Skip to content
If you are interested in trying out Gloo Gateway with the Kubernetes Gateway API, check out Solo Enterprise for kgateway. This version adds enterprise functionality on top of the kgateway open source project.

Enterprise

Page as Markdown

Review security and CVE scan results for Gloo Gateway Enterprise.

Gloo container images are scanned using Trivy for HIGH and CRITICAL vulnerabilities. To learn more about how Solo.io detects, tracks, and remediates CVEs, see CVE lifecycle handling.

Latest 1.21.x Gloo Enterprise Release: 1.21.1

Gloo Enterprise rate-limit-ee image

No scan found

Gloo Enterprise gloo-ee image

No scan found

Gloo Enterprise gloo-ee-envoy-wrapper image

No scan found

Gloo Enterprise observability-ee image

No scan found

Gloo Enterprise extauth-ee image

No scan found

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No scan found

Gloo Enterprise gloo-fed-apiserver image

No scan found

Gloo Enterprise gloo-fed-apiserver-envoy image

No scan found

Gloo Enterprise gloo-federation-console image

No scan found

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No scan found

Release 1.21.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.21.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.21.0 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.21.0 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.21.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.21.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.21.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.21.0 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.21.0 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.21.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.21.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Latest 1.20.x Gloo Enterprise Release: 1.20.10

Gloo Enterprise rate-limit-ee image

No scan found

Gloo Enterprise gloo-ee image

No scan found

Gloo Enterprise gloo-ee-envoy-wrapper image

No scan found

Gloo Enterprise observability-ee image

No scan found

Gloo Enterprise extauth-ee image

No scan found

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No scan found

Gloo Enterprise gloo-fed-apiserver image

No scan found

Gloo Enterprise gloo-fed-apiserver-envoy image

No scan found

Gloo Enterprise gloo-federation-console image

No scan found

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No scan found

Release 1.20.9

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.9 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.9 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.9 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.9 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.9 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.9 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.9 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.9 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.9 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.9 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.8

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.8 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.8 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.8 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.8 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-33416libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.7 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.7 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.7 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.7 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-33416libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.6

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.6 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.6 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.6 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.6 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-25646libpngHIGH1.6.54-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.54-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.54-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.5 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.5 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.5 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.5 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.5 (alpine 3.23.2)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-22695libpngHIGH1.6.53-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.53-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.53-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.53-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.53-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.4 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.4 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-66293libpngHIGH1.6.51-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.51-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.51-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.51-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.3 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.3 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.2 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.2 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.1 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.1 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.20.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv28.0.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.0 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.0 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.2-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.2-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.2-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.37.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Latest 1.19.x Gloo Enterprise Release: 1.19.16

Gloo Enterprise rate-limit-ee image

No scan found

Gloo Enterprise gloo-ee image

No scan found

Gloo Enterprise gloo-ee-envoy-wrapper image

No scan found

Gloo Enterprise observability-ee image

No scan found

Gloo Enterprise extauth-ee image

No scan found

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No scan found

Gloo Enterprise gloo-fed-apiserver image

No scan found

Gloo Enterprise gloo-fed-apiserver-envoy image

No scan found

Gloo Enterprise gloo-federation-console image

No scan found

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No scan found

Release 1.19.15

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.15 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.15 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.15 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.15 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.15 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.15 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.15 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.15 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.15 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.15 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.14

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.14.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.14.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.14.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.14.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.14 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-33416libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.42.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.13

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.13 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.13 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.13 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.13 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.13 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.13 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.13 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.13 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.13 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-25646libpngHIGH1.6.54-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.54-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.54-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.13 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.12

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.12 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.12 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.12 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.12 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.12 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-66293libpngHIGH1.6.51-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.51-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.51-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.51-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.11

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.11 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.11 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.11 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.11 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.11 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.10

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.10 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.10 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.10 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.10 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.10 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.9

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.9 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.9 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.9 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.9 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.9 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.2-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.2-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.2-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.8

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.8 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.8 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.8 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.8 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.8 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.7 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.7 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.7 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.7 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.7 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.6

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.6 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.5 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.4 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.3 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.2 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.1 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.19.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.0 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Latest 1.18.x Gloo Enterprise Release: 1.18.26

Gloo Enterprise rate-limit-ee image

No scan found

Gloo Enterprise gloo-ee image

No scan found

Gloo Enterprise gloo-ee-envoy-wrapper image

No scan found

Gloo Enterprise observability-ee image

No scan found

Gloo Enterprise extauth-ee image

No scan found

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No scan found

Gloo Enterprise gloo-fed-apiserver image

No scan found

Gloo Enterprise gloo-fed-apiserver-envoy image

No scan found

Gloo Enterprise gloo-federation-console image

No scan found

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No scan found

Release 1.18.25

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.25 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.25 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.25 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.25 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.25 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.25 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.25 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.25 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.25 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.25 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.24

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.24 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.24 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.24 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.24 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-33416libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.55-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.41.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32282stdlibHIGHv1.25.81.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.23

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.23 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.23 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.23 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.23 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.23 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.23 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.23 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.23 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.23 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-25646libpngHIGH1.6.54-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.54-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.54-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.23 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-28390libcrypto3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-28390libssl3HIGH3.3.6-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.22

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.22 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.22 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.22 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.22 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.22 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-66293libpngHIGH1.6.51-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.51-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.51-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.51-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.21

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.21 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.21 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.21 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.21 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.21 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.20

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.20 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.20 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.20 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.20 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.20 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.4-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.19

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.19 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.19 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.19 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.19 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.19 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.2-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.2-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.2-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.18

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.18 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.18 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.18 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.18 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.18 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.17

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.17 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.17 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.17 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.17 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.17 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.5.1-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.16

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.16 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.4.1+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.16 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.16 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.16 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.15

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.15 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.15 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.15 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.15 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.14

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.14 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.14 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.14 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.14 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.13

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.13 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.24.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.12

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.12 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.11

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.11 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.10

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.10 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-49795libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.9

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.9 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-49795libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.8

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.8 (ubuntu 20.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-33416libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33416
CVE-2026-33636libpngHIGH1.6.47-r01.6.56-r0https://avd.aquasec.com/nvd/cve-2026-33636
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-49794libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-49795libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.7 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.7 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2025-27113libxml2HIGH2.11.8-r12.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r12.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r12.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.6

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.6 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.6 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.5 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.5 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.4 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.4 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.3 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.3 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32285github.com/buger/jsonparserHIGHv1.1.11.1.2https://avd.aquasec.com/nvd/cve-2026-32285
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.2 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.2 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.1 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.1 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282
Release 1.18.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.2.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.0 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.0 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.31.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32282stdlibHIGHv1.23.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32282