Scanning is missing a reported CVE in ASP.NET Core 6 #9261
Closed
sirredbeard
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
|
Hello @sirredbeard Trivy uses GitHub Advisory database for .Net packages - https://trivy.dev/latest/docs/scanner/vulnerability/#langpkg-data-sources When GitHub updates this advisory, Trivy will be able to detect CVE-2025-7326. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Description
trivy image --severity HIGH,CRITICAL mcr.microsoft.com/dotnet/aspnet:6.0detects CVE-2025-24070 in ASP.NET Core 6, but not CVE-2025-7326.Trivy should be detecting CVE-2025-7326 in scans of ASP.NET Core 6, but it is not.
Trivy is detecting CVE-2025-24070. CVE-2025-24070 doesn't actually include ASP.NET Core 6 in the affected version ranges, however the GHSA entry for CVE-2025-24070 was updated to include 6 because 6 is affected as well, so it's appropriate that Trivy report CVE-2025-2407 too.
CVE-2025-24070 was reported first, then the GHSA was updated, then CVE-2025-7326 was filed separately to directly address ASP.NET Core 6.
Desired Behavior
Trivy scans should report both CVE-2025-24070 and CVE-2025-7326 when ASP.NET Core 6 is found.
Actual Behavior
Only CVE-2025-24070 is being reported.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Debug Output
Operating System
Ubuntu 22.04
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions