SUSE-CU-2026:7288-1: Security update of private-registry/harbor-trivy-adapter
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Jul 24 07:14:25 UTC 2026
SUSE Container Update Advisory: private-registry/harbor-trivy-adapter
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7288-1
Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.23 , private-registry/harbor-trivy-adapter:latest
Container Release : 1.23
Severity : important
Type : security
References : 1266495 1271658 1271670 CVE-2026-39821 CVE-2026-50151 CVE-2026-56852
-----------------------------------------------------------------
The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3147-1
Released: Tue Jul 21 14:44:03 2026
Summary: Security update for trivy
Type: security
Severity: important
References: 1266495,1271658,1271670,CVE-2026-39821,CVE-2026-50151,CVE-2026-56852
This update for trivy fixes the following issues
- Update to version 0.72.0
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495).
- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658).
- CVE-2026-56852: x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271670).
The following package changes have been done:
- trivy-0.72.0-150000.1.27.1 updated
More information about the sle-container-updates
mailing list