Skip to content

CVE-2025-58050 Medium/Critical Vulnerability: pcre2 #1005

@mil7

Description

@mil7

Bug Overview

Hi there,
we currently stumble over prce2's already fixed vulnerability CVE-2025-58050, which is "only" MEDIUM for CVSS 4.0 but CRITICAL for CVSS 3.1. The latter is still enforced at some places.

The vulnerability is known in the latest Image of nginx-alpine.

Thanks for handling this vulnerability 💐

Expected Behavior

CVE-2025-58050 is fixed because prce2 up-to-date.

Steps to Reproduce the Bug

https://hub.docker.com/layers/library/nginx/1.29.2-alpine/images/sha256-c17e49b2e5cf2a4523284e2b446f3829088a233b27f12333ab13546bc177d8c7

Environment Details

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions