<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE on</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/tags/cve/</link><description>Recent content in CVE on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 01 Oct 2026 14:31:17 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/tags/cve/index.xml" rel="self" type="application/rss+xml"/><item><title>How Chainguard issues Security Advisories</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/security-advisories/how-chainguard-issues/</link><pubDate>Fri, 26 Jul 2024 18:09:12 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/security-advisories/how-chainguard-issues/</guid><description>&lt;p&gt;When you scan a newly-built Chainguard Container with a vulnerability scanner, typically, no CVEs will be reported. However, as software packages age, more vulnerabilities are reported and CVEs will begin to accumulate in container images. When this happens, Chainguard releases security advisories to communicate these vulnerabilities to downstream images users.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Advisory timestamps represent when updates are made to the advisory page, not when they were first detected and triaged by Chainguard.&lt;/p&gt;</description></item><item><title>Strategies for minimizing your CVE risk</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/</link><pubDate>Thu, 16 Nov 2023 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/</guid><description>&lt;p&gt;&lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve#what-is-a-cve"&gt;Common vulnerabilities and exposures&lt;/a&gt; (CVEs) are an increasing concern for developers and organizations, which is why Chainguard developed its minimal container images that reduce the attack surface. A new CVE in a widely-used application or a vulnerability scan with numerous positive results can significantly impact security posture, compliance requirements, and development timelines.&lt;/p&gt;
&lt;p&gt;Chances are, your software has already been impacted by a CVE. It&amp;rsquo;s likely there are active CVEs in software you are using. After all, there are software vulnerabilities currently in existence that haven&amp;rsquo;t even been discovered (known as zero-day vulnerabilities). With that said, this conceptual article aims to highlight a few practices and strategies you and your team can use to reduce the risk of CVEs on your software. It also includes a section on &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-risk/#recommended-tools"&gt;tools recommended by Chainguard&lt;/a&gt; that can help to reduce your attack surface area and minimize your risk of CVEs.&lt;/p&gt;</description></item><item><title>False positives and false negatives with container image scanners</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/false-results/</link><pubDate>Thu, 14 Sep 2023 16:59:04 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/false-results/</guid><description>&lt;p&gt;A &lt;em&gt;vulnerability scanner&lt;/em&gt; is a tool that analyzes your software components and reports any &lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve"&gt;CVEs&lt;/a&gt; it finds. Using a vulnerability scanner to find CVEs that impact your system is a critical step in &lt;a href="https://www.chainguard.dev/supply-chain-security-101/cve-remediation-explained"&gt;software vulnerability remediation&lt;/a&gt;, but as you begin to triage scanner-reported vulnerabilities, you may find that your scanner&amp;rsquo;s results are not perfectly accurate.&lt;/p&gt;
&lt;p&gt;The goal of a vulnerability scanner is to identify the vulnerabilities that impact your container images, which can be considered &lt;em&gt;true positive vulnerabilities&lt;/em&gt;. Sometimes, a scanner surfaces CVEs which are not actually impacting your images, which are called &lt;em&gt;false positive vulnerabilities&lt;/em&gt;. Your scanner may even miss some vulnerabilities that are impacting you, termed &lt;em&gt;false negative vulnerabilities&lt;/em&gt;.&lt;/p&gt;</description></item><item><title>Check whether a reported CVE affects your container</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-status/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-status/</guid><description>&lt;p&gt;Use &lt;code&gt;chainctl images advisories list&lt;/code&gt; to compare the advisories for the APK packages in an image with the CVEs reported by your scanner.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This command looks up advisories by APK package. Chainguard records a vulnerability in a Go module, Java archive, or other language component against the APK package that ships it, so the results cover those components too. They don&amp;rsquo;t cover dependencies that your own build adds to the image. For details, see &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/cve-status/#when-the-finding-is-a-go-module-or-java-dependency"&gt;When the finding is a Go module or Java dependency&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Using Grype to scan software artifacts</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/grype-tutorial/</link><pubDate>Thu, 06 Jun 2024 20:00:00 +0200</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/grype-tutorial/</guid><description>&lt;p&gt;&lt;a href="https://github.com/anchore/grype"&gt;Grype&lt;/a&gt; is a vulnerability scanner for container images and filesystems developed and maintained by &lt;a href="https://anchore.com/"&gt;Anchore&lt;/a&gt; and written in the Go programming language. Grype can scan from Docker, OCI, Singularity, podman, image archives, and local directory. Grype is compatible with SBOMs generated by &lt;a href="https://github.com/anchore/syft"&gt;Syft&lt;/a&gt;, and Grype&amp;rsquo;s &lt;a href="https://github.com/anchore/grype-db"&gt;vulnerability database&lt;/a&gt; draws from a wide variety of sources.&lt;/p&gt;
&lt;p&gt;Grype is appropriate for one-off detection for manual CVE mitigation and in automated use in CI pipelines. Chainguard maintains a &lt;a href="https://images.chainguard.dev/directory/image/grype/overview?utm_source=cg-academy&amp;amp;utm_medium=referral&amp;amp;utm_campaign=dev-enablement&amp;amp;utm_content=edu-content-chainguard-chainguard-images-working-with-images-scanners-grype-tutorial"&gt;low-to-no CVE Chainguard Image for Grype&lt;/a&gt; based on our lightweight Wolfi distribution.&lt;/p&gt;</description></item><item><title>How to use Chainguard Security Advisories</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/security-advisories/how-to-use/</link><pubDate>Wed, 27 Dec 2023 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/security-advisories/how-to-use/</guid><description>&lt;p&gt;When using scanners such as &lt;a href="https://github.com/anchore/grype"&gt;Grype&lt;/a&gt; or &lt;a href="https://docs.docker.com/scout/"&gt;Docker Scout&lt;/a&gt; to scan for vulnerabilities in Chainguard Containers, you&amp;rsquo;ll often find that there are few or no CVEs present. However, CVEs can sometimes be found in Chainguard Containers, and you may also encounter CVEs if you&amp;rsquo;re using older tags. In these cases, you will likely wish to check Chainguard&amp;rsquo;s security advisories for information on which CVEs will cause security issues in your deployment.&lt;/p&gt;
&lt;p&gt;To help demystify the nature of CVEs within Chainguard Containers, we&amp;rsquo;ve created a self-service &lt;a href="https://images.chainguard.dev/security?utm_source=cg-academy&amp;amp;utm_medium=referral&amp;amp;utm_campaign=dev-enablement&amp;amp;utm_content=edu-content-chainguard-chainguard-images-working-with-images-security-advisories-how-to-use"&gt;Security Advisories page&lt;/a&gt; that lists every security advisory published for Chainguard Containers. Having this information available allows you to view whether Chainguard is aware of a specific vulnerability reported to exist within a Chainguard Container and whether we&amp;rsquo;ve mitigated or are planning to mitigate the CVE.&lt;/p&gt;</description></item><item><title>Resolve a scanner finding for a CVE Chainguard has fixed</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/scanner-flags-fixed-cve/</link><pubDate>Thu, 01 Oct 2026 14:31:17 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/vulnerability-management/scanner-flags-fixed-cve/</guid><description>&lt;p&gt;Sometimes the Chainguard Console or a Chainguard security advisory reports a CVE as fixed, but your vulnerability scanner still reports it in the same image. When this blocks a CI security gate, the cause is usually a mismatch between the image you scanned, the data your scanner uses, and Chainguard&amp;rsquo;s advisory data. Work through the checks on this page in order; they&amp;rsquo;re arranged so that the most common causes come first.&lt;/p&gt;</description></item><item><title>CVE remediation for Chainguard Libraries</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/libraries/policies-and-security/cve-remediation/</link><pubDate>Thu, 11 Sep 2025 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/libraries/policies-and-security/cve-remediation/</guid><description>&lt;p&gt;CVE remediation for Chainguard Libraries provides protection against
critical and high CVEs. Applications often rely on older versions of libraries,
but upstream maintainers may not apply and release patches for those versions.
Chainguard addresses this gap by backporting vulnerability fixes
from newer releases to older releases, particularly in cases where maintainers
are no longer able to support and provide fixes.&lt;/p&gt;
&lt;p&gt;CVE remediation helps reduce risk for organizations that cannot always upgrade
quickly, especially when moving to a newer version would introduce disruptive
changes. Remediated artifacts are published as incremental patch versions, allowing teams to take a targeted fix for a CVE without taking on a broader upgrade at the same time.&lt;/p&gt;</description></item><item><title>How end-of-life software accumulates vulnerabilities</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/concepts/lifecycle-and-eol/how-eol-software-accumulates-cves/</link><pubDate>Wed, 04 Dec 2024 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/concepts/lifecycle-and-eol/how-eol-software-accumulates-cves/</guid><description>&lt;p&gt;Typically, specific versions of software receive updates on a schedule for a set amount of time. Eventually, though, every version of software will stop receiving support. When project maintainers stop providing updates, it&amp;rsquo;s known as the &lt;em&gt;End-of-Life&lt;/em&gt; (EOL) stage.&lt;/p&gt;
&lt;p&gt;Because it&amp;rsquo;s no longer being actively maintained, software begins to collect vulnerabilities when it reaches EOL. This problem can become compounded when using container images, as they often come with extra components from underlying base images which are all prone to accruing vulnerabilities. This can lead to images with hundreds of components, each collecting vulnerabilities and forming part of the attack surface.&lt;/p&gt;</description></item><item><title>Using wolfictl to manage Security Advisories</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/security-advisories/managing-advisories/</link><pubDate>Mon, 05 Aug 2024 20:23:51 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/security-advisories/managing-advisories/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: This document is deprecated as of June 2025.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Chainguard operates its own &lt;a href="https://images.chainguard.dev/security/?utm_source=cg-academy&amp;amp;utm_medium=referral&amp;amp;utm_campaign=dev-enablement&amp;amp;utm_content=edu-content-chainguard-chainguard-images-working-with-images-security-advisories-managing-advisories"&gt;Security Advisories&lt;/a&gt; page to alert users about the status of vulnerabilities found in Chainguard Containers. To maintain this database, we use &lt;a href="https://github.com/wolfi-dev/wolfictl/"&gt;&lt;code&gt;wolfictl&lt;/code&gt;&lt;/a&gt;, a tool developed for working with the &lt;a href="https://github.com/wolfi-dev/"&gt;Wolfi un-distro&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In this guide, you will walk through using &lt;code&gt;wolfictl&lt;/code&gt; to create an advisory for a vulnerable package. You’ll also learn how to update this advisory as more information about the vulnerability is disclosed over time. To follow along, you will need to have &lt;a href="https://git-scm.com/"&gt;&lt;code&gt;git&lt;/code&gt;&lt;/a&gt; and the &lt;a href="https://go.dev/dl/"&gt;Go programming language&lt;/a&gt; installed on your machine.&lt;/p&gt;</description></item><item><title>Using Trivy to scan software artifacts</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/</link><pubDate>Wed, 03 Jul 2024 20:00:00 +0200</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/</guid><description>&lt;p&gt;&lt;a href="https://github.com/aquasecurity/trivy"&gt;Trivy&lt;/a&gt; is a vulnerability scanner for a wide variety of software artifacts and deployments. Trivy is written in the Go programming language and is maintained by &lt;a href="https://www.aquasec.com/"&gt;Aqua Security&lt;/a&gt;. Trivy targets container images, VMs, filesystems, remote GitHub repositories, and Kubernetes and Amazon Web Services deployments. The tool can be used to detect known vulnerabilities (CVEs), generate SBOMs, analyze licenses, and scan for misconfigurations and exposed secrets. Trivy can be installed from &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/#package-managers"&gt;package managers&lt;/a&gt; or as a &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/#binary-installation"&gt;binary&lt;/a&gt;, and can also be run as a &lt;a href="https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/trivy-tutorial/#container-image"&gt;container image&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Infamous software vulnerabilities</title><link>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/software-security/cves/infamous-cves/</link><pubDate>Fri, 21 Jul 2023 19:16:39 +0000</pubDate><guid>https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/software-security/cves/infamous-cves/</guid><description>&lt;p&gt;&lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve"&gt;Software vulnerabilities&lt;/a&gt; vary in their severity – some are difficult to exploit and have minimal implications, while others can be exploited easily, giving an attacker significant leverage over a computer system. In cases where widely-implemented software contains high-severity vulnerabilities, the damage caused by their exploitation can affect millions of developers and services worldwide.&lt;/p&gt;
&lt;p&gt;In this article, you will learn how the KEV Catalog tracks known exploited software vulnerabilities, and how it serves as a tool for developers and federal agencies. In addition, you will explore Log4Shell, Heartbleed, and Shellshock, three infamous software vulnerabilities which have had major impacts on software security worldwide.&lt;/p&gt;</description></item></channel></rss>