SUSE-CU-2026:7288-1: Security update of private-registry/harbor-trivy-adapter

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 24 07:14:25 UTC 2026


SUSE Container Update Advisory: private-registry/harbor-trivy-adapter
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7288-1
Container Tags        : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.23 , private-registry/harbor-trivy-adapter:latest
Container Release     : 1.23
Severity              : important
Type                  : security
References            : 1266495 1271658 1271670 CVE-2026-39821 CVE-2026-50151 CVE-2026-56852
-----------------------------------------------------------------

The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3147-1
Released:    Tue Jul 21 14:44:03 2026
Summary:     Security update for trivy
Type:        security
Severity:    important
References:  1266495,1271658,1271670,CVE-2026-39821,CVE-2026-50151,CVE-2026-56852
This update for trivy fixes the following issues

- Update to version 0.72.0
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495).
- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658).
- CVE-2026-56852: x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271670).


The following package changes have been done:

- trivy-0.72.0-150000.1.27.1 updated


More information about the sle-container-updates mailing list