Gloo container images are scanned using Trivy for HIGH and CRITICAL vulnerabilities. To learn more about how Solo.io detects, tracks, and remediates CVEs, see CVE lifecycle handling.

Latest 1.19.x Gloo Enterprise Release: 1.19.2

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.19.2 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.2 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.2 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.19.2 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.19.2 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.19.2 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.2 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.2 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.19.2 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.2 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.19.1

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.19.1 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.19.1 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.19.1 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.19.1 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.1 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.19.1 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.1 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.19.0

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.19.0 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.19.0 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.19.0 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.19.0 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.19.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.19.0 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.19.0 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.19.0 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Latest 1.18.x Gloo Enterprise Release: 1.18.14

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.14 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.14 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.14 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.14 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.14 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.14 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.18.14 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.14 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.13

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.13 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.13 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.13 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.13 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.13 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.18.13 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.13 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.12

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.12 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.18.12 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.11

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.11 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.18.11 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.10

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.10 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.9

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.9 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.8

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.8 (ubuntu 20.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.7

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.7 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.7 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2025-27113libxml2HIGH2.11.8-r12.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r12.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r12.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.6

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.6 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.6 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.5

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.5 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.5 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.4

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.4 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.4 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.3

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.3 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.3 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.2

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.2 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.2 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.1

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.1 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.1 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.1 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.1 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.1 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.1 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.1 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.18.0

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.18.0 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.18.0 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.18.0 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.2.15.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.18.0 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.18.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.18.0 (ubuntu 22.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.18.0 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.18.0 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2024-45337golang.org/x/cryptoCRITICALv0.28.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.28.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.31.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Latest 1.17.x Gloo Enterprise Release: 1.17.12

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.12 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.12 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.12 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.12 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.17.12 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.12 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.11

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.11 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.17.11 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.11 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.24.11.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.10

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.10 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.10 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.10 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.9

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.9 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.9 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.9 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.8

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.8 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.8 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.42-r11.1.42-r2https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.42-r11.1.42-r2https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.8 (alpine 3.21.3)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.7

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.7 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.7 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.7 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.6

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.6 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.6 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.6 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.5

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.5 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.5 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.5 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.4

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.4 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.4 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.4 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.3

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.3 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.3 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.3-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.3 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.2

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.17.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.17.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.17.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.17.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.2 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.2 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.3-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.2 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.17.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.17.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.17.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.17.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.1 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.1 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2024-45337golang.org/x/cryptoCRITICALv0.25.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.25.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.17.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.17.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.17.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.17.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.17.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.17.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.17.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.17.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.17.0 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.17.0 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.17.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30153github.com/getkin/kin-openapiHIGHv0.107.00.131.0https://avd.aquasec.com/nvd/cve-2025-30153
CVE-2024-45337golang.org/x/cryptoCRITICALv0.21.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.21.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.22.41.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Latest 1.16.x Gloo Enterprise Release: 1.16.20

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.16.20 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.20 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.20 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.16.20 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.16.20 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.16.20 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.20 (ubuntu 24.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.20 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

No Vulnerabilities Found for quay.io/solo-io/gloo-federation-console:1.16.20 (alpine 3.21.3)

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.20 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.19

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.16.19 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.19 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.19 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.16.19 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.16.19 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.16.19 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.19 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.19 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.19 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.19 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.18

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.16.18 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.18 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.18 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.16.18 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.16.18 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.16.18 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.18 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.18 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.18 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.18 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.17

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.16.17 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.17 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.17 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.16.17 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.16.17 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.16.17 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.17 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.17 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.17 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-31498c-aresHIGH1.34.3-r01.34.5-r0https://avd.aquasec.com/nvd/cve-2025-31498
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2025-32414libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.13.4-r52.13.4-r6https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.42-r11.1.42-r2https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.42-r11.1.42-r2https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.6.3-r05.6.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.17 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.23.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.16

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.16.16 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.16 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.16 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.16.16 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.16.16 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.16.16 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.16 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.16 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.16 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.4-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.16 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22869golang.org/x/cryptoHIGHv0.31.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.15

Gloo Enterprise rate-limit-ee image

No Vulnerabilities Found for quay.io/solo-io/rate-limit-ee:1.16.15 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.15 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.15 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

No Vulnerabilities Found for quay.io/solo-io/observability-ee:1.16.15 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

No Vulnerabilities Found for quay.io/solo-io/extauth-ee:1.16.15 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed:1.16.15 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.15 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.15 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.15 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-8176libexpatHIGH2.6.3-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.15 (alpine 3.17.6)

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.14

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.14 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.14 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.14 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.14 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.14 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.14 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.14 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.14 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.14 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.14 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.13

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.13 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.13 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.13 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.13 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.13 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.13 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.13 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.13 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.12

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.12 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.12 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.12 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.12 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.12 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.12 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.12 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.6-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.12 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.14-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.11

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.11 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.11 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.11 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.11 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.11 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.11 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.11 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.5-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.5-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.11 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.10

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.10 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.10 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.10 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.10 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.10 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2025-22874stdlibHIGHv1.21.111.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.10 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.10 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.5-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.5-r03.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.8-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.8-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.8-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.10 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.13-r03.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.9

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.9 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.9 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.9 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.9 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.9 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.101.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.101.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.9 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.9 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r63.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r63.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.9 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.8

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.8 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.8 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.8 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.8 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.8 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.8 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.8 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r63.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r63.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.8 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.7

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.7 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.7 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.7 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r63.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r63.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.7 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r53.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.6

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.6 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.91.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2025-22874stdlibHIGHv1.21.91.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.6 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.6 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.6 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.5

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.5 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.5 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.5 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-45490libexpatHIGH2.6.2-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.2-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.5 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.4

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.4 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.81.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.81.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.81.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.4 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.4 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-28757libexpatHIGH2.6.0-r02.6.2-r0https://avd.aquasec.com/nvd/cve-2024-28757
CVE-2024-45490libexpatHIGH2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.0-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.4 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.3

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.3 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.3 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.3 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-28757libexpatHIGH2.6.0-r02.6.2-r0https://avd.aquasec.com/nvd/cve-2024-28757
CVE-2024-45490libexpatHIGH2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.0-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.3 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.2

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.2 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.71.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.71.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.71.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.2 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.2 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2024-28757libexpatHIGH2.6.0-r02.6.2-r0https://avd.aquasec.com/nvd/cve-2024-28757
CVE-2024-45490libexpatHIGH2.6.0-r02.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.6.0-r02.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-56171libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.7-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.7-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.7-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.2 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.1

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.1 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.1 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.1 (alpine 3.18.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.5.0-r12.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.5.0-r12.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2023-52425libexpatHIGH2.5.0-r12.6.0-r0https://avd.aquasec.com/nvd/cve-2023-52425
CVE-2024-28757libexpatHIGH2.5.0-r12.6.2-r0https://avd.aquasec.com/nvd/cve-2024-28757
CVE-2024-45490libexpatHIGH2.5.0-r12.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.5.0-r12.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r53.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-25062libxml2HIGH2.11.6-r02.11.7-r0https://avd.aquasec.com/nvd/cve-2024-25062
CVE-2024-56171libxml2HIGH2.11.6-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.6-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.6-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.6-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.6-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.1 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r43.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874
Release 1.16.0

Gloo Enterprise rate-limit-ee image

Vulnerabilities Listed for quay.io/solo-io/rate-limit-ee:1.16.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/rate-limit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee:1.16.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-ee-envoy-wrapper image

No Vulnerabilities Found for quay.io/solo-io/gloo-ee-envoy-wrapper:1.16.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/envoyinit

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise observability-ee image

Vulnerabilities Listed for quay.io/solo-io/observability-ee:1.16.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/observability

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise extauth-ee image

Vulnerabilities Listed for quay.io/solo-io/extauth-ee:1.16.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/extauth

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-30204github.com/golang-jwt/jwt/v4HIGHv4.5.04.5.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-30204github.com/golang-jwt/jwt/v5HIGHv5.0.05.2.2https://avd.aquasec.com/nvd/cve-2025-30204
CVE-2025-46569github.com/open-policy-agent/opaHIGHv0.58.01.4.0https://avd.aquasec.com/nvd/cve-2025-46569
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise caching-ee image

No scan found

Gloo Enterprise discovery-ee image

No scan found

Gloo Enterprise gloo-fed image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed:1.16.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver:1.16.0 (ubuntu 20.04)

Vulnerabilities Listed for usr/local/bin/gloo-fed-apiserver

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.61.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.61.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.61.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874

Gloo Enterprise gloo-fed-apiserver-envoy image

No Vulnerabilities Found for quay.io/solo-io/gloo-fed-apiserver-envoy:1.16.0 (ubuntu 18.04)

Gloo Enterprise gloo-federation-console image

Vulnerabilities Listed for quay.io/solo-io/gloo-federation-console:1.16.0 (alpine 3.18.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-2398curlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197curlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-6119libcrypto3HIGH3.1.4-r33.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-2398libcurlHIGH8.5.0-r08.7.1-r0https://avd.aquasec.com/nvd/cve-2024-2398
CVE-2024-6197libcurlHIGH8.5.0-r08.9.0-r0https://avd.aquasec.com/nvd/cve-2024-6197
CVE-2024-45491libexpatCRITICAL2.5.0-r12.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45491
CVE-2024-45492libexpatCRITICAL2.5.0-r12.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45492
CVE-2023-52425libexpatHIGH2.5.0-r12.6.0-r0https://avd.aquasec.com/nvd/cve-2023-52425
CVE-2024-28757libexpatHIGH2.5.0-r12.6.2-r0https://avd.aquasec.com/nvd/cve-2024-28757
CVE-2024-45490libexpatHIGH2.5.0-r12.6.3-r0https://avd.aquasec.com/nvd/cve-2024-45490
CVE-2024-8176libexpatHIGH2.5.0-r12.7.0-r0https://avd.aquasec.com/nvd/cve-2024-8176
CVE-2024-6119libssl3HIGH3.1.4-r33.1.7-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-25062libxml2HIGH2.11.6-r02.11.7-r0https://avd.aquasec.com/nvd/cve-2024-25062
CVE-2024-56171libxml2HIGH2.11.6-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2024-56171
CVE-2025-24928libxml2HIGH2.11.6-r02.11.8-r1https://avd.aquasec.com/nvd/cve-2025-24928
CVE-2025-27113libxml2HIGH2.11.6-r02.11.8-r2https://avd.aquasec.com/nvd/cve-2025-27113
CVE-2025-32414libxml2HIGH2.11.6-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32414
CVE-2025-32415libxml2HIGH2.11.6-r02.11.8-r3https://avd.aquasec.com/nvd/cve-2025-32415
CVE-2024-55549libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2024-55549
CVE-2025-24855libxsltHIGH1.1.38-r01.1.38-r1https://avd.aquasec.com/nvd/cve-2025-24855
CVE-2025-31115xz-libsHIGH5.4.3-r05.4.3-r1https://avd.aquasec.com/nvd/cve-2025-31115

Gloo Enterprise gloo-fed-rbac-validating-webhook image

Vulnerabilities Listed for quay.io/solo-io/gloo-fed-rbac-validating-webhook:1.16.0 (alpine 3.17.6)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-6119libcrypto3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119
CVE-2024-6119libssl3HIGH3.0.12-r23.0.15-r0https://avd.aquasec.com/nvd/cve-2024-6119

Vulnerabilities Listed for usr/local/bin/gloo-fed-rbac-validating-webhook

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-45337golang.org/x/cryptoCRITICALv0.17.00.31.0https://avd.aquasec.com/nvd/cve-2024-45337
CVE-2025-22869golang.org/x/cryptoHIGHv0.17.00.35.0https://avd.aquasec.com/nvd/cve-2025-22869
CVE-2024-24790stdlibCRITICALv1.21.51.21.11, 1.22.4https://avd.aquasec.com/nvd/cve-2024-24790
CVE-2023-45288stdlibHIGHv1.21.51.21.9, 1.22.2https://avd.aquasec.com/nvd/cve-2023-45288
CVE-2025-22874stdlibHIGHv1.21.51.23.10, 1.24.4https://avd.aquasec.com/nvd/cve-2025-22874