CVE-2025-26042 Still Listed as Open on Docker Scout Despite Being Fixed
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- docker
- Domain
- security
Research direction
Start by comparing Docker Scout's displayed entry for CVE-2025-26042 with the current GitHub advisory GHSA-hx7h-9vf7-5xhg and its withdrawn duplicate. Trace the vulnerability data or update entry point used by Docker Scout; done when Scout shows the corrected fixed or patched status and version.
Written by the indexing model from the issue text.
Description
I would like to report an issue where CVE-2025-26042 is still marked as open/vulnerable on Docker Scout, even though this CVE has already been fixed.
Background
There were previously duplicate advisories for this vulnerability:
-
GitHub Advisory:
GHSA-hx7h-9vf7-5xhg (current and authoritative, shows the issue as fixed) -
Withdrawn GitHub Advisory:
GHSA-3rw8-4xrq-3f7p (withdrawn as a duplicate of the above) -
NIST & GitLab Advisories:
- Both still reference CVE-2025-26042, but do not reflect the current fixed status like GitHub does.
Request
Please update the status of CVE-2025-26042 on Docker Scout and display the correct fixed/patched version in accordance with the GitHub advisory (GHSA-hx7h-9vf7-5xhg).
If further details or context are needed, please let me know!
Thank you!
- Dominant language
- Shell
- Stars
- 455
- Forks
- 134
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker/scout-cli
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
allstar
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar existsOpen
Difficulty 4/5 3-5 days Newbie friendliness 64/100
All issues in docker/scout-cli
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
alunduil/alunduil-infrastructure#629 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
duckdb/duckdb-skills#19 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
YosysHQ/oss-cad-suite-build#216 ·