CVE-2026-102252
- EPSS 0.09%
- Veröffentlicht 29.09.2026 19:41:42
- Zuletzt bearbeitet 30.09.2026 16:17:06
A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VM...
CVE-2025-13425
- EPSS 0.11%
- Veröffentlicht 20.11.2025 15:30:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (denial of servi...
CVE-2025-5981
- EPSS 0.21%
- Veröffentlicht 18.06.2025 08:28:02
- Zuletzt bearbeitet 07.08.2025 15:34:04
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.