Gloo container images are scanned using Trivy for HIGH and CRITICAL vulnerabilities. To learn more about how Solo.io detects, tracks, and remediates CVEs, see CVE lifecycle handling.

Latest 1.21.x Gloo Enterprise Release: 1.21.0

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.21.0 (alpine 3.21.3)

No Vulnerabilities Found for usr/local/bin/rate-limit

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.21.0 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.21.0 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/envoyinit

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.21.0 (alpine 3.21.3)

No Vulnerabilities Found for usr/local/bin/observability

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.21.0 (alpine 3.21.3)

No Vulnerabilities Found for usr/local/bin/extauth

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.21.0 (alpine 3.21.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.21.0 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo-fed-apiserver

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.21.0 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.21.0 (alpine 3.23.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.21.0 (alpine 3.21.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed-rbac-validating-webhook

Latest 1.20.x Gloo Enterprise Release: 1.20.9

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.20.9 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/rate-limit

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.9 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.9 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/envoyinit

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.20.9 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/observability

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.20.9 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/extauth

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.20.9 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.9 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo-fed-apiserver

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.9 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.20.9 (alpine 3.23.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.9 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed-rbac-validating-webhook

Release 1.20.8

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.20.8 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.8 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.8 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.20.8 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.20.8 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.20.8 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.8 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.8 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.8 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.4-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.8 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
Release 1.20.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.7 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.7 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.7 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.7 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.4-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.7 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.6

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.20.6 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.6 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.6 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.20.6 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.20.6 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.20.6 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.6 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.6 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-25646libpngHIGH1.6.54-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.6 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.20.5 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.5 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.20.5 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.5 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.5 (alpine 3.23.2)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-22695libpngHIGH1.6.53-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.53-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.53-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.4 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.4 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-66293libpngHIGH1.6.51-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.51-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.3 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.3 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.2 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.2 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.1 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.1 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.20.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.20.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv28.1.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.20.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.20.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.20.0 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.20.0 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.2-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.2-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.20.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.37.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Latest 1.19.x Gloo Enterprise Release: 1.19.15

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.19.15 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/rate-limit

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.15 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.15 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/envoyinit

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.19.15 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/observability

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.19.15 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/extauth

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.19.15 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.15 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo-fed-apiserver

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.15 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.19.15 (alpine 3.23.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.15 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed-rbac-validating-webhook

Release 1.19.14

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.19.14 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.19.14 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.19.14 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.19.14 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.14 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.14 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.4-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.14 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.75.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
Release 1.19.13

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.19.13 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.13 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.13 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.19.13 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.19.13 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.19.13 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.13 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.13 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.13 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-25646libpngHIGH1.6.54-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.13 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.12

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.12 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.12 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.12 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.12 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.12 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-66293libpngHIGH1.6.51-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.51-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.12 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.11

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.11 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.11 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.11 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.11 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.11 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.11 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.10

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.10 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.10 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.10 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.10 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.10 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.9

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.9 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.9 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.9 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.9 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.9 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.2-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.2-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.8

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.8 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.8 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.8 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.8 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.8 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.1-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.7 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.7 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.7 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.7 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.7 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.1-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.7 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.6

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.6 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.5 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.4 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.3 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.19.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.19.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.2 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.1 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.19.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.03.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.0 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Latest 1.18.x Gloo Enterprise Release: 1.18.25

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.25 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/rate-limit

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.25 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.25 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/envoyinit

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.25 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/observability

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.25 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/extauth

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.25 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.25 (ubuntu 24.04)

No Vulnerabilities Found for usr/local/bin/gloo-fed-apiserver

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.25 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.18.25 (alpine 3.23.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.25 (alpine 3.23.3)

No Vulnerabilities Found for usr/local/bin/gloo-fed-rbac-validating-webhook

Release 1.18.24

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.24 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.24 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.24 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.24 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.24 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.24 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.24 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.24 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.24 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.4-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.24 (alpine 3.23.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
Release 1.18.23

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.23 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.23 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.23 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.23 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.23 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.23 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.23 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.23 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.23 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2026-25646libpngHIGH1.6.54-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.23 (alpine 3.21.5)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.22

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.22 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.22 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.22 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.22 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.22 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-66293libpngHIGH1.6.51-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.51-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.51-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.22 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.21

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.21 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.21 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.21 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.21 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.21 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.21 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.20

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.20 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.20 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.20 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.20 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.20 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.3-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.3-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.4-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.20 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.19

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.19 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.19 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.19 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.19 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.19 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.2-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.2-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.2-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.18

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.18 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.18 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.18 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.18 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.18 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.1-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.17

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.17 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.17 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.17 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.17 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.17 (alpine 3.22.1)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.1-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.1-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.51-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.5.1-r03.5.5-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.8-r02.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-58050pcre2CRITICAL10.43-r110.46-r0https://avd.aquasec.com/nvd/cve-2025-58050

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.16

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.16 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.16 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.16 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.16 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.42.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.16 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.15

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.15 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.15 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.15 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.15 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.15 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.14

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee:1.18.14 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

Vulnerabilities Listed for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.14 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-48384git-manHIGH1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3https://avd.aquasec.com/nvd/cve-2025-48384
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver:1.18.14 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.14 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.14 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.13

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.13 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.13 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.11.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.11.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.11.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.11.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.11.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.11.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.11.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.12

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.12 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.12 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.11

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.11 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-49795libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r62.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.11 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.10

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.10 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.32.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-49795libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.9

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.9 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-49795libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.8

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.8 (ubuntu 20.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-32767libexpatCRITICAL2.7.0-r02.7.5-r0https://avd.aquasec.com/nvd/cve-2026-32767
CVE-2026-25210libexpatHIGH2.7.0-r02.7.4-r0https://avd.aquasec.com/nvd/cve-2026-25210
CVE-2025-64720libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-64720
CVE-2025-65018libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-65018
CVE-2025-66293libpngHIGH1.6.47-r01.6.53-r0https://avd.aquasec.com/nvd/cve-2025-66293
CVE-2026-22695libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22695
CVE-2026-22801libpngHIGH1.6.47-r01.6.54-r0https://avd.aquasec.com/nvd/cve-2026-22801
CVE-2026-25646libpngHIGH1.6.47-r01.6.55-r0https://avd.aquasec.com/nvd/cve-2026-25646
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-49794libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49794
CVE-2025-49796libxml2CRITICAL2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49796
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-49795libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-49795
CVE-2025-6021libxml2HIGH2.13.4-r52.13.9-r0https://avd.aquasec.com/nvd/cve-2025-6021
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.7 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.7 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2025-27113libxml2HIGH2.11.8-r12.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r12.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r12.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.71.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.71.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.71.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.71.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.71.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.6

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.6 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.6 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.5 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.5 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.4 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.4 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.3 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.3 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
GHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparserHIGHv1.1.1https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.2 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.2 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.1 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.1 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
Release 1.18.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.3.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.16.23.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679

Gloo Enterprise gloo-fed-apiserver-envoy image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.0 (ubuntu 22.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.2.27-3ubuntu2.12.2.27-3ubuntu2.5https://avd.aquasec.com/nvd/cve-2025-68973

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.0 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2CRITICAL2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-26519muslHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.4-r21.2.4-r3https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-15467libssl3CRITICAL3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2025-69419libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.0.15-r13.0.19-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2025-26519muslHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519
CVE-2025-26519musl-utilsHIGH1.2.3-r51.2.3-r6https://avd.aquasec.com/nvd/cve-2025-26519

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.31.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22868golang.org/x/oauth2HIGHv0.23.00.27.0https://avd.aquasec.com/nvd/cve-2025-22868
CVE-2026-33186google.golang.org/grpcCRITICALv1.67.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.23.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.23.31.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.23.31.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.23.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.23.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.23.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679