Credential Disclosure Vulnerability in Grype by Anchore
CVE-2025-65965
8.2HIGH
What is CVE-2025-65965?
A credential disclosure vulnerability was identified in Grype, a vulnerability scanner for container images and filesystems. Affected versions from 0.68.0 to 0.104.0 may inadvertently include unsanitized registry credentials in output files when using the --file or --output options. This exposure can lead to unintended credential leakage, compromising security. Users are encouraged to upgrade to version 0.104.1 to mitigate the risk, or alternatively, redirect standard output to a file to safely capture scan results without exposing sensitive information.
Affected Version(s)
grype >= 0.68.0, < 0.104.1
