Skip to content
You are viewing the documentation for Solo Enterprise for Istio, formerly known as Gloo Mesh (OSS APIs).

Security and CVE scan results

Page as Markdown

Review security and CVE scan results for Solo.io products.

Gloo container images are scanned using Trivy for HIGH and CRITICAL vulnerabilities. To learn more about how Solo.io detects, tracks, and remediates CVEs, see CVE lifecycle handling.

Security and CVE scan

Latest 2.12.x gloo mesh enterprise Release: 2.12.3

gloo mesh enterprise gloo-mesh-envoy image

No scan found

gloo mesh enterprise gloo-mesh-agent image

No scan found

gloo mesh enterprise gloo-mesh-apiserver image

No scan found

gloo mesh enterprise gloo-mesh-spire-controller image

No scan found

gloo mesh enterprise gloo-mesh-portal-server image

No scan found

gloo mesh enterprise gloo-mesh-analyzer image

No scan found

gloo mesh enterprise gloo-mesh-mgmt-server image

No scan found

gloo mesh enterprise gloo-mesh-istiod-agent image

No scan found

gloo mesh enterprise gloo-mesh-ui image

No scan found

Release 2.12.2

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.12.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.12.2 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.12.1

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.12.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.12.1 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.12.0

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.12.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.12.0 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Latest 2.11.x gloo mesh enterprise Release: 2.11.5

gloo mesh enterprise gloo-mesh-envoy image

No scan found

gloo mesh enterprise gloo-mesh-agent image

No scan found

gloo mesh enterprise gloo-mesh-apiserver image

No scan found

gloo mesh enterprise gloo-mesh-spire-controller image

No scan found

gloo mesh enterprise gloo-mesh-portal-server image

No scan found

gloo mesh enterprise gloo-mesh-analyzer image

No scan found

gloo mesh enterprise gloo-mesh-mgmt-server image

No scan found

gloo mesh enterprise gloo-mesh-istiod-agent image

No scan found

gloo mesh enterprise gloo-mesh-ui image

No scan found

Release 2.11.4

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.11.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.11.4 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.11.3

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.11.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv29.1.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.7.65.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-25679stdlibHIGHv1.25.71.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.71.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.11.3 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.11.2

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.11.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.11.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.11.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.11.1

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.11.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.11.1 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.51.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.51.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.25.51.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.51.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.11.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.11.0

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.11.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.3.3+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.38.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.38.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.11.0 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.24.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.76.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.25.31.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.25.31.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.25.31.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.25.31.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.25.31.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.11.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Latest 2.10.x gloo mesh enterprise Release: 2.10.6

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-apiserver image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-spire-controller image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-portal-server image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-analyzer image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-mgmt-server image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-istiod-agent image

No Vulnerabilities Found for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.6 (alpine 3.23.4)

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.10.5

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.5 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.10.4

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.10.3

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.10.2

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.2 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.10.1

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.2.2+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.1 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.04.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.73.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.10.0

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.10.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.10.0 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.61.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-58183stdlibHIGHv1.24.61.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.61.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.61.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.61.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.61.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.10.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Latest 2.9.x gloo mesh enterprise Release: 2.9.6

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.39.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.39.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.1.34.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.78.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2026-32280stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.26.11.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283
CVE-2026-33810stdlibHIGHv1.26.11.26.2https://avd.aquasec.com/nvd/cve-2026-33810

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.6 (alpine 3.23.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-31789libcrypto3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-31789libssl3CRITICAL3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2026-28387libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.5.5-r03.5.6-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r211.2.5-r23https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.9.5

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.9.4

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.9.3

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.3 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.9.2

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2025-32462sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32462
CVE-2025-32463sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32463
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.2 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.9.1

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.1 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2025-32462sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32462
CVE-2025-32463sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32463
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.1 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.9.0

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.9.0 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2025-32462sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32462
CVE-2025-32463sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32463
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv28.0.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.35.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.35.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.9.0 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Latest 2.8.x gloo mesh enterprise Release: 2.8.6

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.8.6 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.8.6 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.8.6 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.8.5

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.8.5 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.8.5 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.43.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.111.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.111.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2026-25679stdlibHIGHv1.24.111.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.111.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.8.5 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.8.4

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.8.4 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.32.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu5.24.04.11.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-34986github.com/go-jose/go-jose/v4HIGHv4.0.54.1.4https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.36.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.36.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.8.4 (alpine 3.21.5)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.5-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.5-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.74.21.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.91.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-61726stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.91.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.91.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.91.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.91.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.8.4 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.8.3

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.8.3 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2025-32462sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32462
CVE-2025-32463sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32463
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-spire-controller image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-spire-controller:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/spire-controller-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-portal-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-portal-server:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/portal-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-analyzer image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-analyzer:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/analyzer-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-mgmt-server image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-mgmt-server:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/mgmt-server-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.271.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-istiod-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-istiod-agent:2.8.3 (alpine 3.21.4)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.4-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.4-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/istiod-agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33186google.golang.org/grpcCRITICALv1.71.11.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-68121stdlibCRITICALv1.24.41.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-47907stdlibHIGHv1.24.41.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.41.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.41.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.41.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.41.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.41.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-ui image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-ui:2.8.3 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184
Release 2.8.2

gloo mesh enterprise gloo-mesh-envoy image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-envoy:2.8.2 (ubuntu 24.04)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-68973gpgvHIGH2.4.4-2ubuntu17.22.4.4-2ubuntu17.4https://avd.aquasec.com/nvd/cve-2025-68973
CVE-2025-32462sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32462
CVE-2025-32463sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.1https://avd.aquasec.com/nvd/cve-2025-32463
CVE-2026-35535sudoHIGH1.9.15p5-3ubuntu51.9.15p5-3ubuntu5.24.04.2https://avd.aquasec.com/nvd/cve-2026-35535

gloo mesh enterprise gloo-mesh-agent image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-agent:2.8.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/agent-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32283

gloo mesh enterprise gloo-mesh-apiserver image

Vulnerabilities Listed for gcr.io/gloo-mesh/gloo-mesh-apiserver:2.8.2 (alpine 3.21.3)

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2025-15467libcrypto3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libcrypto3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libcrypto3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libcrypto3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2025-15467libssl3CRITICAL3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-15467
CVE-2026-31789libssl3CRITICAL3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-31789
CVE-2025-69419libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69419
CVE-2025-69421libssl3HIGH3.3.3-r03.3.6-r0https://avd.aquasec.com/nvd/cve-2025-69421
CVE-2026-28387libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28387
CVE-2026-28388libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28388
CVE-2026-28389libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28389
CVE-2026-28390libssl3HIGH3.3.3-r03.3.7-r0https://avd.aquasec.com/nvd/cve-2026-28390
CVE-2026-40200muslHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-40200musl-utilsHIGH1.2.5-r91.2.5-r11https://avd.aquasec.com/nvd/cve-2026-40200
CVE-2026-22184zlibHIGH1.3.1-r21.3.2-r0https://avd.aquasec.com/nvd/cve-2026-22184

Vulnerabilities Listed for usr/local/bin/apiserver-linux-amd64

Vulnerability IDPackageSeverityInstalled VersionFixed VersionReference
CVE-2024-25621github.com/containerd/containerdHIGHv1.7.241.7.29https://avd.aquasec.com/nvd/cve-2024-25621
CVE-2025-15558github.com/docker/cliHIGHv27.5.1+incompatible29.2.0https://avd.aquasec.com/nvd/cve-2025-15558
CVE-2026-34040github.com/docker/dockerHIGHv27.5.0+incompatible29.3.1https://avd.aquasec.com/nvd/cve-2026-34040
CVE-2026-34986github.com/go-jose/go-jose/v3HIGHv3.0.33.0.5https://avd.aquasec.com/nvd/cve-2026-34986
CVE-2026-33816github.com/jackc/pgx/v5CRITICALv5.6.05.9.0https://avd.aquasec.com/nvd/cve-2026-33816
CVE-2026-35469github.com/moby/spdystreamHIGHv0.5.00.5.1https://avd.aquasec.com/nvd/cve-2026-35469
CVE-2026-24051go.opentelemetry.io/otel/sdkHIGHv1.34.01.40.0https://avd.aquasec.com/nvd/cve-2026-24051
CVE-2026-39883go.opentelemetry.io/otel/sdkHIGHv1.34.01.43.0https://avd.aquasec.com/nvd/cve-2026-39883
CVE-2026-33186google.golang.org/grpcCRITICALv1.70.01.79.3https://avd.aquasec.com/nvd/cve-2026-33186
CVE-2025-53547helm.sh/helm/v3HIGHv3.17.33.18.4, 3.17.4https://avd.aquasec.com/nvd/cve-2025-53547
CVE-2025-68121stdlibCRITICALv1.24.21.24.13, 1.25.7, 1.26.0-rc.3https://avd.aquasec.com/nvd/cve-2025-68121
CVE-2025-22874stdlibHIGHv1.24.21.24.4https://avd.aquasec.com/nvd/cve-2025-22874
CVE-2025-47907stdlibHIGHv1.24.21.23.12, 1.24.6https://avd.aquasec.com/nvd/cve-2025-47907
CVE-2025-58183stdlibHIGHv1.24.21.24.8, 1.25.2https://avd.aquasec.com/nvd/cve-2025-58183
CVE-2025-61726stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61726
CVE-2025-61728stdlibHIGHv1.24.21.24.12, 1.25.6https://avd.aquasec.com/nvd/cve-2025-61728
CVE-2025-61729stdlibHIGHv1.24.21.24.11, 1.25.5https://avd.aquasec.com/nvd/cve-2025-61729
CVE-2026-25679stdlibHIGHv1.24.21.25.8, 1.26.1https://avd.aquasec.com/nvd/cve-2026-25679
CVE-2026-32280stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32280
CVE-2026-32281stdlibHIGHv1.24.21.25.9, 1.26.2https://avd.aquasec.com/nvd/cve-2026-32281
CVE-2026-32283