Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
govulcheck reports that this vulnerability is found in a required module, but appears to not be called (#2 below). === Module Results === Vulnerability #1: GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues More info: https://pkg.go.dev/vuln/GO-2026-5932 Module: golang.org/x/crypto Found in: golang.org/x/crypto.0 Fixed in: N/A Vulnerability #2: GO-2026-5746 Docker: 'PUT /containers/{id}/archive' executes container binary on the host in github.com/docker/docker More info: https://pkg.go.dev/vuln/GO-2026-5746 Module: github.com/docker/docker Found in: github.com/docker/docker.2+incompatible Fixed in: N/A Vulnerability #3: GO-2026-5617 Race condition in 'docker cp' in github.com/docker/docker allows bind mount redirection More info: https://pkg.go.dev/vuln/GO-2026-5617 Module: github.com/docker/docker Found in: github.com/docker/docker.2+incompatible Fixed in: N/A This scan also found 0 vulnerabilities in packages you import and 3 vulnerabilities in modules you require, but your code doesn't appear to call these vulnerabilities.