Skip to content

Trivy and Docker Scout are not able to detect CVE-2025-49844 Redis vulnerability score 10.0 #482

@bedla

Description

@bedla

Hi,
I found out that latest score 10 vulnerability is not detect by Trivy, see details here aquasecurity/trivy#9595 .
It seems that one of the solution might be to distribute SBOM CycloneDX JSON files in one of the layers.
It is because Redis binary cannot be scanned for dependencies etc.
Would you consider support this?
Thank you
Ivos

From Trivy source-code (and docs):

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions