+ {"findings":[{"awsAccountId":"123456789012","description":"The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).","epss":{"score":0.00024},"exploitAvailable":"NO","findingArn":"arn:aws:inspector2:us-east-2:123456789012:finding/fb6294abcdef0123456789abcdef8123","firstObservedAt":1748539687.919,"fixAvailable":"YES","inspectorScore":6.5,"inspectorScoreDetails":{"adjustedCvss":{"adjustments":[],"cvssSource":"NVD","score":6.5,"scoreSource":"NVD","scoringVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}},"lastObservedAt":1749165796.162,"packageVulnerabilityDetails":{"cvss":[{"baseScore":6.5,"scoringVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","source":"NVD","version":"3.1"},{"baseScore":6.5,"scoringVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","source":"NVD","version":"3.1"}],"referenceUrls":["https://groups.google.com/g/golang-announce/c/ezSKR9vqbqA","https://nvd.nist.gov/vuln/detail/CVE-2025-22872","https://alas.aws.amazon.com/AL2023/ALAS-2025-981.html","https://alas.aws.amazon.com/AL2/ALASDOCKER-2025-064.html","https://alas.aws.amazon.com/AL2023/ALAS-2025-980.html","https://alas.aws.amazon.com/AL2/ALASDOCKER-2025-063.html","https://alas.aws.amazon.com/AL2023/ALAS-2025-979.html","https://alas.aws.amazon.com/cve/json/v1/CVE-2025-22872.json","https://alas.aws.amazon.com/AL2/ALAS-2025-2863.html","https://alas.aws.amazon.com/cve/json/v1/CVE-2025-22872.json"],"relatedVulnerabilities":[],"source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-22872","vendorCreatedAt":1744827364,"vendorSeverity":"MEDIUM","vendorUpdatedAt":1747437319,"vulnerabilityId":"CVE-2025-22872","vulnerablePackages":[{"epoch":0,"filePath":"vol-0e47545061282cd35:/p1:opt/cni/bin/aws-cni","fixedInVersion":"0.38.0","name":"golang.org/x/net","packageManager":"GOBINARY","version":"v0.1.0"},{"epoch":0,"filePath":"vol-0e47545061282cd35:/p1:etc/eks/image-credential-provider/ecr-credential-provider","fixedInVersion":"0.38.0","name":"golang.org/x/net","packageManager":"GOBINARY","version":"v0.30.0"},{"epoch":0,"filePath":"vol-0e47545061282cd35:/p1:opt/cni/bin/dhcp","fixedInVersion":"0.38.0","name":"golang.org/x/net","packageManager":"GOBINARY","version":"v0.30.0"},{"epoch":0,"filePath":"vol-0e47545061282cd35:/p1:usr/bin/aws-iam-authenticator","fixedInVersion":"0.38.0","name":"golang.org/x/net","packageManager":"GOBINARY","version":"v0.30.0"},{"epoch":0,"filePath":"vol-0e47545061282cd35:/p1:usr/bin/kubelet","fixedInVersion":"0.38.0","name":"golang.org/x/net","packageManager":"GOBINARY","version":"v0.30.0"},{"arch":"X86_64","epoch":0,"fixedInVersion":"0:2.0.5-1.amzn2.0.1","name":"nerdctl","packageManager":"OS","release":"1.amzn2.0.1","remediation":"yum update nerdctl","version":"2.0.4"}]},"remediation":{"recommendation":{"text":"None Provided"}},"resources":[{"details":{"awsEc2Instance":{"iamInstanceProfileArn":"arn:aws:iam::123456789012:instance-profile/eks-0012345a-1234-5678-1234-6c1abcdef012","imageId":"ami-0e0f0123456789abd","ipV4Addresses":["10.90.1.245","10.90.1.45","10.90.1.168","10.90.1.157","1.128.0.1","10.90.1.103","10.90.1.197","10.90.1.220","10.90.1.86","10.90.1.29","10.90.1.18","10.90.1.181","10.90.1.161","10.90.1.229","10.90.1.108","10.90.1.219","10.90.1.9","10.90.1.106","10.90.1.206"],"ipV6Addresses":[],"launchedAt":1748534768,"platform":"AMAZON_LINUX_2","subnetId":"subnet-0ababcdefabcdef8b","type":"t3.medium","vpcId":"vpc-04ab0123456789123"}},"id":"i-0fabcdefabcdef50b","partition":"aws","region":"us-east-2","tags":{"aws:autoscaling:groupName":"eks-sei_demo_prod_linux-00c12345-abcd-1234-5678-601234567896","aws:ec2launchtemplate:version":"6","aws:eks:cluster-name":"sei_demo_prod","eks:cluster-name":"sei_demo_prod","eks:nodegroup-name":"sei_demo_prod_linux","k8s.io/cluster-autoscaler/enabled":"true","k8s.io/cluster-autoscaler/sei_demo_prod":"owned","kubernetes.io/cluster/sei_demo_prod":"owned"},"type":"AWS_EC2_INSTANCE"}],"severity":"MEDIUM","status":"ACTIVE","title":"CVE-2025-22872 - golang.org/x/net, golang.org/x/net and 4 more","type":"PACKAGE_VULNERABILITY","updatedAt":1749165796.162}]}
0 commit comments