Anchore develops container vulnerability scanning and supply-chain security tooling deployed across software development and artifact-management pipelines; its product line centers on tools such as Syft and Quill for software composition analysis and container inspection. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in weakness classes related to resource management, information disclosure, exception handling, path traversal, and sensitive-data logging that reflect the parsing and filesystem-access demands of tools that must inspect and analyze untrusted container images and artifacts. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anchore over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24579CRITICAL stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stere | Jan 31, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-1766HIGH Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore E | Jul 20, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-11075CRITICAL In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer se | May 27, 2020 | 9.9 | 24 | NO | NO |
CVE-2023-24827HIGH syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure flaw was found in Syft versions | Feb 7, 2023 | 7.5 | 23 | NO | NO |
CVE-2018-1999033MEDIUM An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item | Aug 1, 2018 | 6.5 | 21 | NO | NO |
CVE-2026-33481MEDIUM Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly cleanu | Mar 26, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-31961MEDIUM Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vulnerability when parsing Mach-O b | Mar 11, 2026 | 5.5 | 20 | NO | NO |
CVE-2026-31960MEDIUM Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies during the Apple notarization p | Mar 11, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-31959MEDIUM Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Server-Side Request Forgery (SSRF) vulnerability when attempting | Mar 11, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anchore.
Media articles that mention a CVE ID that affects a product developed by Anchore — matched by CVE ID, not by vendor name.