CVE-2025-65965

Name
CVE-2025-65965
Description
Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is written using the --file or --output json=<file> option, the registry credentials will be included unsanitized in the output file. This issue has been patched in version 0.104.1. Users running affected versions of grype can work around this vulnerability by redirecting stdout to a file instead of using the --file or --output options.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/anchore/grype/commit/39f7fa17af2739cafe9b27176d4a68f7c05f21c1
MISC https://github.com/anchore/grype/pull/3068
CONFIRM https://github.com/anchore/grype/security/advisories/GHSA-6gxw-85q2-q646

Match rules

CPE URI Source package Min version Max version
grype >= 0.68.0 < 0.104.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
grype edge-community 0.104.1-r0 Michał Polański <michal@polanski.me> fixed
grype edge-community 0.103.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.100.0-r1 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.100.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.99.1-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.98.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.97.1-r1 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.97.1-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.97.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.96.1-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.96.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.95.0-r1 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.95.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.92.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.87.0-r4 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.87.0-r3 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.87.0-r2 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.87.0-r1 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.87.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.86.1-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.86.0-r1 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.86.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype edge-community 0.84.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype 3.22-community 0.98.0-r3 Michał Polański <michal@polanski.me> possibly vulnerable
grype 3.22-community 0.98.0-r2 Michał Polański <michal@polanski.me> possibly vulnerable
grype 3.22-community 0.98.0-r1 Michał Polański <michal@polanski.me> possibly vulnerable
grype 3.22-community 0.98.0-r0 Michał Polański <michal@polanski.me> possibly vulnerable
grype 3.22-community 0.87.0-r5 Michał Polański <michal@polanski.me> possibly vulnerable