[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21645-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":20,"duplicates":21,"related":22,"reserved_at":9,"published_at":26,"modified_at":27,"state":9,"summary":28,"references_raw":30,"kevs":50,"epss":9,"epss_history":51,"metrics":52,"affected":53},"OPENSUSE-SU-2026:21645-1","Security update for trivy\n\nThis update for trivy fixes the following issue:\n\n- CVE-2026-72815,CVE-2026-72816,CVE-2026-72817: github.com/go-chi/chi/v5: multiple IP spoofing vulnerabilities allow\n  authentication bypass, authorization override, and log forgery (bsc#1276128).\n\nChanges for trivy:\n\n- Update to version 0.74.0:\n * release: v0.74.0 [main] (#11037)\n * chore(deps): update golang.org/x modules (#11094)\n * chore(deps): bump the docker group with 2 updates (#11090)\n * docs: update release branch ruleset instructions (#11093)\n * chore(deps): bump the common group across 1 directory with 7 updates (#11086)\n * fix(misconf): unmark cty values outside the evaluation context (#11078)\n * chore(deps): bump the aws group across 1 directory with 6 updates (#11053)\n * fix(misconf): parse Azure flexible server parameters under their own names (#11072)\n * chore(deps): bump the docker group with 2 updates (#11054)\n * feat: add RapidFort curated image scanner (#10452)\n * feat(java): resolve JAR license URLs to SPDX IDs (Bundle-License, pom \u003Curl>) (#10948)\n * refactor(misconf): remove unused Azure expression-related code (#10637)\n * fix(server): preserve check aliases and query in uploaded blobs (#11080)\n * fix(java): read artifact properties only from the MANIFEST.MF main section (#11066)\n * fix(terraform): support OpenTofu language block (#10923)\n * chore(deps): bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2 (#11063)\n * ci: trigger Auto Ready for Review after Test docs (#11045)\n * docs: remove trivy-checks from AWS ECR locations (#11044)\n * refactor(ubuntu): move EOL version resolution out of loop (#11047)\n * fix(python): normalize dependency names in PEP 621 pyproject.toml (#11050)\n * chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#11042)\n * chore(deps): bump github.com/nikolalohinski/gonja/v2 to v2.9.0 (#11038)\n * fix(terraform): avoid panic when for_each local has unknown object values (#11019)\n * chore(deps): bump the github-actions group across 2 directories with 15 updates (#11028)\n * ci(spdx): migrate to Slack notifications (#11032)\n * ci(helm): bump Trivy version to 0.73.0 for Trivy Helm Chart 0.25.0 (#11034)\n- Update to version 0.73.0:\n * release: v0.73.0 [main] (#11012)\n * docs: clarify debug logs when version check or telemetry is disabled (#10984)\n * feat(java): support user-defined Maven mirrors in trivy.yaml (#11006)\n * chore(deps): bump the common group across 1 directory with 17 updates (#11025)\n * chore(deps): bump the docker group across 1 directory with 2 updates (#10991)\n * chore(deps): bump the aws group across 1 directory with 6 updates (#10947)\n * refactor(alpine): remove type assertion when reading the APKINDEX archive (#11013)\n * chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#10995)\n * feat(vex): discover OpenVEX in generic in-toto OCI referrers (#10986)\n * refactor(vuln): add OS.Supplier field and unify supplier terminology (#11007)\n * chore(deps): bump github.com/google/cel-go from 0.28.1 to 0.30.0 (#11009)\n * fix(vex): reject non-local VEX repository names (#10987)\n * fix(vex): handle 304 status code (#10307)\n * fix(vuln): don't skip packages covered by a driver's own advisory feed (#10980)\n * fix(conda): avoid panic on an all-operator dependency line (#10955)\n * chore: add schema id (#10969)\n * feat(vex): native discovery of VEX documents stored as OCI artifacts (#10932)\n * feat: add bounded read helpers (#10974)\n * fix(dotnet): identify deps.json root project from dependency graph (#10954)\n * feat(java): read Jenkins plugin manifest licenses (#10939)\n * docs: ask contributors to coordinate before starting on an issue (#10940)\n * fix(nodejs): support pnpm workspaces with overlapping packages (#10894)\n * ci: create release branch with the App token to bypass the merge queue rule (#10931)\n * chore(deps): bump the common group across 1 directory with 15 updates (#10892)\n * feat(seal): detect no-prefix packages by version suffix (#10911)\n * chore(deps): bump the testcontainers group with 2 updates (#10918)\n * chore(deps): bump the docker group across 1 directory with 4 updates (#10919)\n * fix(java): set per-file digest for nested JARs (#10855)\n * fix(misconf): guard nil Healthcheck when building Dockerfile from history (#10899)\n * ci(helm): bump Trivy version to 0.72.0 for Trivy Helm Chart 0.24.0 (#10908)\n * ci(helm): allow trivy team to approve Chart.yaml bumps (#10912)\n",null,[],[],[],[14,16,18],{"_key":15},"CVE-2026-72815",{"_key":17},"CVE-2026-72816",{"_key":19},"CVE-2026-72817",[],[],[23,24,25],{"_key":15},{"_key":17},{"_key":19},"2026-08-25T07:22:37Z","2026-08-27T18:23:13.685422441Z",{"cisa_kev":29,"cisa_ransomware":29,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[31,37,42,46],{"url":32,"sources":33,"tags":35},"https://bugzilla.suse.com/1276128",[34],"osv_opensuse",[36],"REPORT",{"url":38,"sources":39,"tags":40},"https://www.suse.com/security/cve/CVE-2026-72815",[34],[41],"WEB",{"url":43,"sources":44,"tags":45},"https://www.suse.com/security/cve/CVE-2026-72816",[34],[41],{"url":47,"sources":48,"tags":49},"https://www.suse.com/security/cve/CVE-2026-72817",[34],[41],[],[],[],[54],{"ecosystem":55,"name":56,"vendor":57,"product":58,"cpe_part":9,"purl_type":59,"purl_namespace":57,"purl_name":58,"source":9,"versions":60},"openSUSE","trivy","opensuse","trivy&distro=openSUSE Leap 16.0","rpm",[61],{"version":62,"is_range":63,"range_type":64,"version_start":9,"version_start_type":9,"version_end":65,"version_end_type":66,"fixed_in":9},"lt0_74_0_160000_1_1",true,"ecosystem","0.74.0-160000.1.1","excluding"]