trivy-fips

Direct Vulnerabilities

Known vulnerabilities in the trivy-fips package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-jpjm-c3r5-q96r

<0.72.0-r7
  • L
CVE-2026-56852

<0.72.0-r7
  • L
GHSA-hrxh-6v49-42gf

<0.72.0-r6
  • H
Improper Verification of Cryptographic Signature

<0.72.0-r4
  • L
GHSA-9vcr-p3rj-q5q6

<0.72.0-r4
  • L
GHSA-8xwf-rjm4-xvhv

<0.72.0-r2
  • L
Improper Certificate Validation

<0.72.0-r2
  • L
Server-Side Request Forgery (SSRF)

<0.72.0-r2
  • L
Cleartext Transmission of Sensitive Information

<0.72.0-r2
  • L
GHSA-jxpm-75mh-9fp7

<0.72.0-r2
  • L
GHSA-xf85-363p-868w

<0.72.0-r2
  • L
GHSA-vh4v-2xq2-g5cg

<0.72.0-r2
  • L
GHSA-wfqv-66vq-46rm

<0.72.0-r2
  • L
External Control of File Name or Path

<0.72.0-r2
  • H
Allocation of Resources Without Limits or Throttling

<0.72.0-r1
  • L
GHSA-9c54-x2g4-v92j

<0.72.0-r1
  • L
GHSA-jpcc-p29g-p8mq

<0.70.0-r2
  • L
Symlink Following

<0.70.0-r1
  • L
CVE-2026-47262

<0.70.0-r2
  • L
CVE-2026-50195

<0.70.0-r1
  • L
Uncontrolled Memory Allocation

<0.71.2-r1
  • L
GHSA-rgh6-rfwx-v388

<0.70.0-r1
  • L
GHSA-q4h4-gmj2-qvw2

<0.69.3-r12
  • L
GHSA-5wrp-cwcj-q835

<0.71.2-r1
  • L
Improper Input Validation

<0.70.0-r1
  • L
GHSA-rm3j-f69w-wqmq

<0.69.3-r12
  • L
GHSA-78mq-xcr3-xm33

<0.69.3-r12
  • L
GHSA-qpw4-5x99-6vjp

<0.69.3-r12
  • L
GHSA-45gg-vh54-h5m9

<0.69.3-r12
  • L
GHSA-xhf5-7wjv-pqxp

<0.70.0-r2
  • L
Improper Input Validation

<0.70.0-r2
  • L
GHSA-f5wc-c3c7-36mc

<0.69.3-r12
  • L
GHSA-89gr-r52h-f8rx

<0.69.3-r12
  • L
GHSA-w879-237q-wc7r

<0.69.3-r12
  • L
GHSA-x527-x647-q7gg

<0.69.3-r12
  • M
Improper Check for Unusual or Exceptional Conditions

<0.71.2-r2
  • L
GHSA-cvxm-645q-p574

<0.70.0-r1
  • L
GHSA-33vj-92qq-66hc

<0.70.0-r1
  • L
GHSA-w6c6-c85g-mmv6

<0.71.2-r2
  • L
GHSA-vgwf-h737-ff37

<0.69.3-r12
  • H
Authentication Bypass

<0.70.0-r0
  • H
Symlink Following

<0.70.0-r0
  • L
GHSA-x86f-5xw2-fm2r

<0.70.0-r0
  • L
GHSA-pxq6-2prw-chj9

<0.70.0-r0
  • L
Uncontrolled Search Path Element

<0.70.0-r0
  • L
Cross-site Scripting (XSS)

<0.70.0-r0
  • L
GHSA-x744-4wpc-v9h2

<0.70.0-r0
  • H
Off-by-one Error

<0.70.0-r0
  • L
GHSA-vp62-88p7-qqf5

<0.70.0-r0
  • L
GHSA-rg2x-37c3-w2rh

<0.70.0-r0
  • L
CVE-2026-42504

<0.69.3-r13
  • L
GHSA-h3gm-q7m7-mp28

<0.69.3-r13
  • L
CVE-2026-42507

<0.69.3-r13
  • L
GHSA-h524-452v-82p9

<0.69.3-r13
  • L
GHSA-4279-q6mj-392r

<0.69.3-r13
  • L
CVE-2026-27145

<0.69.3-r13
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<0.69.3-r12
  • L
Integer Overflow or Wraparound

<0.69.3-r12
  • L
Incorrect Type Conversion or Cast

<0.69.3-r12
  • L
Improper Certificate Validation

<0.69.3-r12
  • L
Improper Privilege Management

<0.69.3-r12
  • L
Improper Verification of Cryptographic Signature

<0.69.3-r12
  • L
Out-of-Bounds

<0.69.3-r12
  • L
GHSA-fqw6-gf59-qr4w

<0.69.3-r12
  • L
CVE-2026-46595

<0.69.3-r12
  • L
Deserialization of Untrusted Data

<0.69.3-r12
  • L
Improper Certificate Validation

<0.69.3-r12
  • L
Missing Authorization

<0.69.3-r12
  • L
GHSA-m7cr-m3pv-hgrp

<0.69.3-r10
  • L
GHSA-crhj-59gh-8x96

<0.69.3-r10
  • C
Improper Encoding or Escaping of Output

<0.69.3-r10
  • L
Directory Traversal

<0.69.3-r10
  • L
GHSA-389r-gv7p-r3rp

<0.69.3-r9
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<0.69.3-r9
  • L
GHSA-pmwq-pjrm-6p5r

<0.69.3-r7
  • L
GHSA-xq5j-9r39-c3vf

<0.69.3-r7
  • L
CVE-2026-42499

<0.69.3-r7
  • M
Out-of-bounds Write

<0.69.3-r7
  • L
Cross-site Scripting (XSS)

<0.69.3-r7
  • L
GHSA-5m4p-2gjx-p2g8

<0.69.3-r7
  • L
GHSA-p9h5-jm8x-mjm5

<0.69.3-r7
  • L
CVE-2026-42501

<0.69.3-r7
  • L
GHSA-497x-jcxf-m478

<0.69.3-r7
  • L
GHSA-qf3q-3h68-mmh2

<0.69.3-r7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.69.3-r7
  • L
GHSA-2283-wf8c-rw8r

<0.69.3-r7
  • H
Double Free

<0.69.3-r7
  • H
NULL Pointer Dereference

<0.69.3-r7
  • L
GHSA-8g2r-hhvj-mv99

<0.69.3-r7
  • L
GHSA-qc64-m6c2-v4x7

<0.69.3-r7
  • H
Allocation of Resources Without Limits or Throttling

<0.69.3-r7
  • M
Link Following

<0.69.3-r7
  • L
Improper Encoding or Escaping of Output

<0.69.3-r7
  • L
GHSA-3v2c-x6q9-f697

<0.69.3-r7
  • H
Insufficiently Protected Credentials

<0.69.3-r7
  • L
GHSA-92mm-2pjq-r785

<0.69.3-r7
  • H
Untrusted Search Path

<0.69.3-r7
  • L
GHSA-pc3f-x583-g7j2

<0.69.3-r7
  • L
Allocation of Resources Without Limits or Throttling

<0.69.3-r7
  • L
Uncaught Exception

<0.69.3-r7
  • L
GHSA-hfvc-g4fc-pqhx

<0.69.3-r7
  • L
GHSA-xm5m-wgh2-rrg3

<0.69.3-r7
  • L
GHSA-78h2-9frx-2jm8

<0.69.3-r7
  • L
CVE-2026-4660

<0.69.3-r7
  • L
GHSA-xmrv-pmrh-hhx2

<0.69.3-r7
  • L
GHSA-3xc5-wrhm-f963

<0.69.3-r7
  • L
Improper Certificate Validation

<0.69.3-r7
  • L
GHSA-hr2v-4r36-88hr

<0.69.3-r7
  • M
Directory Traversal

<0.69.3-r7
  • H
Allocation of Resources Without Limits or Throttling

<0.69.3-r12
  • L
GHSA-x4jj-h2v8-hqqv

<0.69.3-r12
  • L
GHSA-m4pr-4j3g-9v7v

<0.69.3-r12
  • L
CVE-2026-32280

<0.69.3-r12
  • L
GHSA-jrg3-gfjw-hm96

<0.69.3-r12
  • L
GHSA-gjvh-7jh8-7xhm

<0.69.3-r12
  • M
Allocation of Resources Without Limits or Throttling

<0.69.3-r12
  • L
GHSA-5w89-2c2x-6x66

<0.69.3-r12
  • H
Improper Certificate Validation

<0.69.3-r12
  • L
GHSA-7mr4-xjxg-34g6

<0.69.3-r12
  • M
Cross-site Scripting (XSS)

<0.69.3-r12
  • H
Incorrect Authorization

<0.69.3-r12
  • L
GHSA-4c29-8rgm-jvjj

<0.69.3-r4
  • L
GHSA-jhf3-xxhw-2wpp

<0.69.3-r4
  • H
Directory Traversal

<0.69.3-r4
  • C
Directory Traversal

<0.69.3-r4
  • L
Integer Underflow

<0.69.3-r4
  • L
GHSA-4vrq-3vrq-g6gg

<0.69.3-r4
  • L
GHSA-gm2x-2g9h-ccm8

<0.69.3-r4
  • L
Improper Validation of Array Index

<0.69.3-r4
  • L
Improper Authorization

<0.69.3-r3
  • L
GHSA-p77j-4mvh-x3m3

<0.69.3-r3
  • L
Cross-site Scripting (XSS)

<0.69.3-r2
  • L
GHSA-j4j7-vw47-rhfq

<0.69.3-r2
  • L
Direct Request ('Forced Browsing')

<0.69.3-r2
  • L
GHSA-rv83-g57w-fr8j

<0.69.3-r2
  • L
Directory Traversal

<0.69.3-r2
  • L
GHSA-j3gx-2473-5fp8

<0.69.3-r2
  • L
GHSA-9h8m-3fm2-qjrq

<0.69.1-r3
  • L
Untrusted Search Path

<0.69.1-r3
  • L
GHSA-q9hv-hpm4-hj6x

<0.69.1-r2
  • C
CVE-2026-1229

<0.69.1-r2
  • L
GHSA-37cx-329c-33x3

<0.69.1-r1
  • M
Improper Validation of Integrity Check Value

<0.69.1-r1
  • H
Improper Verification of Cryptographic Signature

<0.69.0-r0
  • L
GHSA-846p-jg2w-w324

<0.69.0-r0
  • H
Reachable Assertion

<0.69.0-r0
  • L
GHSA-jqc5-w2xx-5vq4

<0.69.0-r0
  • L
Directory Traversal

<0.69.0-r0
  • L
GHSA-fcv2-xgw5-pqxf

<0.69.0-r0
  • M
Directory Traversal

<0.69.0-r0
  • L
GHSA-fphv-w9fq-2525

<0.69.0-r0
  • L
GHSA-4c4x-jm2x-pf9j

<0.68.2-r2
  • L
GHSA-273p-m2cw-6833

<0.68.2-r2
  • L
NULL Pointer Dereference

<0.68.2-r2
  • L
Server-Side Request Forgery (SSRF)

<0.68.2-r2
  • L
GHSA-4f8r-qqr9-fq8j

<0.67.2-r1
  • L
GHSA-6v2p-p543-phr9

<0.60.0-r4
  • L
GHSA-hcg3-q754-cr77

<0.60.0-r2
  • L
Race Condition

<0.67.2-r1
  • L
CVE-2025-58181

<0.67.2-r4
  • L
GHSA-j5w8-q4qc-rx2x

<0.67.2-r4
  • M
Memory Leak

<0.67.2-r3
  • H
Symlink Following

<0.67.2-r2
  • H
Incorrect Execution-Assigned Permissions

<0.67.2-r3
  • L
Algorithmic Complexity

<0.67.2-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.65.0-r5
  • L
Allocation of Resources Without Limits or Throttling

<0.65.0-r3
  • L
Use of Uninitialized Resource

<0.65.0-r3
  • L
CVE-2025-8959

<0.65.0-r3
  • L
Race Condition

<0.65.0-r1
  • M
Missing Initialization of Resource

<0.64.1-r2
  • H
Arbitrary Code Injection

<0.64.1-r0
  • L
CVE-2025-4673

<0.63.0-r1
  • L
CVE-2025-22874

<0.63.0-r1
  • L
Arbitrary Code Injection

<0.62.1-r0
  • L
CVE-2025-22872

<0.61.0-r3
  • L
Allocation of Resources Without Limits or Throttling

<0.61.0-r2
  • L
Stack-based Buffer Overflow

<0.61.0-r2
  • L
CVE-2025-22871

<0.61.0-r1
  • L
CVE-2025-22868

<0.60.0-r4
  • H
Integer Overflow or Wraparound

<0.60.0-r4
  • L
Asymmetric Resource Consumption (Amplification)

<0.60.0-r5
  • L
CVE-2025-22870

<0.60.0-r3
  • L
CVE-2025-22869

<0.60.0-r2
  • L
Allocation of Resources Without Limits or Throttling

<0.59.1-r2
  • L
CVE-2025-22866

<0.59.1-r1
  • L
Resource Exhaustion

<0.58.2-r0
  • L
Arbitrary Argument Injection

<0.58.2-r0
  • L
CVE-2024-45338

<0.58.0-r2
  • L
CVE-2024-45337

<0.58.0-r1
  • L
Improper Handling of Exceptional Conditions

<0.57.0-r1
  • L
CVE-2024-34156

<0.55.1-r0
  • L
CVE-2024-34158

<0.55.1-r0
  • L
CVE-2024-34155

<0.55.1-r0
  • L
CVE-2024-41110

<0.54.0-r0
  • L
CVE-2024-24791

<0.53.0-r1
  • H
CVE-2024-6257

<0.52.2-r1
  • M
Race Condition

<0.52.1-r1
  • C
CVE-2024-24790

<0.52.0-r2
  • M
CVE-2024-24789

<0.52.0-r2