VYPR

Go modules package

github.com/docker/compose/v2

pkg:golang/github.com/docker/compose/v2

Vulnerabilities (1)

  • CVE-2025-62725HigOct 27, 2025
    affected >= 2.34.0, < 2.40.2fixed 2.40.2

    Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile w