Trivy is not reporting CVE-2025-30399 in .NET container #9445
Closed
tomkerkhove
started this conversation in
False Detection
Replies: 2 comments 8 replies
-
|
Hello @tomkerkhove Can you send file name with vulnerable package? Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
8 replies
-
|
track #9451 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
CVE-2025-30399
Description
Trivy is not reporting CVE-2025-30399 in .NET container that is running version that is subject to it.
As per Alpine coverage & .NET coverage, it should report known vulnerabilities with a fix.
Reproduction Steps
1. Run "trivy image mcr.microsoft.com/azure-api-management/gateway:2.9.1" 2. https://github.com/advisories/GHSA-266m-wp2v-x7mq is not flaggedTarget
Container Image
Scanner
Vulnerability
Target OS
No response
Debug Output
Version
~ trivy --version Version: 0.65.0 Vulnerability DB: Version: 2 UpdatedAt: 2025-09-05 06:30:47.074373351 +0000 UTC NextUpdate: 2025-09-06 06:30:47.07437308 +0000 UTC DownloadedAt: 2025-09-05 08:42:19.1349901 +0000 UTCChecklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions