UNCLASSIFIED - NO CUI

Skip to content

chore(findings): afdco/misp-modules

Summary

afdco/misp-modules has 265 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=afdco/misp-modules&tag=v3.0.2-2&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2020-23922 Twistlock CVE Low giflib-5.2.1-2.5 0.03785 false
CVE-2020-23922 Anchore CVE Low libgif7-5.2.1-2.5 0.03785 false
CVE-2017-17740 Twistlock CVE Low openldap-2.5.13+dfsg-5 0.02838 false
CVE-2017-17740 Anchore CVE Low libldap-2.5-0-2.5.13+dfsg-5 0.02838 false
CVE-2017-2814 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.01958 false
CVE-2017-2814 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.01958 false
CVE-2017-2814 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.01958 false
CVE-2015-3276 Twistlock CVE Low openldap-2.5.13+dfsg-5 0.01757 false
CVE-2015-3276 Anchore CVE Low libldap-2.5-0-2.5.13+dfsg-5 0.01757 false
CVE-2017-16232 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.01738 false
CVE-2017-2820 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.01219 false
CVE-2017-2820 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.01219 false
CVE-2017-2820 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.01219 false
CVE-2023-2953 Twistlock CVE Low openldap-2.5.13+dfsg-5 0.01149 false
CVE-2023-2953 Anchore CVE High libldap-2.5-0-2.5.13+dfsg-5 0.01149 false
CVE-2021-40633 Twistlock CVE Low giflib-5.2.1-2.5 0.01031 false
CVE-2021-40633 Anchore CVE Low libgif7-5.2.1-2.5 0.01031 false
CVE-2019-9543 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00678 false
CVE-2019-9543 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00678 false
CVE-2019-9543 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00678 false
CVE-2017-9083 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00676 false
CVE-2017-9083 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00676 false
CVE-2017-9083 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00676 false
CVE-2020-28463 Anchore CVE Medium reportlab-4.3.1 0.00671 false
CVE-2016-10505 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00656 false
CVE-2016-10505 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00656 false
CVE-2024-28757 Twistlock CVE Low expat-2.5.0-1+deb12u2 0.00621 false
CVE-2024-28757 Anchore CVE Low libexpat1-2.5.0-1+deb12u2 0.00621 false
CVE-2018-16376 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00566 false
CVE-2018-16376 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00566 false
CVE-2025-61765 Twistlock CVE Medium python-socketio-5.12.1 0.00565 false
CVE-2018-18064 Twistlock CVE Low cairo-1.16.0-7 0.00510 false
CVE-2018-18064 Anchore CVE Low libcairo2-1.16.0-7 0.00510 false
CVE-2017-2818 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00504 false
CVE-2017-2818 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00504 false
CVE-2017-2818 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00504 false
CVE-2012-0039 Anchore CVE Low libglib2.0-0-2.74.6-2+deb12u7 0.00492 false
CVE-2016-9114 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00478 false
CVE-2016-9114 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00478 false
CVE-2018-5709 Twistlock CVE Low krb5-1.20.1-2+deb12u4 0.00463 false
CVE-2018-5709 Anchore CVE Low libgssapi-krb5-2-1.20.1-2+deb12u4 0.00463 false
CVE-2018-5709 Anchore CVE Low libkrb5-3-1.20.1-2+deb12u4 0.00463 false
CVE-2018-5709 Anchore CVE Low libkrb5support0-1.20.1-2+deb12u4 0.00463 false
CVE-2018-5709 Anchore CVE Low libk5crypto3-1.20.1-2+deb12u4 0.00463 false
CVE-2025-0725 Twistlock CVE Low curl-7.88.1-10+deb12u14 0.00460 false
CVE-2025-0725 Anchore CVE Low libcurl4-7.88.1-10+deb12u14 0.00460 false
CVE-2018-10126 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00459 false
CVE-2018-10126 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00459 false
CVE-2016-9113 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00448 false
CVE-2016-9113 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00448 false
CVE-2023-6277 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00418 false
CVE-2023-6277 Anchore CVE Medium libtiff6-4.5.0-6+deb12u3 0.00418 false
CVE-2016-9115 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00374 false
CVE-2016-9115 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00374 false
CVE-2016-9117 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00357 false
CVE-2016-9117 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00357 false
CVE-2016-9116 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00357 false
CVE-2016-9116 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00357 false
CVE-2017-9937 Twistlock CVE Low jbigkit-2.1-6.1 0.00354 false
CVE-2017-9937 Anchore CVE Low libjbig0-2.1-6.1 0.00354 false
CVE-2019-9545 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00333 false
CVE-2019-9545 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00333 false
CVE-2019-9545 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00333 false
CVE-2019-6988 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00327 false
CVE-2019-6988 Anchore CVE Low libopenjp2-7-2.5.0-2+deb12u2 0.00327 false
CVE-2021-45346 Anchore CVE Low libsqlite3-0-3.40.1-2+deb12u2 0.00242 false
CVE-2021-4214 Twistlock CVE Low libpng1.6-1.6.39-2 0.00233 false
CVE-2021-4214 Anchore CVE Low libpng16-16-1.6.39-2 0.00233 false
CVE-2024-45993 Twistlock CVE Low giflib-5.2.1-2.5 0.00225 false
CVE-2024-45993 Anchore CVE Low libgif7-5.2.1-2.5 0.00225 false
CVE-2024-26458 Twistlock CVE Low krb5-1.20.1-2+deb12u4 0.00206 false
CVE-2024-26458 Anchore CVE Low libk5crypto3-1.20.1-2+deb12u4 0.00206 false
CVE-2024-26458 Anchore CVE Low libkrb5-3-1.20.1-2+deb12u4 0.00206 false
CVE-2024-26458 Anchore CVE Low libkrb5support0-1.20.1-2+deb12u4 0.00206 false
CVE-2024-26458 Anchore CVE Low libgssapi-krb5-2-1.20.1-2+deb12u4 0.00206 false
CVE-2024-2379 Twistlock CVE Low curl-7.88.1-10+deb12u14 0.00205 false
CVE-2024-2379 Anchore CVE Low libcurl4-7.88.1-10+deb12u14 0.00205 false
CVE-2023-5388 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00174 false
CVE-2023-5388 Anchore CVE Medium libnss3-2:3.87.1-1+deb12u1 0.00174 false
CVE-2025-1352 Twistlock CVE Low elfutils-0.188-2.1 0.00173 false
CVE-2025-1352 Anchore CVE Low libelf1-0.188-2.1 0.00173 false
CVE-2025-29070 Anchore CVE Low liblcms2-2-2.14-2 0.00168 false
CVE-2023-45931 Anchore CVE Low libglapi-mesa-22.3.6-1+deb12u1 0.00162 false
CVE-2023-45931 Anchore CVE Low libglx-mesa0-22.3.6-1+deb12u1 0.00162 false
CVE-2023-45931 Anchore CVE Low libgl1-mesa-dri-22.3.6-1+deb12u1 0.00162 false
CVE-2025-1632 Twistlock CVE Low libarchive-3.6.2-1+deb12u3 0.00156 false
CVE-2025-1632 Anchore CVE Low libarchive13-3.6.2-1+deb12u3 0.00156 false
CVE-2023-6135 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00152 false
CVE-2023-6135 Anchore CVE Medium libnss3-2:3.87.1-1+deb12u1 0.00152 false
CVE-2025-27516 Twistlock CVE High jinja2-3.1.5 This vulnerability impacts applications which execute untrusted templates. This is uncommon for web and other document rendering use cases, but may be common in deployment tools that allow third party plugins. 0.00138 false
CVE-2019-6461 Twistlock CVE Low cairo-1.16.0-7 0.00137 false
CVE-2019-6461 Anchore CVE Low libcairo2-1.16.0-7 0.00137 false
CVE-2020-15719 Twistlock CVE Low openldap-2.5.13+dfsg-5 0.00135 false
CVE-2020-15719 Anchore CVE Low libldap-2.5-0-2.5.13+dfsg-5 0.00135 false
CVE-2019-6462 Twistlock CVE Low cairo-1.16.0-7 0.00133 false
CVE-2019-6462 Anchore CVE Low libcairo2-1.16.0-7 0.00133 false
CVE-2024-6239 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00127 false
CVE-2024-6239 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00127 false
CVE-2024-6239 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00127 false
CVE-2023-45924 Anchore CVE Low libgl1-1.6.0-1 0.00123 false
CVE-2023-45924 Anchore CVE Low libglx0-1.6.0-1 0.00123 false
CVE-2023-45924 Anchore CVE Low libglvnd0-1.6.0-1 0.00123 false
CVE-2023-39329 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00122 false
CVE-2023-39329 Anchore CVE Medium libopenjp2-7-2.5.0-2+deb12u2 0.00122 false
CVE-2023-52355 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00119 false
CVE-2023-52355 Anchore CVE High libtiff6-4.5.0-6+deb12u3 0.00119 false
CVE-2022-24106 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00114 false
CVE-2022-24106 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00114 false
CVE-2022-24106 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00114 false
CVE-2017-14159 Twistlock CVE Low openldap-2.5.13+dfsg-5 0.00113 false
CVE-2017-14159 Anchore CVE Low libldap-2.5-0-2.5.13+dfsg-5 0.00113 false
CVE-2024-7883 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00108 false
CVE-2024-7883 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00108 false
CVE-2017-11697 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00106 false
CVE-2017-11697 Anchore CVE Low libnss3-2:3.87.1-1+deb12u1 0.00106 false
CVE-2024-47081 Twistlock CVE Medium requests-2.32.3 0.00104 false
CVE-2025-47287 Twistlock CVE High tornado-6.4.2 0.00103 false
CVE-2024-31852 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00103 false
CVE-2024-31852 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00103 false
CVE-2017-11698 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00088 false
CVE-2017-11698 Anchore CVE Low libnss3-2:3.87.1-1+deb12u1 0.00088 false
CVE-2017-11696 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00088 false
CVE-2017-11696 Anchore CVE Low libnss3-2:3.87.1-1+deb12u1 0.00088 false
CVE-2017-11695 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00088 false
CVE-2017-11695 Anchore CVE Low libnss3-2:3.87.1-1+deb12u1 0.00088 false
CVE-2024-26461 Twistlock CVE Low krb5-1.20.1-2+deb12u4 0.00081 false
CVE-2024-26461 Anchore CVE Low libgssapi-krb5-2-1.20.1-2+deb12u4 0.00081 false
CVE-2024-26461 Anchore CVE Low libkrb5support0-1.20.1-2+deb12u4 0.00081 false
CVE-2024-26461 Anchore CVE Low libk5crypto3-1.20.1-2+deb12u4 0.00081 false
CVE-2024-26461 Anchore CVE Low libkrb5-3-1.20.1-2+deb12u4 0.00081 false
CVE-2025-9086 Twistlock CVE Low curl-7.88.1-10+deb12u14 0.00077 false
CVE-2025-9086 Anchore CVE High libcurl4-7.88.1-10+deb12u14 0.00077 false
CVE-2025-59375 Twistlock CVE Low expat-2.5.0-1+deb12u2 0.00075 false
CVE-2025-59375 Anchore CVE High libexpat1-2.5.0-1+deb12u2 0.00075 false
CVE-2025-1377 Twistlock CVE Low elfutils-0.188-2.1 0.00074 false
CVE-2025-1377 Anchore CVE Low libelf1-0.188-2.1 0.00074 false
CVE-2022-28506 Twistlock CVE Low giflib-5.2.1-2.5 0.00070 false
CVE-2022-28506 Anchore CVE Low libgif7-5.2.1-2.5 0.00070 false
CVE-2013-4472 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00070 false
CVE-2013-4472 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00070 false
CVE-2013-4472 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00070 false
CVE-2023-45919 Anchore CVE Low libglx-mesa0-22.3.6-1+deb12u1 0.00067 false
CVE-2023-45919 Anchore CVE Low libglapi-mesa-22.3.6-1+deb12u1 0.00067 false
CVE-2023-45919 Anchore CVE Low libgl1-mesa-dri-22.3.6-1+deb12u1 0.00067 false
CVE-2023-45922 Anchore CVE Low libglapi-mesa-22.3.6-1+deb12u1 0.00060 false
CVE-2023-45922 Anchore CVE Low libgl1-mesa-dri-22.3.6-1+deb12u1 0.00060 false
CVE-2023-45922 Anchore CVE Low libglx-mesa0-22.3.6-1+deb12u1 0.00060 false
CVE-2025-52886 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00058 false
CVE-2025-52886 Anchore CVE Medium libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00058 false
CVE-2025-52886 Anchore CVE Medium libpoppler126-22.12.0-2+deb12u1 0.00058 false
CVE-2025-50420 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00056 false
CVE-2025-50420 Anchore CVE Medium libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00056 false
CVE-2025-50420 Anchore CVE Medium libpoppler126-22.12.0-2+deb12u1 0.00056 false
CVE-2025-1376 Twistlock CVE Low elfutils-0.188-2.1 0.00055 false
CVE-2025-1376 Anchore CVE Low libelf1-0.188-2.1 0.00055 false
CVE-2025-7709 Twistlock CVE Low sqlite3-3.40.1-2+deb12u2 0.00054 false
CVE-2025-7709 Anchore CVE Medium libsqlite3-0-3.40.1-2+deb12u2 0.00054 false
CVE-2023-25193 Twistlock CVE Low harfbuzz-6.0.0+dfsg-3 0.00051 false
CVE-2023-25193 Anchore CVE High libharfbuzz0b-6.0.0+dfsg-3 0.00051 false
CVE-2024-7531 Twistlock CVE Low nss-2:3.87.1-1+deb12u1 0.00050 false
CVE-2024-7531 Anchore CVE Medium libnss3-2:3.87.1-1+deb12u1 0.00050 false
CVE-2022-1210 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00050 false
CVE-2022-1210 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00050 false
CVE-2023-39327 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00048 false
CVE-2023-39327 Anchore CVE Medium libopenjp2-7-2.5.0-2+deb12u2 0.00048 false
CVE-2025-43859 Twistlock CVE Critical h11-0.14.0 0.00047 false
CVE-2025-53643 Twistlock CVE Low aiohttp-3.11.13 If the above conditions are met which is already unlikely, they are affected. 0.00045 false
CVE-2025-7458 Twistlock CVE Low sqlite3-3.40.1-2+deb12u2 0.00038 false
CVE-2025-7458 Anchore CVE Critical libsqlite3-0-3.40.1-2+deb12u2 0.00038 false
CVE-2023-35936 Anchore CVE Medium pandoc-2.4 0.00037 false
CVE-2025-10148 Twistlock CVE Low curl-7.88.1-10+deb12u14 0.00036 false
CVE-2025-10148 Anchore CVE Medium libcurl4-7.88.1-10+deb12u14 0.00036 false
CVE-2025-1372 Twistlock CVE Low elfutils-0.188-2.1 0.00035 false
CVE-2025-1372 Anchore CVE Low libelf1-0.188-2.1 0.00035 false
CVE-2025-8961 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00034 false
CVE-2025-8961 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00034 false
CVE-2025-1371 Twistlock CVE Low elfutils-0.188-2.1 0.00033 false
CVE-2025-1371 Anchore CVE Low libelf1-0.188-2.1 0.00033 false
CVE-2023-26924 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00033 false
CVE-2025-1365 Twistlock CVE Low elfutils-0.188-2.1 0.00031 false
CVE-2025-1365 Anchore CVE Low libelf1-0.188-2.1 0.00031 false
CVE-2023-29942 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00031 false
CVE-2023-29942 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00031 false
CVE-2023-29941 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00031 false
CVE-2023-29941 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00031 false
CVE-2023-29935 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00031 false
CVE-2023-29935 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00031 false
CVE-2025-8534 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00030 false
CVE-2025-8534 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00030 false
CVE-2023-37769 Twistlock CVE Low pixman-0.42.2-1 0.00029 false
CVE-2023-37769 Anchore CVE Low libpixman-1-0-0.42.2-1 0.00029 false
CVE-2023-48161 Twistlock CVE Low giflib-5.2.1-2.5 0.00028 false
CVE-2023-48161 Anchore CVE Low libgif7-5.2.1-2.5 0.00028 false
CVE-2024-13978 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00027 false
CVE-2024-13978 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00027 false
CVE-2023-29933 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00026 false
CVE-2023-29933 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00026 false
CVE-2023-29932 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00026 false
CVE-2023-29932 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00026 false
CVE-2025-9714 Twistlock CVE Low libxml2-2.9.14+dfsg-1.3~deb12u4 0.00025 false
CVE-2025-9714 Anchore CVE Medium libxml2-2.9.14+dfsg-1.3~deb12u4 0.00025 false
CVE-2025-5918 Twistlock CVE Low libarchive-3.6.2-1+deb12u3 0.00025 false
CVE-2025-5918 Anchore CVE Medium libarchive13-3.6.2-1+deb12u3 0.00025 false
CVE-2025-9165 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00024 false
CVE-2025-50181 Twistlock CVE Medium urllib3-2.3.0 Most users dont disable redirects on the PoolManager. Set redirectsFalseredirects0 on the .request call instead of on the toplevel urllib3.PoolManager 0.00023 false
CVE-2023-38745 Anchore CVE Medium pandoc-2.4 0.00023 false
CVE-2025-31344 Twistlock CVE Low giflib-5.2.1-2.5 0.00022 false
CVE-2025-31344 Anchore CVE High libgif7-5.2.1-2.5 0.00022 false
CVE-2025-8851 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00021 false
CVE-2025-8851 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00021 false
CVE-2025-29088 Twistlock CVE Low sqlite3-3.40.1-2+deb12u2 0.00020 false
CVE-2025-29088 Anchore CVE Low libsqlite3-0-3.40.1-2+deb12u2 0.00020 false
CVE-2023-29934 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00020 false
CVE-2023-29934 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00020 false
CVE-2025-50422 Twistlock CVE Low cairo-1.16.0-7 0.00019 false
CVE-2025-50422 Anchore CVE Low libcairo2-1.16.0-7 0.00019 false
CVE-2023-52426 Twistlock CVE Low expat-2.5.0-1+deb12u2 0.00019 false
CVE-2023-52426 Anchore CVE Low libexpat1-2.5.0-1+deb12u2 0.00019 false
CVE-2023-39742 Twistlock CVE Low giflib-5.2.1-2.5 0.00019 false
CVE-2023-39742 Anchore CVE Low libgif7-5.2.1-2.5 0.00019 false
CVE-2023-29939 Twistlock CVE Low llvm-toolchain-15-1:15.0.6-4 0.00019 false
CVE-2023-29939 Anchore CVE Low libllvm15-1:15.0.6-4+b1 0.00019 false
CVE-2025-25724 Twistlock CVE Low libarchive-3.6.2-1+deb12u3 0.00018 false
CVE-2025-25724 Anchore CVE Low libarchive13-3.6.2-1+deb12u3 0.00018 false
CVE-2025-8177 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00017 false
CVE-2025-8177 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00017 false
CVE-2025-8176 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00017 false
CVE-2025-8176 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00017 false
CVE-2025-52885 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00017 false
CVE-2025-52885 Anchore CVE Medium libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00017 false
CVE-2025-52885 Anchore CVE Medium libpoppler126-22.12.0-2+deb12u1 0.00017 false
CVE-2025-43718 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00017 false
CVE-2025-43718 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00017 false
CVE-2025-43718 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00017 false
CVE-2023-45913 Anchore CVE Low libgl1-mesa-dri-22.3.6-1+deb12u1 0.00017 false
CVE-2023-45913 Anchore CVE Low libglx-mesa0-22.3.6-1+deb12u1 0.00017 false
CVE-2023-45913 Anchore CVE Low libglapi-mesa-22.3.6-1+deb12u1 0.00017 false
CVE-2023-1916 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00017 false
CVE-2023-1916 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00017 false
CVE-2023-6228 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00016 false
CVE-2023-6228 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00016 false
CVE-2025-50182 Twistlock CVE Medium urllib3-2.3.0 Pyodide is extremely rare configuration for users in production. 0.00014 false
CVE-2024-25260 Twistlock CVE Low elfutils-0.188-2.1 0.00014 false
CVE-2024-25260 Anchore CVE Low libelf1-0.188-2.1 0.00014 false
CVE-2023-39328 Twistlock CVE Low openjpeg2-2.5.0-2+deb12u2 0.00013 false
CVE-2023-39328 Anchore CVE Medium libopenjp2-7-2.5.0-2+deb12u2 0.00013 false
CVE-2023-30571 Twistlock CVE Low libarchive-3.6.2-1+deb12u3 0.00013 false
CVE-2023-30571 Anchore CVE Low libarchive13-3.6.2-1+deb12u3 0.00013 false
CVE-2023-3164 Twistlock CVE Low tiff-4.5.0-6+deb12u3 0.00010 false
CVE-2023-3164 Anchore CVE Low libtiff6-4.5.0-6+deb12u3 0.00010 false
CVE-2025-43903 Twistlock CVE Low poppler-22.12.0-2+deb12u1 0.00009 false
CVE-2025-43903 Anchore CVE Low libpoppler126-22.12.0-2+deb12u1 0.00009 false
CVE-2025-43903 Anchore CVE Low libpoppler-cpp0v5-22.12.0-2+deb12u1 0.00009 false
CVE-2025-8732 Anchore CVE Low libxml2-2.9.14+dfsg-1.3~deb12u4 0.00008 false
CVE-2025-52099 Twistlock CVE Low sqlite3-3.40.1-2+deb12u2 N/A false
CVE-2025-52099 Anchore CVE Low libsqlite3-0-3.40.1-2+deb12u2 N/A false
PRISMA-2023-0024 Twistlock CVE High aiohttp-3.11.13 N/A N/A
GHSA-vqfr-h8mv-ghfj Anchore CVE Critical h11-0.14.0 N/A N/A
GHSA-pq67-6m6q-mj2v Anchore CVE Medium urllib3-2.3.0 N/A N/A
GHSA-g8c6-8fjj-2r4m Anchore CVE Medium python-socketio-5.12.1 N/A N/A
GHSA-cpwx-vrp4-4pq7 Anchore CVE Medium jinja2-3.1.5 N/A N/A
GHSA-9hjg-9r4m-mvj7 Anchore CVE Medium requests-2.32.3 N/A N/A
GHSA-9548-qrrj-x5pj Anchore CVE Low aiohttp-3.11.13 N/A N/A
GHSA-7cx3-6m66-7c5m Anchore CVE High tornado-6.4.2 N/A N/A
GHSA-48p4-8xcf-vxj5 Anchore CVE Medium urllib3-2.3.0 N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=afdco/misp-modules&tag=v3.0.2-2&branch=master

Tasks

Contributor:

  • Apply the StatusReview label to this issue for a merge request review and wait for feedback

OR

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue for a VAT justifications review and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Review or Verification label will be removed and the issue will be sent back to To-Do. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Review or Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information