Skip to main content

Vendor/product archive

anchore / syft CVEs

Beta · best-effort

2 CVEs tagged to anchore / syft0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-33481

Published Mar 26, 2026

Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly clean…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2023-24827

Published Feb 7, 2023

syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure flaw was found in Syft versions…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1