q8q-rj6j-mhjq
Axios: Nested axios option objects can consume polluted prototype values
axios 1.15.1 1.18.0
GHSA-f4gw-2p7v-4548
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
axios 1.15.1 1.18.0
GHSA-hcpx-6fm6-wx23
Axios form serializer maxDepth bypass via {} metatoken
axios 1.15.1 1.18.0
GHSA-jqh4-m9w3-8hp9
Axios: Fetch adapter ReadableStream uploads bypass maxBodyLength
axios 1.15.1 1.18.0
GHSA-mmx7-hfxf-jppx
Axios: Prototype pollution gadgets can alter axios request construction
axios 1.15.1 1.18.0
GHSA-mwf2-3pr3-8698
Axios: HTTP/2 streamed uploads bypass maxBodyLength
axios 1.15.1 1.18.0
GHSA-pmv8-rq9r-6j72
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
axios 1.15.1 1.18.0
CVE-2026-45149
brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges
brace-expansion 5.0.5 5.0.6
CVE-2026-41238
DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution
dompurify 3.3.3 3.4.0
CVE-2026-41239
DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions
dompurify 3.3.3 3.4.0
CVE-2026-41240
DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization
dompurify 3.3.3 3.4.0
CVE-2026-49458
dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes
dompurify 3.3.3 3.4.6
CVE-2026-49459
dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution
dompurify 3.3.3 3.4.6
CVE-2026-49978
dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
dompurify 3.3.3 3.4.7
CVE-2026-65898
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ...
dompurify 3.3.3 3.4.11
CVE-2026-65902
DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct refe ...
dompurify 3.3.3 3.4.7
CVE-2026-65903
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...
dompurify 3.3.3 3.4.0
CVE-2026-45249
Apache ECharts has a cross-site scripting (XSS) vulnerability
echarts 5.5.1 6.1.0
GHSA-r4q5-vmmm-2653
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets
follow-redirects 1.15.11 1.16.0
CVE-2026-41888
github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion
github.com/distribution/distribution v2.8.2+incompatible -
CVE-2025-47909
Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
github.com/gorilla/csrf v1.7.3 -
CVE-2026-49834
sigstore-go is a Go library for Sigstore signing and verification. Pri ...
github.com/sigstore/sigstore-go v1.1.4 1.2.0
CVE-2026-49835
timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality
github.com/sigstore/timestamp-authority/v2 v2.0.6 2.1.0
CVE-2025-64718
js-yaml: js-yaml prototype pollution in merge
js-yaml 4.1.0 4.1.1
CVE-2026-53550
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
js-yaml 4.1.1 4.2.0
CVE-2026-53550
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
js-yaml 4.1.0 4.2.0
CVE-2026-54370
acl: TOCTOU Symlink Traversal via getfacl/setfacl
libacl1 2.3.2-2+b1 -
CVE-2026-54371
attr: Symlink Traversal Privilege Escalation via getfattr and setfattr
libattr1 1:2.5.2-3 -

Showing 100 of 194 findings. See workflow artifacts for full JSON reports.

Go Module Updates

Module From Target After Status
github.com/goharbor/harbor/src - v1.26.5 - failed
go.opentelemetry.io/otel v1.43.0 v1.44.0 v1.44.0 updated

Scanner Status

Scanner Exit code Notes
govulncheck 0 -
trivy fs 0 -
trivy image: 8gears.container-registry.com/8gcr/harbor-core:latest 0 -
trivy image: 8gears.container-registry.com/8gcr/harbor-jobservice:latest 0 -
trivy image: 8gears.container-registry.com/8gcr/harbor-registryctl:latest 0 -
trivy image: 8gears.container-registry.com/8gcr/harbor-exporter:latest 0 -
trivy image: 8gears.container-registry.com/8gcr/harbor-portal:latest 0 -
trivy image: 8gears.container-registry.com/8gcr/harbor-registry:latest 0 -
trivy image: 8gears.container-registry.com/8gcr/trivy-adapter:latest 0 -

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions