Skip to content

Security Vulnerability CVE-2025-49794 and CVE-2025-49796 (libxml2) #1004

@tobka777

Description

@tobka777

Bug Overview

Hello,

CVE-2025-49794 and CVE-2025-49796 is detected in the most recent scan like nginx:1.28.0-alpine.

https://hub.docker.com/layers/library/nginx/1.28.0-alpine/images/sha256-ebd7cd95af06f54013757a30a148fb4d63b80d28503c291455b60027b764271c

This vulnerability appears to originate from Alpine Image. We would appreciate it if you could provide a fix for this security vulnerability.

As a temporary measure, we have updated libxml2 to 2.13.9-r0 in our project.

Expected Behavior

No critical CVE

Steps to Reproduce the Bug

nginx:1.28.0-alpine has two critical CVEs: CVE-2025-49794 and CVE-2025-49796

Environment Details

  • Version: nginx:1.28.0-alpine

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions