Skip to content

A critical vulnerabilities is displayed on the Audit Vulnerabilities tab, but is not included in the Overview tab. #1539

@d-afanasiev

Description

@d-afanasiev

Current Behavior

A critical vulnerabilities is displayed in the Audit Vulnerabilities tab, but is not included in the Overview tab.
In this case, this concerns three vulnerabilities:
CVE-2026-42581
CVE-2026-42584
CVE-2026-42579

https://nvd.nist.gov/vuln/detail/CVE-2026-42581
https://nvd.nist.gov/vuln/detail/CVE-2026-42584
https://nvd.nist.gov/vuln/detail/CVE-2026-42579

Image Image

Package URL (PURL): pkg:maven/io.netty/netty-codec-http@4.1.130.Final

This issue is inconvenient because you cannot rely on the Overview tab or Projects, as it is unclear whether there are critical vulnerabilities in this project.

Steps to Reproduce

  1. Create a custom project.
  2. Upload the pkg:maven/io.netty/netty-codec-http@4.1.130.Final package to the project.
  3. I use trivy analyzer for my projects.

Expected Behavior

On the Overview tab, vulnerability summaries are correctly performed to ensure correct response to critical vulnerabilities.

Image Image

Dependency-Track Frontend Version

4.7.x

Browser

Google Chrome

Browser Version

No response

Operating System

Windows

Checklist

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions