> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/ce-release-notes/prisma-tm-cloud-compute-edition-release-information/known-issues-34.md).

# Fixed and Known Issues in 34.xx

The following table lists the fixed issues for 34.xx releases.

## Fixed Issues

| **ISSUE ID**                                                                                                                                                   | **DESCRIPTION**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>OS Bundle Package No Longer Overwrites App Version</strong></p><p><mark style="background-color:orange;">34.04.160</mark></p>                       | Fixed the scanner to prevent OS bundle packages from overwriting the application version during `correlateOSPackages`. This resolves incorrect vulnerability matches that occurred when OS package metadata incorrectly replaced application version information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>SQLite Read-Only Filesystem No Longer Causes Extraction Failure</strong></p><p><mark style="background-color:orange;">34.04.160</mark></p>          | Fixed an issue where a read-only SQLite filesystem caused OS package extraction to fail during image scanning. The scanner now handles read-only filesystem conditions correctly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Disabled AWS Regions me-south-1 and me-central-1 to Prevent STS Timeouts</strong></p><p><mark style="background-color:orange;">34.04.160</mark></p> | Disabled the `me-south-1` and `me-central-1` AWS regions to prevent STS authentication timeouts that affected serverless scanning operations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Image Scanner Cleans Up Extracted JAR Files</strong></p><p><mark style="background-color:orange;">34.04.160</mark></p>                              | Fixed the image scanner to delete extracted JAR files immediately after inspection and clean up stale JAR directories on startup. This prevents disk space exhaustion caused by accumulated temporary files.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Defender Connectivity Issue Resolved</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                     | <p>Resolved a regression in Quinn update 34.04.145 that makes the Defender set iptables/nftables entries in your environment, even when there is no policy such as Cloud Native Network Security (CNNS) or DNS monitoring requesting it.</p><p>This bug affects all 34.04 Defenders. If the Defender is deployed on Tanzu Application Service (TAS), this may lead to severe connectivity issues.</p><p>The referenced hotfix addresses this issue and ensures that iptables/nftables rules are set only when it is explicitly reflected in the policy.</p>                                                                                                                                                                                               |
| <p><strong>Resolved Issues</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                          | <p>Additional Fixes & Improvements:</p><ul><li>Improved Startup Reliability: This fix addresses an issue where the Defender may appear not to initialize properly in CRI environments, with logs indicating:</li></ul><p><code>Failed to initialize CRI client: runtime version cannot be determined.</code></p><ul><li>Expanded Compliance Support: Added support for nftables in Compliance checks.</li><li>Health Reporting Accuracy: Fixed a bug where the Defender incorrectly reported an "unhealthy" status when operating normally.</li></ul>                                                                                                                                                                                                     |
| <p><strong>CWP-64752</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Fixed false-positive vulnerability matches for third-party packages</strong></p><p>Fixed scanner to stop incorrectly deriving correlated OS package versions for all third-party package types, preventing false-positive vulnerability matches.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-64741</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Fixed AVA scan result corruption</strong></p><p>Fixed an issue where trailing output after an AVA (sub) process scan could corrupt scan results.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-64729</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>CNNF rules applied only when enabled</strong></p><p>Fixed Cloud Native Network Firewall to only apply rules when the feature is explicitly enabled, preventing unintended network enforcement.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>CWP-64712</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Fixed container Defender status command</strong></p><p>Fixed the container Defender status command output.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-64122</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Improved gzip file detection</strong></p><p>Fixed tarball/gzip detection to use magic bytes rather than relying solely on file extension, resolving scan failures for misnamed archives.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-64647</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Fixed Windows vulnerability assessments</strong></p><p>Fixed incorrect FixedBuild mapping across Windows product IDs in the intelligence builder, resolving inaccurate Windows vulnerability assessments.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>CWP-64675</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Execute yum as root for RPM database access</strong></p><p>Fixed image augmentation to execute yum commands as root when accessing RPM databases via SQLite, resolving scan failures on certain container images.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>CWP-64702</strong></p><p><mark style="background-color:orange;">34.04.156</mark></p>                                                                | <p><strong>Fixed crash in compressed layer verification</strong></p><p>Fixed a potential crash caused by an array index out of bounds when verifying compressed layer timestamps during image scanning.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>CWP-64581</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Resolved rare kernel panic in runtime monitoring</strong></p><p>Fixed a race condition in fsmon that could lead to a kernel panic.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CWP-64543</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed WAAS rule forcing defender memory to 4GB</strong></p><p>WAAS rule no longer forces defender max memory to 4GB when enabled on a cluster.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>CWP-64542</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed defender memory settings preservation</strong></p><p>Defender memory settings are now preserved correctly and no longer decrease unexpectedly.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CWP-64538</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed SSH host activity detection on Debian 13</strong></p><p>SSH host activity is now properly detected on Debian 13 systems.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>CWP-64513</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Improved version detection accuracy for vulnerability assessment</strong></p><p>Defender and twistcli now correctly use OS package version when an app is correlated but its version is missing.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-64494</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Reduced false positive CVEs from RPM Epoch detection</strong></p><p>Fixed possible false positive CVE-2023-47038 due to RPM Epoch detection issues.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-64486</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed container data display in image tab for agentless scans</strong></p><p>Container data now displays correctly in the image tab when using agentless scanning.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CWP-64467</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Resolved yum hang during agentless scanning</strong></p><p>Fixed an issue where the yum command would get stuck during agentless scanning.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-64464</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed OCI agentless connectivity in Ashburn region</strong></p><p>Resolved agentless connectivity issues for OCI in the Ashburn region.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>CWP-64458</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Improved busybox version detection in agentless scans</strong></p><p>Agentless scanning now correctly detects the full busybox version on hosts.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-64454</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Multiple defender stability improvements</strong></p><p>Backlog bug fixes for defender stability in Quinn Update 4.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-64425</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed app-embedded defender exit on DNS resolution failures</strong></p><p>App-embedded defender no longer exits when handleGetAddrInfoEvent fails.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-64402</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed 502 bad gateway error in Runtime Security Module</strong></p><p>Resolved a Runtime Security connectivity issue.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>CWP-64398</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed image cleanup skipping images with empty hosts</strong></p><p>Image cleanup logic no longer skips images when the hosts field is empty.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>CWP-64382</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed RHEL 10 defender false iptables error logging</strong></p><p>Host defender using nftables on RHEL 10 no longer logs errors about missing iptables.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-64380</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed Cloud Run functions appearing in Radar when feature flag is off</strong></p><p>Functions created with gcloud run are no longer listed in Radar view when the feature flag is disabled.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>CWP-64367</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed ServiceNow alert integration reliability</strong></p><p>Resolved issues with alerts failing to send to ServiceNow.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-64359</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed CNNS container summary count mismatch</strong></p><p>CNNS for containers now correctly sums up to match its detail counts.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-64358</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed incident audit CSV serial number column</strong></p><p>The twistlock\_incidents\_audit CSV file serial number column now increments correctly instead of showing constant #0.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-64319</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed registry scan handling of long image tags</strong></p><p>Registry scan image cleanup no longer fails when tag exceeds 128-character limit.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-64237</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed consistent WAAS protection for Istio traffic</strong></p><p>Istio traffic is now consistently protected by defender when using WAAS.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-64233</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed registry scanner error message formatting</strong></p><p>Registry scanner log now shows proper image pull error messages instead of %!s(MISSING).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>CWP-64167</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Resolved log flooding from missing container images</strong></p><p>Fixed "Failed to find image for container" messages flooding the log.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-64117</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed ECS EXTERNAL launch type handling</strong></p><p>Cloud Discovery now correctly handles ECS EXTERNAL launch type.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>CWP-64116</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed auto-defend rules custom role filtering</strong></p><p>Host and serverless auto-defend rules are now properly filtered by custom role.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>CWP-64068</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed agentless scan status persistence after refresh</strong></p><p>Agentless last scan field no longer disappears on page refresh.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CWP-64402</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Fixed 502 bad gateway error in Runtime Security Module</strong></p><p>Resolved a Runtime Security connectivity issue.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>CWP-64398</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Image cleanup logic skips images when hosts field is empty</strong></p><p>Fixed an issue where images that have been deleted from their namespaces are still being shown in the console.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-64117</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Cloud Discovery limitation resolved</strong></p><p>ECS task definition containers with <code>launchType: External</code> that are listed in the Inventory are not present in the Prisma Cloud Console ( Runtime Security > Radar). This issue is now fixed.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>CWP-63717</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Filepaths of secrets found by scanners other than agentless contain prefix of scan directory</strong></p><p>Resolved an issue with the Vulnerability scan report for registry images showing vulnerabilities that are tagged to an image path which does not actually exist on the image.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>CWP-64258</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Cloud Radar resource reporting</strong></p><p>Fixed an issue with the inaccurate reporting for Defended resources.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CWP-64116</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Console - host and serverless auto-defend rules are not filtered by custom role</strong></p><p>Resolved an issue with a custom role user not being able to access certain specifications when working with Defender Auto-Deploy rules.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>CWP-64265</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Macro fields not populated</strong></p><p>Fixed an issue with some macro fields not being populated, when a Compliance trigger is set up to forward alerts via Webhook to Service Now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>CWP-64459</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>NF table support</strong></p><p>Following the addition of NF tables support in WAAS, NF tables support is also now available for Defender (CNNF and Runtime Policy).</p><p><strong>Note:</strong> Open issues relating to the Compliance scan flow, will be addressed in a subsequent release.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>CWP-64543</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Defender Memory Settings</strong></p><p>This fix prevents memory decrease if it is already set.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>CWP-63255</strong></p><p><mark style="background-color:orange;">34.04.145</mark></p>                                                                | <p><strong>Unused Defender packages</strong></p><p>Removed multiple unused packages to reduce exposure to CVEs.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CWP-64867</strong></p><p><mark style="background-color:orange;">34.03.138</mark></p>                                                                | <p><strong>RPM database patch</strong></p><p>Added a sqlite3 patch for RPM database (rpmdb) to address package metadata extraction issues in RPM-based images.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>PCSUP-29054</strong></p><p><mark style="background-color:orange;">34.03.138</mark></p>                                                              | <p><strong>Standardized Non-Privileged User ID for Defender CLI</strong></p><p>To enhance security across all supported operating systems, the Defender component will now use the standardized, <strong>non-privileged</strong> User ID (1100) when executing Command Line Interface (CLI) commands.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-63569</strong></p><p><mark style="background-color:orange;">34.03.138</mark></p>                                                                | <p><strong>Account-level reporting of scan date and time</strong></p><p>The scan start and end date and time were earlier reported at the region level and weren’t precise in some situations. This fix ensures accurate reporting of scan start and end date and time at the individual account level.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>CWP-63632</strong></p><p><mark style="background-color:orange;">34.03.138</mark></p>                                                                | <p><strong>Release name for Windows Server 2025 doesn’t resolve correctly</strong></p><p>This issue is fixed now. The release name for Windows Server 2025 displays correctly.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-64185</strong></p><p><mark style="background-color:orange;">34.03.138</mark></p>                                                                | <p><strong>Improved defender stability with Read-only 'runc' paths</strong></p><p>Previously, in crio environments, if the paths to <code>runc</code> were located in read-only directories, the defender would delegate the calls to the first runtime it found, increasing the risk of node instability.</p><p>This issue has now been resolved, and defender will use the default runtime. To properly deploy the newer version containing this fix, follow these steps:</p><ol><li>Remove the existing defender daemonset.</li><li>Ensure that no ZZ-twistlock.conf file is present in /etc/crio/crio.conf.d. If it exists, delete it.</li><li>Restart the affected node.</li><li>Deploy the new defender.</li></ol>                                  |
| <p><strong>CWP-64196</strong></p><p><mark style="background-color:orange;">34.03.138</mark></p>                                                                | <p><strong>App-embedded Defender crashes on thread termination</strong></p><p>The App-embedded defender crashes if the application it is protecting, or a thread of the application, terminates while it is connecting to the app-embedded defender.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>CWP-61530</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>False positives for Oracle images and hosts</strong></p><p>The issue with CVE matching for Oracle images and hosts, which caused false positives due to missing Oracle module information, is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-63043</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>False positives for OpenShift images</strong></p><p>False positives were reported for OpenShift images due to incorrect parsing of the release label.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CWP-63194</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>False positives due to incorrect Red Hat version comparison</strong></p><p>Added support for the epoch prefix in Red Hat images. Previously, the epoch was omitted during image scanning, causing version comparisons to ignore it and resulting in false positives. This fix ensures the epoch value is included, allowing accurate version comparisons and preventing incorrect vulnerability matches.</p>                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-63341</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>Defender periodic scans are not disabled when the scan interval is set to 0</strong></p><p>Even when the scan interval for images, containers and hosts is set to 0 on the Manage > System > Scan page in the UI, the defender continues to execute periodic scans every 24 hours.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>CWP-63479</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>Incorrect value in the CaaS containers column</strong></p><p>The value in the CaaS containers column in the Registry images table on the Monitor > Vulnerabilities > Image > Registries page was not updated if the Fargate task was no longer available in Prisma Cloud.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-63695</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>Serverless scanning of Python packages in the requirements.txt file</strong></p><p>Previously, dependencies in the requirements.txt file were not considered during vulnerability and compliance scans of Azure serverless functions and GCP Cloud Run functions for Python. Now, packages specified in requirements.txt are also included in the scan.</p><p>Note that for packages in the file to be taken into consideration, specific package versions need to be specified using "==". For example: docopt == 0.6.1</p>                                                                                                                                                                                                                   |
| <p><strong>CWP-63711</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>URLs for RHEL repos</strong></p><p>The issue with CVE matching that caused false positives when relative URLs for Red Hat repositories are used is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>CWP-63808</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>Gateway timeout while loading feeds</strong></p><p>Feed changed notifications to Defenders are now batched and spread to prevent 504 Gateway Timeout errors from concurrent downloads. Defenders also use Exponential Backoff with Jitter for retries.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>CWP-63880</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>Base image history tagging</strong></p><p>Scanning over 50 digests under one rule caused older base image digests to be deleted, removing base image links. The Base Image tag incorrectly remained under the Layers tab for these images. This has been fixed: the Base Image tag is now correctly removed from the Layers tab for images whose original base images were overridden.</p>                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>CWP-63887</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>False positives for Amazon ALAS CVE advisories</strong></p><p>False positives were generated because of the change in the URL for the Amazon ALAS CVE advisory file. The underlying cause for these false positives is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>CWP-63924</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>Node crashes on OpenShift 4.18 clusters</strong></p><p>Node crashes may happen on OpenShift 4.18 clusters in case the defender is configured with a block policy.</p><p>This happens because OpenShift 4.18 has changed the default runtime implementation from <code>runc</code> to <code>crun</code>, and the defender didn’t handle that change correctly.</p><p>The issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>CWP-63935</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p>                                                                | <p><strong>JWT tokens with Japanese characters fail to authenticate</strong></p><p>Prisma Cloud roles with names that included Japanese characters caused an error.</p><p>This issue has been fixed.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>CWP-63359</strong></p><p><mark style="background-color:orange;">34.01.126</mark></p>                                                                | <p><strong>#IngressNightmare vulnerabilities</strong></p><p>This issue is fixed now.</p><p>An enhanced mechanism for identification of packages helps in improved detection of vulnerabilities, such as the #ingressnightmare vulnerability issue.</p><p>This enhancement allows for earlier detection and remediation, proactively mitigating potential exploits.</p>                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>CWP-63421</strong></p><p><mark style="background-color:orange;">34.01.126</mark></p>                                                                | <p><strong>The "defended" status for ECS task definitions inocorrectly set to <code>false</code></strong></p><p>ECS task definition entities discovered as part of cloud discovery have a "defended" status. This "defended" status field is set to true if a Fargate defender is detected as installed in one of the containers in the task definition. This "defended" status field was incorrectly set to <code>false</code> even when a Fargate defender was installed in one of the containers.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                   |
| <p><strong>CWP-62961</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Namespace associations for an image are not refreshed</strong></p><p>When an image that is associated with multiple Kubernetes namespaces is removed from one of the namespaces, the namespace associations for the image are not refreshed and the image continues to list the namespace from which it was removed.</p><p>This issue is fixed for on-premise deployments now.</p><p>To enable this fix, you need to:</p><ol><li>Edit the twistlock.cfg file and set the CLEAN\_STALE\_NAMESPACES flag to true.</li><li>Restart the console.</li></ol><p>By default, the flag CLEAN\_STALE\_NAMESPACES is set to false. When you enable this flag and restart the console, namespaces associated with images are refreshed every 12 hours.</p> |
| <p><strong>CWP-59903</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Cleanup of system resources after registry scanning</strong></p><p>A new scanner tag is generated when an image is pulled for scanning. In certain cases, this tag was not properly removed after the scan completed.</p><p>This issue is fixed now. Improvements to the registry scan mechanism ensure a proper cleanup of system resources after scanning.</p>                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>CWP-60416</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Incorrect parsing of Ruby advisories that use RC versions</strong></p><p>Incorrect parsing of Ruby advisories that use RC versions (such as '3.0.0-rc.1') caused false positive CVE reporting.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>CWP-61862</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>An incorrect fix date is reported for CVEs that did not provide a fix date initially</strong></p><p>An incorrect fix date is reported for CVEs that did not provide a fix date initially and were then reopened and fixed (again) with a fix date that is later than the date when the issue was first reported as fixed. Prisma Cloud reported the date when the issue was first reported as fixed and did not update the fix date after the issue was reopened and fixed with a different date.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                           |
| <p><strong>CWP-62128</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Changes in the Ubuntu feed caused false positives in some situations</strong></p><p>Changes in the Ubuntu feed format added an asterisk in the condition for some CVE entries. This was not parsed correctly and led to false positives.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>CWP-62193</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Incorrect fixed version reported for some CVEs reported in NVD</strong></p><p>An issue with the parsing of NVD data led to an incorrect fixed version being reported in some cases.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CWP-62290</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Fixed Debian issues that have a CVE with the "nodsa\_reason" property set to "ignored" are reported as a vulnerability</strong></p><p>Debian CVEs that have an Urgency of "unimportant" or a "nodsa\_reason" setting of "ignored" in the Debian feed were not reported as vulnerabilities when detected by Prisma Cloud Compute.</p><p>This issue is fixed now. Now, such CVEs will be reported as vulnerabilities with the status 'will not fix' by Prisma Cloud Compute.</p>                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-62394</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>In a few situations serverless credits were consumed even after disabling the serverless functionality</strong></p><p>In setups/tenants that had a particular (core-serverless-scan-concurrent-flow-enabled) setting enabled, serverless scan results were not deleted. This caused some serverless credits to be consumed even after the serverless feature was disabled in the tenant.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                    |
| <p><strong>CWP-62552</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Defender is unable to identify the OpenShift installation on the OpenShift nodes</strong></p><p>The OpenShift version is not available in the RELEASE\_VERSION environment variable in the running 'openshift-tuned' process due to a change in OpenShift. It has now been replaced by a new process called cluster-node-tuning-operator that receives 'openshift-tuned' via command line args. Defenders were unable to detect the OpenShift installation due to this change.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                              |
| <p><strong>CWP-62562</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Fixed RHEL issues are incorrectly flagged as unresolved due to an issue in mapping CPEs to RHEL repositories</strong></p><p>After Redhat switched to the new VEX format for reporting CVEs and fixes, some fixed RHEL issues were incorrectly flagged as unresolved due to an issue in mapping CPEs to RHEL repositories.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-62570</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Base images when scanned separately displayed vulnerabilities that were not present</strong></p><p>The scan results for some base images that were scanned separately incorrectly displayed vulnerabilities–even though no vulnerabilities were present in those base images. Whereas, images using those base images reported the vulnerabilities correctly and did not display any vulnerabilities for the underlying base images.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-62575</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>False positives observed for vulnerabilities reported in the RedHat VEX format without specific distro-release information</strong></p><p>Vulnerabilities reported in the RedHat VEX format without specific distro-release information generated false positives.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>CWP-62590</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Prisma Cloud reported incorrect fix dates for RedHat vulnerabilities</strong></p><p>This issue occurred for vulnerabilities reported as fixed through RedHat feeds in the VEX format. This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>CWP-62609</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Including packages of a Go application that are part of the main module in the scan results</strong></p><p>Previously, Prisma Cloud scan results did not include Go packages that were part of the main module, resulting in the omission of these packages and their associated vulnerabilities in the console.</p><p>This issue has now been resolved.</p>                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-62668</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Compliance check 598 always fails for Kubernetes containers running Redis if the container was created without using –requirepass parameter</strong></p><p>Compliance check 598 fails and shows the error “App uses weak or default password” for Kubernetes containers running redis even though the container uses a strong password. This issue occurs if the container was created without using –requirepass parameter.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                |
| <p><strong>CWP-62883</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>The 'fix status' column in the vulnerability report is blank for a few CVEs</strong></p><p>The 'fix status' column in the vulnerability report is blank for a few CVEs due to missing information in the NVD vulnerability feed.</p><p>This issue is fixed now. The required information is now gathered using a separate NVD function.</p>                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>CWP-62884</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Stale unpaired cloud security agents (CSAs) are not deleted</strong></p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-62994</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Container protected by an App embedded defender with File System monitoring enabled crashes when an SSH connection is made to it</strong></p><p>Container protected by an App embedded defender with File System monitoring enabled crashes when an SSH connection is made to it.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-63032</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Support Jenkins LTS CVEs detection</strong></p><p>Prisma Cloud now extracts software edition information from CVEs and utilizes it for scanning. This enables Prisma Cloud scanners to differentiate software editions, such as Jenkins LTS releases from regular Jenkins releases, and accurately identify vulnerabilities.</p>                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>CWP-63033</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Improved Vulnerability Reporting for Mirrored RHEL Repositories</strong></p><p>Repository identifiers often change when repositories are mirrored from Red Hat’s Content Delivery Network (CDN) to alternative cloud environments, like AWS. This may result in inaccurate vulnerability reporting.</p><p>The issue has now been resolved by extracting the relative URLs of repositories from the image and comparing them with the corresponding relative URLs provided in the repository-to-CPE mapping file for CVE matching.</p>                                                                                                                                                                                                          |
| <p><strong>CWP-63110</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p>                                                       | <p><strong>Incorrect data is returned when Prisma Cloud roles that have read only access to Windows hosts try to access and retrieve data from those Windows hosts</strong></p><p>Incorrect data is returned when Prisma Cloud roles that have read only access to Windows hosts try to access and retrieve cloud metadata from those Windows hosts.</p><p>This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                   |

## Known Issues

The following table lists the known issues for the 34.00 release.

| **ISSUE ID**                                                                                    | **DESCRIPTION**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ----------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>CWP-63632</strong></p><p><mark style="background-color:orange;">34.01.126</mark></p> | <p><strong>Host details display incorrect Windows version</strong></p><p>Windows Server 2025 is incorrectly reported as Windows Server 2022 on the Host details panel.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **--**                                                                                          | <p><strong>Google Cloud Run Functions (Gen2) May Not Be Scanned with Selective Registry Scanning</strong></p><p>Google offers serverless functions in two versions: Cloud Functions ("Gen1") and Cloud Run Functions ("Gen2"). Prisma Cloud fully supports vulnerability scanning for Gen1 functions.</p><p>For Gen2, when code is uploaded to Google Cloud Run Functions, a container image is created and stored in Google Artifact Registry (GAR) or Google Container Registry (GCR). If Prisma Cloud is set to scan all registries in your GCP account, Gen2 function images will be scanned. To view results, check the relevant registry and refer to Google’s naming conventions for container images <a href="https://cloud.google.com/artifact-registry/docs/docker/names">here</a>.</p><p>If Prisma Cloud is configured to scan only selected repositories, the specific repository used by Cloud Run might not be scanned. We are working to support Gen2 function scanning in this scenario.</p> |
| **CWP-62339**                                                                                   | <p><strong>Discrepancies in Vulnerability Scan Results</strong></p><p>In rare instances, discrepancies were observed between vulnerability scan results from Defender and Twistcli host scans.</p><p>For example, certain compliance checks identified by Twistcli were not reflected in Defender scan results, and vice versa. Additionally, for some operating systems, Twistcli reported a higher number of high-severity findings compared to Defender.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/ce-release-notes/prisma-tm-cloud-compute-edition-release-information/known-issues-34.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
