github.com/quay/claircore
foundation modules for scanning container packages and reporting vulnerabilities
Activity
- Latest release
- 5d ago
- Total releases
- 63
- Cadence
- ~24 days
- Last 12 months
- 12
Reach
- Stars
- 153
Details
- First release
- Nov 27, 2019
| Version | Released | |
|---|---|---|
v1.6.0
minor
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (31)
+ 23 more |
|
v1.5.54
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.54
patch
Dependencies (29)
+ 21 more |
|
v1.5.53
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.53
patch
Dependencies (29)
+ 21 more |
|
v1.5.52
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.52
patch
Dependencies (27)
+ 19 more |
|
v1.5.51
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.51
patch
Dependencies (28)
+ 20 more |
|
v1.5.50
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.50
patch
Dependencies (28)
+ 20 more |
|
v1.5.49
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.49
patch
Dependencies (29)
+ 21 more |
|
v1.5.48
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.48
patch
Dependencies (31)
+ 23 more |
|
v1.5.47
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.47
patch
Dependencies (31)
+ 23 more |
|
v1.5.46
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.46
patch
Dependencies (31)
+ 23 more |
|
v1.5.45
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.45
patch
Dependencies (31)
+ 23 more |
|
v1.5.44
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.44
patch
Dependencies (31)
+ 23 more |
|
v1.5.43
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.43
patch
Dependencies (32)
+ 24 more |
|
v1.5.42
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.42
patch
Dependencies (32)
+ 24 more |
|
v1.5.41
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.41
patch
Dependencies (32)
+ 24 more |
|
v1.5.40
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.40
patch
Dependencies (32)
+ 24 more |
|
v1.5.39
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.39
patch
Dependencies (33)
+ 25 more |
|
v1.5.38
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.38
patch
Dependencies (32)
+ 24 more |
|
v1.5.37
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.37
patch
Dependencies (32)
+ 24 more |
|
v1.5.36
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.36
patch
Dependencies (32)
+ 24 more |
|
v1.5.35
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.35
patch
Dependencies (32)
+ 24 more |
|
v1.5.32
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.32
patch
Dependencies (30)
+ 22 more |
|
v1.5.30
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.30
patch
Dependencies (30)
+ 22 more |
|
v1.5.29
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.29
patch
Dependencies (30)
+ 22 more |
|
v1.5.27
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.27
patch
Dependencies (29)
+ 21 more |
|
v1.5.22
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.22
patch
Dependencies (29)
+ 21 more |
|
v1.5.18
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.18
patch
Dependencies (27)
+ 19 more |
|
v1.5.16
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.16
patch
Dependencies (27)
+ 19 more |
|
v1.5.14
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.14
patch
Dependencies (27)
+ 19 more |
|
v1.5.7
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.7
patch
Dependencies (27)
+ 19 more |
|
v1.5.3
minor
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.5.3
minor
Dependencies (27)
+ 19 more |
|
v1.4.18
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.4.18
patch
Dependencies (28)
+ 20 more |
|
v1.4.17
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.4.17
patch
Dependencies (28)
+ 20 more |
|
v1.4.15
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.4.15
patch
Dependencies (28)
+ 20 more |
|
v1.4.12
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.4.12
patch
Dependencies (28)
+ 20 more |
|
v1.4.8
patch
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.4.8
patch
Dependencies (28)
+ 20 more |
|
v1.4.7
minor
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.4.7
minor
Dependencies (28)
+ 20 more |
|
v0.4.8
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.8
patch
Dependencies (27)
+ 19 more |
|
v1.1.0
major
1 CVE
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev |
v1.1.0
major
Dependencies (27)
+ 19 more |
|
v1.1.0-rc.0
pre
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v1.1.0-rc.0
pre
Dependencies (28)
+ 20 more |
|
v0.4.7
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.7
patch
Dependencies (27)
+ 19 more |
|
v0.1.26
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.26
patch
Dependencies (25)
+ 17 more |
|
v0.4.2
minor
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.2
minor
Dependencies (27)
+ 19 more |
|
v0.1.25
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.25
patch
Dependencies (25)
+ 17 more |
|
v0.3.2
minor
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.3.2
minor
Dependencies (24)
+ 16 more |
|
v0.1.21
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.21
patch
Dependencies (24)
+ 16 more |
|
v0.2.0
minor
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.2.0
minor
Dependencies (23)
+ 15 more |
|
v0.1.19
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.19
patch
Dependencies (24)
+ 16 more |
|
v0.1.18
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.18
patch
Dependencies (24)
+ 16 more |
|
v0.1.16
patch
2 CVEs
CVE-2026-10517
GO-2026-5939
GHSA-698x-9w2p-7vvp
Jul 17, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints in github.com/quay/claircore References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2021-3762
GO-2022-0346
GHSA-mq47-6wwv-v79w
Jul 15, 2022
Path traversal in github.com/quay/claircore A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem. Fixed in
1.1.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.1.16
patch
Dependencies (24)
+ 16 more |