nginx:1.27-alpine| Target Source | Type | Critical | High | Medium | Low | Policy Status |
|---|---|---|---|---|---|---|
nginx:1.27-alpine (3.21.3) | Container Image | 2 | 35 | 48 | 26 | FAIL |
| Severity | Vulnerability ID | Package / Asset | Versions (Installed → Fixed) | Evidence Details & Mitigation Strategy |
|---|---|---|---|---|
| Medium | CVE-2024-58251 | busybox | 1.37.0-r12 → 1.37.0-r14 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.37.0-r14 and rebuild image; pin dependency then push new image. |
| Low | CVE-2025-46394 | busybox | 1.37.0-r12 → 1.37.0-r14 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.37.0-r14 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2024-58251 | busybox-binsh | 1.37.0-r12 → 1.37.0-r14 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.37.0-r14 and rebuild image; pin dependency then push new image. |
| Low | CVE-2025-46394 | busybox-binsh | 1.37.0-r12 → 1.37.0-r14 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.37.0-r14 and rebuild image; pin dependency then push new image. |
| High | CVE-2026-33630 | c-ares | 1.34.5-r0 → 1.34.8-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 1.34.8-r0 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2025-62408 | c-ares | 1.34.5-r0 → 1.34.6-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 1.34.6-r0 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2025-4947 | curl | 8.12.1-r1 → 8.14.0-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 8.14.0-r0 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2025-5025 | curl | 8.12.1-r1 → 8.14.0-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 8.14.0-r0 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2025-5399 | curl | 8.12.1-r1 → 8.14.1-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 8.14.1-r0 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2025-9086 | curl | 8.12.1-r1 → 8.14.1-r2 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 8.14.1-r2 and rebuild image; pin dependency then push new image. |
| Low | CVE-2025-10148 | curl | 8.12.1-r1 → 8.14.1-r2 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 8.14.1-r2 and rebuild image; pin dependency then push new image. |
| Critical | CVE-2026-31789 | libcrypto3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libcrypto3=3.3.7-r0 or apt-get install libcrypto3=3.3.7-r0) |
| High | CVE-2025-15467 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| High | CVE-2025-69421 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| High | CVE-2026-28387 | libcrypto3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libcrypto3=3.3.7-r0 or apt-get install libcrypto3=3.3.7-r0) |
| High | CVE-2026-28388 | libcrypto3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libcrypto3=3.3.7-r0 or apt-get install libcrypto3=3.3.7-r0) |
| High | CVE-2026-28389 | libcrypto3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libcrypto3=3.3.7-r0 or apt-get install libcrypto3=3.3.7-r0) |
| High | CVE-2026-28390 | libcrypto3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libcrypto3=3.3.7-r0 or apt-get install libcrypto3=3.3.7-r0) |
| Medium | CVE-2025-69419 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Medium | CVE-2025-9230 | libcrypto3 | 3.3.3-r0 → 3.3.5-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.5-r0 (alpine: apk add --no-cache libcrypto3=3.3.5-r0 or apt-get install libcrypto3=3.3.5-r0) |
| Medium | CVE-2025-9231 | libcrypto3 | 3.3.3-r0 → 3.3.5-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.5-r0 (alpine: apk add --no-cache libcrypto3=3.3.5-r0 or apt-get install libcrypto3=3.3.5-r0) |
| Medium | CVE-2026-31790 | libcrypto3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libcrypto3=3.3.7-r0 or apt-get install libcrypto3=3.3.7-r0) |
| Low | CVE-2025-15468 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Low | CVE-2025-66199 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Low | CVE-2025-68160 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Low | CVE-2025-69418 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Low | CVE-2025-69420 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Low | CVE-2025-9232 | libcrypto3 | 3.3.3-r0 → 3.3.5-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.5-r0 (alpine: apk add --no-cache libcrypto3=3.3.5-r0 or apt-get install libcrypto3=3.3.5-r0) |
| Low | CVE-2026-22795 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Low | CVE-2026-22796 | libcrypto3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libcrypto3=3.3.6-r0 or apt-get install libcrypto3=3.3.6-r0) |
| Medium | CVE-2025-4947 | libcurl | 8.12.1-r1 → 8.14.0-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 8.14.0-r0 (alpine: apk add --no-cache libcurl=8.14.0-r0 or apt-get install libcurl=8.14.0-r0) |
| Medium | CVE-2025-5025 | libcurl | 8.12.1-r1 → 8.14.0-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 8.14.0-r0 (alpine: apk add --no-cache libcurl=8.14.0-r0 or apt-get install libcurl=8.14.0-r0) |
| Medium | CVE-2025-5399 | libcurl | 8.12.1-r1 → 8.14.1-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 8.14.1-r0 (alpine: apk add --no-cache libcurl=8.14.1-r0 or apt-get install libcurl=8.14.1-r0) |
| Medium | CVE-2025-9086 | libcurl | 8.12.1-r1 → 8.14.1-r2 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 8.14.1-r2 (alpine: apk add --no-cache libcurl=8.14.1-r2 or apt-get install libcurl=8.14.1-r2) |
| Low | CVE-2025-10148 | libcurl | 8.12.1-r1 → 8.14.1-r2 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 8.14.1-r2 (alpine: apk add --no-cache libcurl=8.14.1-r2 or apt-get install libcurl=8.14.1-r2) |
| High | CVE-2025-59375 | libexpat | 2.7.0-r0 → 2.7.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.7.2-r0 (alpine: apk add --no-cache libexpat=2.7.2-r0 or apt-get install libexpat=2.7.2-r0) |
| High | CVE-2026-25210 | libexpat | 2.7.0-r0 → 2.7.4-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.7.4-r0 (alpine: apk add --no-cache libexpat=2.7.4-r0 or apt-get install libexpat=2.7.4-r0) |
| High | CVE-2026-45186 | libexpat | 2.7.0-r0 → 2.8.1-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.1-r0 (alpine: apk add --no-cache libexpat=2.8.1-r0 or apt-get install libexpat=2.8.1-r0) |
| High | CVE-2026-56408 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| High | CVE-2026-66046 | libexpat | 2.7.0-r0 → 2.8.4-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.4-r0 (alpine: apk add --no-cache libexpat=2.8.4-r0 or apt-get install libexpat=2.8.4-r0) |
| High | CVE-2026-76641 | libexpat | 2.7.0-r0 → 2.8.4-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.4-r0 (alpine: apk add --no-cache libexpat=2.8.4-r0 or apt-get install libexpat=2.8.4-r0) |
| Medium | CVE-2026-32776 | libexpat | 2.7.0-r0 → 2.7.5-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.7.5-r0 (alpine: apk add --no-cache libexpat=2.7.5-r0 or apt-get install libexpat=2.7.5-r0) |
| Medium | CVE-2026-32777 | libexpat | 2.7.0-r0 → 2.7.5-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.7.5-r0 (alpine: apk add --no-cache libexpat=2.7.5-r0 or apt-get install libexpat=2.7.5-r0) |
| Medium | CVE-2026-32778 | libexpat | 2.7.0-r0 → 2.7.5-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.7.5-r0 (alpine: apk add --no-cache libexpat=2.7.5-r0 or apt-get install libexpat=2.7.5-r0) |
| Medium | CVE-2026-50219 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56131 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56132 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56403 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56404 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56405 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56406 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56407 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56409 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56410 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56411 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-56412 | libexpat | 2.7.0-r0 → 2.8.2-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.2-r0 (alpine: apk add --no-cache libexpat=2.8.2-r0 or apt-get install libexpat=2.8.2-r0) |
| Medium | CVE-2026-76956 | libexpat | 2.7.0-r0 → 2.8.4-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.4-r0 (alpine: apk add --no-cache libexpat=2.8.4-r0 or apt-get install libexpat=2.8.4-r0) |
| Medium | CVE-2026-76957 | libexpat | 2.7.0-r0 → 2.8.4-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.4-r0 (alpine: apk add --no-cache libexpat=2.8.4-r0 or apt-get install libexpat=2.8.4-r0) |
| Low | CVE-2026-24515 | libexpat | 2.7.0-r0 → 2.7.4-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.7.4-r0 (alpine: apk add --no-cache libexpat=2.7.4-r0 or apt-get install libexpat=2.7.4-r0) |
| Low | CVE-2026-41080 | libexpat | 2.7.0-r0 → 2.8.1-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.8.1-r0 (alpine: apk add --no-cache libexpat=2.8.1-r0 or apt-get install libexpat=2.8.1-r0) |
| High | CVE-2025-64720 | libpng | 1.6.47-r0 → 1.6.53-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.53-r0 (alpine: apk add --no-cache libpng=1.6.53-r0 or apt-get install libpng=1.6.53-r0) |
| High | CVE-2025-65018 | libpng | 1.6.47-r0 → 1.6.53-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.53-r0 (alpine: apk add --no-cache libpng=1.6.53-r0 or apt-get install libpng=1.6.53-r0) |
| High | CVE-2025-66293 | libpng | 1.6.47-r0 → 1.6.53-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.53-r0 (alpine: apk add --no-cache libpng=1.6.53-r0 or apt-get install libpng=1.6.53-r0) |
| High | CVE-2026-22695 | libpng | 1.6.47-r0 → 1.6.54-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.54-r0 (alpine: apk add --no-cache libpng=1.6.54-r0 or apt-get install libpng=1.6.54-r0) |
| High | CVE-2026-22801 | libpng | 1.6.47-r0 → 1.6.54-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.54-r0 (alpine: apk add --no-cache libpng=1.6.54-r0 or apt-get install libpng=1.6.54-r0) |
| High | CVE-2026-25646 | libpng | 1.6.47-r0 → 1.6.55-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.55-r0 (alpine: apk add --no-cache libpng=1.6.55-r0 or apt-get install libpng=1.6.55-r0) |
| Medium | CVE-2025-64505 | libpng | 1.6.47-r0 → 1.6.53-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.53-r0 (alpine: apk add --no-cache libpng=1.6.53-r0 or apt-get install libpng=1.6.53-r0) |
| Medium | CVE-2025-64506 | libpng | 1.6.47-r0 → 1.6.53-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.53-r0 (alpine: apk add --no-cache libpng=1.6.53-r0 or apt-get install libpng=1.6.53-r0) |
| Medium | CVE-2026-33416 | libpng | 1.6.47-r0 → 1.6.56-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.56-r0 (alpine: apk add --no-cache libpng=1.6.56-r0 or apt-get install libpng=1.6.56-r0) |
| Medium | CVE-2026-33636 | libpng | 1.6.47-r0 → 1.6.56-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.56-r0 (alpine: apk add --no-cache libpng=1.6.56-r0 or apt-get install libpng=1.6.56-r0) |
| Medium | CVE-2026-34757 | libpng | 1.6.47-r0 → 1.6.57-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.6.57-r0 (alpine: apk add --no-cache libpng=1.6.57-r0 or apt-get install libpng=1.6.57-r0) |
| Critical | CVE-2026-31789 | libssl3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libssl3=3.3.7-r0 or apt-get install libssl3=3.3.7-r0) |
| High | CVE-2025-15467 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| High | CVE-2025-69421 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| High | CVE-2026-28387 | libssl3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libssl3=3.3.7-r0 or apt-get install libssl3=3.3.7-r0) |
| High | CVE-2026-28388 | libssl3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libssl3=3.3.7-r0 or apt-get install libssl3=3.3.7-r0) |
| High | CVE-2026-28389 | libssl3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libssl3=3.3.7-r0 or apt-get install libssl3=3.3.7-r0) |
| High | CVE-2026-28390 | libssl3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libssl3=3.3.7-r0 or apt-get install libssl3=3.3.7-r0) |
| Medium | CVE-2025-69419 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Medium | CVE-2025-9230 | libssl3 | 3.3.3-r0 → 3.3.5-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.5-r0 (alpine: apk add --no-cache libssl3=3.3.5-r0 or apt-get install libssl3=3.3.5-r0) |
| Medium | CVE-2025-9231 | libssl3 | 3.3.3-r0 → 3.3.5-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.5-r0 (alpine: apk add --no-cache libssl3=3.3.5-r0 or apt-get install libssl3=3.3.5-r0) |
| Medium | CVE-2026-31790 | libssl3 | 3.3.3-r0 → 3.3.7-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.7-r0 (alpine: apk add --no-cache libssl3=3.3.7-r0 or apt-get install libssl3=3.3.7-r0) |
| Low | CVE-2025-15468 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Low | CVE-2025-66199 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Low | CVE-2025-68160 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Low | CVE-2025-69418 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Low | CVE-2025-69420 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Low | CVE-2025-9232 | libssl3 | 3.3.3-r0 → 3.3.5-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.5-r0 (alpine: apk add --no-cache libssl3=3.3.5-r0 or apt-get install libssl3=3.3.5-r0) |
| Low | CVE-2026-22795 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| Low | CVE-2026-22796 | libssl3 | 3.3.3-r0 → 3.3.6-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.3.6-r0 (alpine: apk add --no-cache libssl3=3.3.6-r0 or apt-get install libssl3=3.3.6-r0) |
| High | CVE-2025-32414 | libxml2 | 2.13.4-r5 → 2.13.4-r6 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.4-r6 (alpine: apk add --no-cache libxml2=2.13.4-r6 or apt-get install libxml2=2.13.4-r6) |
| High | CVE-2025-32415 | libxml2 | 2.13.4-r5 → 2.13.4-r6 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.4-r6 (alpine: apk add --no-cache libxml2=2.13.4-r6 or apt-get install libxml2=2.13.4-r6) |
| High | CVE-2025-49794 | libxml2 | 2.13.4-r5 → 2.13.9-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.9-r0 (alpine: apk add --no-cache libxml2=2.13.9-r0 or apt-get install libxml2=2.13.9-r0) |
| High | CVE-2025-49795 | libxml2 | 2.13.4-r5 → 2.13.9-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.9-r0 (alpine: apk add --no-cache libxml2=2.13.9-r0 or apt-get install libxml2=2.13.9-r0) |
| High | CVE-2025-49796 | libxml2 | 2.13.4-r5 → 2.13.9-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.9-r0 (alpine: apk add --no-cache libxml2=2.13.9-r0 or apt-get install libxml2=2.13.9-r0) |
| High | CVE-2026-6732 | libxml2 | 2.13.4-r5 → 2.13.9-r1 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.9-r1 (alpine: apk add --no-cache libxml2=2.13.9-r1 or apt-get install libxml2=2.13.9-r1) |
| Medium | CVE-2025-6021 | libxml2 | 2.13.4-r5 → 2.13.9-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.9-r0 (alpine: apk add --no-cache libxml2=2.13.9-r0 or apt-get install libxml2=2.13.9-r0) |
| Low | CVE-2025-6170 | libxml2 | 2.13.4-r5 → 2.13.9-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 2.13.9-r0 (alpine: apk add --no-cache libxml2=2.13.9-r0 or apt-get install libxml2=2.13.9-r0) |
| Medium | CVE-2026-4367 | libxpm | 3.5.17-r0 → 3.5.19-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 3.5.19-r0 (alpine: apk add --no-cache libxpm=3.5.19-r0 or apt-get install libxpm=3.5.19-r0) |
| High | CVE-2026-40200 | musl | 1.2.5-r9 → 1.2.5-r11 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.2.5-r11 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2026-6042 | musl | 1.2.5-r9 → 1.2.5-r10 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.2.5-r10 and rebuild image; pin dependency then push new image. |
| High | CVE-2026-40200 | musl-utils | 1.2.5-r9 → 1.2.5-r11 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.2.5-r11 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2026-6042 | musl-utils | 1.2.5-r9 → 1.2.5-r10 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.2.5-r10 and rebuild image; pin dependency then push new image. |
| High | CVE-2026-27135 | nghttp2-libs | 1.64.0-r0 → 1.68.1 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.68.1 (alpine: apk add --no-cache nghttp2-libs=1.68.1 or apt-get install nghttp2-libs=1.68.1) |
| Medium | CVE-2024-58251 | ssl_client | 1.37.0-r12 → 1.37.0-r14 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.37.0-r14 and rebuild image; pin dependency then push new image. |
| Low | CVE-2025-46394 | ssl_client | 1.37.0-r12 → 1.37.0-r14 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update package to 1.37.0-r14 and rebuild image; pin dependency then push new image. |
| Low | CVE-2025-8961 | tiff | 4.7.0-r0 → 4.7.1-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 4.7.1-r0 and rebuild image; pin dependency then push new image. |
| Low | CVE-2025-9165 | tiff | 4.7.0-r0 → 4.7.1-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update package to 4.7.1-r0 and rebuild image; pin dependency then push new image. |
| Medium | CVE-2026-34743 | xz-libs | 5.6.3-r1 → 5.8.3-r0 | Issue: See linked entry Evidence Layer: sha256:39c2ddfd6010082a4a646e7ca44e95aca9bf3eaebc00f17f7ccc2954004f2a7d Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 5.8.3-r0 (alpine: apk add --no-cache xz-libs=5.8.3-r0 or apt-get install xz-libs=5.8.3-r0) |
| High | CVE-2026-22184 | zlib | 1.3.1-r2 → 1.3.2-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.3.2-r0 (alpine: apk add --no-cache zlib=1.3.2-r0 or apt-get install zlib=1.3.2-r0) |
| Medium | CVE-2026-27171 | zlib | 1.3.1-r2 → 1.3.2-r0 | Issue: See linked entry Evidence Layer: sha256:f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870 Required Action: Update base image or package: e.g. in Dockerfile use updated distro/base; rebuild image with fixed package 1.3.2-r0 (alpine: apk add --no-cache zlib=1.3.2-r0 or apt-get install zlib=1.3.2-r0) |
| MEDIUM | yaml.kubernetes.security.run-as-non-root.run-as-non-root | /usr/local/lib/hermes-agent/devsec-poc/poc.yaml | N/A | Issue: When running containers in Kubernetes, it's important to ensure that they are properly secured to prevent privilege escalation attacks. One potential vulnerability is when a container is allowed to run applications as the root user, which could allow an attacker to gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container, with the parameter `runAsNonRoot` set to `true`. This will ensure that the container runs as a non-root user, limiting the damage that could be caused by any potential attacks. By adding a `securityContext` to the container in your Kubernetes pod, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. Required Action: Review and remediate in codebase (create PR, add tests) |
| MEDIUM | yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext | /usr/local/lib/hermes-agent/devsec-poc/poc.yaml | N/A | Issue: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This will prevent the container from running any privileged processes and limit the impact of any potential attacks. By adding a `securityContext` to your Kubernetes pod, you can help to ensure that your containerized applications are more secure and less vulnerable to privilege escalation attacks. Required Action: Review and remediate in codebase (create PR, add tests) |
This report proves that critical severity vulnerabilities have been identified. Remediation actions are suggested per finding. Image digest and artifact information is recorded above.