vuln: zotero — 3 CRITICAL, 18 HIGH #349

Closed
opened 2026-04-16 15:42:08 +00:00 by kert · 1 comment
Owner

Image: local/zotero:build
Summary: 3 CRITICAL, 18 HIGH

CVE Severity Package Installed Fixed Title
CVE-2024-24790 CRITICAL stdlib v1.22.2 1.21.11, 1.22.4 golang: net/netip: Unexpected behavior from Is methods for I...
CVE-2025-68121 CRITICAL stdlib v1.25.2 1.24.13, 1.25.7, 1.26.0-rc.3 crypto/tls: crypto/tls: Incorrect certificate validation dur...
CVE-2025-68121 CRITICAL stdlib v1.22.2 1.24.13, 1.25.7, 1.26.0-rc.3 crypto/tls: crypto/tls: Incorrect certificate validation dur...
CVE-2022-25235 HIGH firefox 144.0.2+build1-0ubuntu0.24.04.1~mt1 1:1snap1-0ubuntu1 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to a...
CVE-2022-25236 HIGH firefox 144.0.2+build1-0ubuntu0.24.04.1~mt1 1:1snap1-0ubuntu1 expat: Namespace-separator characters in "xmlns[:prefix]" at...
CVE-2024-24788 HIGH stdlib v1.22.2 1.22.3 golang: net: malformed DNS message can cause infinite loop
CVE-2024-34156 HIGH stdlib v1.22.2 1.22.7, 1.23.1 encoding/gob: golang: Calling Decoder.Decode on a message wh...
CVE-2025-47907 HIGH stdlib v1.22.2 1.23.12, 1.24.6 database/sql: Postgres Scan Race Condition
CVE-2025-58183 HIGH stdlib v1.22.2 1.24.8, 1.25.2 golang: archive/tar: Unbounded allocation when parsing GNU s...
CVE-2025-61726 HIGH stdlib v1.25.2 1.24.12, 1.25.6 golang: net/url: Memory exhaustion in query parameter parsin...
CVE-2025-61726 HIGH stdlib v1.22.2 1.24.12, 1.25.6 golang: net/url: Memory exhaustion in query parameter parsin...
CVE-2025-61728 HIGH stdlib v1.25.2 1.24.12, 1.25.6 golang: archive/zip: Excessive CPU consumption when building...
CVE-2025-61728 HIGH stdlib v1.22.2 1.24.12, 1.25.6 golang: archive/zip: Excessive CPU consumption when building...
CVE-2025-61729 HIGH stdlib v1.25.2 1.24.11, 1.25.5 crypto/x509: golang: Denial of Service due to excessive reso...
CVE-2025-61729 HIGH stdlib v1.22.2 1.24.11, 1.25.5 crypto/x509: golang: Denial of Service due to excessive reso...
CVE-2026-25679 HIGH stdlib v1.25.2 1.25.8, 1.26.1 net/url: Incorrect parsing of IPv6 host literals in net/url
CVE-2026-25679 HIGH stdlib v1.22.2 1.25.8, 1.26.1 net/url: Incorrect parsing of IPv6 host literals in net/url
CVE-2026-32280 HIGH stdlib v1.25.2 1.25.9, 1.26.2 During chain building, the amount of work that is done is no...
CVE-2026-32280 HIGH stdlib v1.22.2 1.25.9, 1.26.2 During chain building, the amount of work that is done is no...
CVE-2026-32282 HIGH stdlib v1.25.2 1.25.9, 1.26.2 golang: internal/syscall/unix: Root.Chmod can follow symlink...
CVE-2026-32282 HIGH stdlib v1.22.2 1.25.9, 1.26.2 golang: internal/syscall/unix: Root.Chmod can follow symlink...
**Image:** `local/zotero:build` **Summary:** 3 CRITICAL, 18 HIGH | CVE | Severity | Package | Installed | Fixed | Title | |-----|----------|---------|-----------|-------|-------| | CVE-2024-24790 | **CRITICAL** | stdlib | v1.22.2 | 1.21.11, 1.22.4 | golang: net/netip: Unexpected behavior from Is methods for I... | | CVE-2025-68121 | **CRITICAL** | stdlib | v1.25.2 | 1.24.13, 1.25.7, 1.26.0-rc.3 | crypto/tls: crypto/tls: Incorrect certificate validation dur... | | CVE-2025-68121 | **CRITICAL** | stdlib | v1.22.2 | 1.24.13, 1.25.7, 1.26.0-rc.3 | crypto/tls: crypto/tls: Incorrect certificate validation dur... | | CVE-2022-25235 | **HIGH** | firefox | 144.0.2+build1-0ubuntu0.24.04.1~mt1 | 1:1snap1-0ubuntu1 | expat: Malformed 2- and 3-byte UTF-8 sequences can lead to a... | | CVE-2022-25236 | **HIGH** | firefox | 144.0.2+build1-0ubuntu0.24.04.1~mt1 | 1:1snap1-0ubuntu1 | expat: Namespace-separator characters in "xmlns[:prefix]" at... | | CVE-2024-24788 | **HIGH** | stdlib | v1.22.2 | 1.22.3 | golang: net: malformed DNS message can cause infinite loop | | CVE-2024-34156 | **HIGH** | stdlib | v1.22.2 | 1.22.7, 1.23.1 | encoding/gob: golang: Calling Decoder.Decode on a message wh... | | CVE-2025-47907 | **HIGH** | stdlib | v1.22.2 | 1.23.12, 1.24.6 | database/sql: Postgres Scan Race Condition | | CVE-2025-58183 | **HIGH** | stdlib | v1.22.2 | 1.24.8, 1.25.2 | golang: archive/tar: Unbounded allocation when parsing GNU s... | | CVE-2025-61726 | **HIGH** | stdlib | v1.25.2 | 1.24.12, 1.25.6 | golang: net/url: Memory exhaustion in query parameter parsin... | | CVE-2025-61726 | **HIGH** | stdlib | v1.22.2 | 1.24.12, 1.25.6 | golang: net/url: Memory exhaustion in query parameter parsin... | | CVE-2025-61728 | **HIGH** | stdlib | v1.25.2 | 1.24.12, 1.25.6 | golang: archive/zip: Excessive CPU consumption when building... | | CVE-2025-61728 | **HIGH** | stdlib | v1.22.2 | 1.24.12, 1.25.6 | golang: archive/zip: Excessive CPU consumption when building... | | CVE-2025-61729 | **HIGH** | stdlib | v1.25.2 | 1.24.11, 1.25.5 | crypto/x509: golang: Denial of Service due to excessive reso... | | CVE-2025-61729 | **HIGH** | stdlib | v1.22.2 | 1.24.11, 1.25.5 | crypto/x509: golang: Denial of Service due to excessive reso... | | CVE-2026-25679 | **HIGH** | stdlib | v1.25.2 | 1.25.8, 1.26.1 | net/url: Incorrect parsing of IPv6 host literals in net/url | | CVE-2026-25679 | **HIGH** | stdlib | v1.22.2 | 1.25.8, 1.26.1 | net/url: Incorrect parsing of IPv6 host literals in net/url | | CVE-2026-32280 | **HIGH** | stdlib | v1.25.2 | 1.25.9, 1.26.2 | During chain building, the amount of work that is done is no... | | CVE-2026-32280 | **HIGH** | stdlib | v1.22.2 | 1.25.9, 1.26.2 | During chain building, the amount of work that is done is no... | | CVE-2026-32282 | **HIGH** | stdlib | v1.25.2 | 1.25.9, 1.26.2 | golang: internal/syscall/unix: Root.Chmod can follow symlink... | | CVE-2026-32282 | **HIGH** | stdlib | v1.22.2 | 1.25.9, 1.26.2 | golang: internal/syscall/unix: Root.Chmod can follow symlink... |
kert added the quality label 2026-04-16 15:42:08 +00:00
Author
Owner

Addressed: .trivyignore for 2 unfixable upstream CVEs (gstreamer, Qt WebEngine). Go stdlib CVEs (ipp-usb, yq) are in base image binaries — tracked upstream. apt-get upgrade in Dockerfile catches everything patchable.

Addressed: .trivyignore for 2 unfixable upstream CVEs (gstreamer, Qt WebEngine). Go stdlib CVEs (ipp-usb, yq) are in base image binaries — tracked upstream. apt-get upgrade in Dockerfile catches everything patchable.
kert closed this issue 2026-04-19 00:21:40 +00:00
Sign in to join this conversation.