github.com/google/osv-scalibr
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/google/osv-scalibrpage 1 of 1
- CVE-2025-13425LOWCVSS 1.9EG 0.0✓ Fixed in 0.3.42025-11-20
A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (deni…
- CVE-2025-5981MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.2.12025-06-18
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted contain…
Check whether github.com/google/osv-scalibr is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/google/osv-scalibr CVEs against the assets you own.
Start Free Scan →