Snyk - Open Source Security

Snyk test report

November 26th 2025, 2:45:33 pm (UTC+00:00)

Scanned the following paths:
  • public.ecr.aws/docker/library/redis:7.2.11-alpine/docker/library/redis (apk)
  • public.ecr.aws/docker/library/redis:7.2.11-alpine/tianon/gosu//usr/local/bin/gosu (gomodules)
2 known vulnerabilities
10 vulnerable dependency paths
19 dependencies

CVE-2024-58251

low severity


Detailed paths


NVD Description

Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine. See How to fix? for Alpine:3.21 relevant fixed versions and status.

In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.

Remediation

Upgrade Alpine:3.21 busybox to version 1.37.0-r14 or higher.

References


CVE-2025-46394

low severity


Detailed paths


NVD Description

Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine. See How to fix? for Alpine:3.21 relevant fixed versions and status.

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

Remediation

Upgrade Alpine:3.21 busybox to version 1.37.0-r14 or higher.

References