Skip to content

Weekly audit refresh: 32696049090 - #63

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh
Open

Weekly audit refresh: 32696049090#63
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

CVE delta

Net change

SeverityAddedRemovedNet
Critical60+6
High1621+161
Medium159719+1578
Low2225+217

Changed images: 20 of 44

Per-image detail

baserow-baserow-2.2.2

  • Added: C:0 H:6 M:3 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-53612 (HIGH) — bsdutils
      • CVE-2026-53613 (HIGH) — bsdutils
      • CVE-2026-53614 (HIGH) — bsdutils
      • CVE-2026-54284 (HIGH) — sqlparse
      • CVE-2026-59893 (HIGH) — sqlparse
      • CVE-2026-71491 (HIGH) — sqlparse
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • CVE-2026-16742 (MEDIUM) — libsystemd0
      • ...and 2 more

docker.io-louislam-uptime-kuma-2.3.2

  • Added: C:4 H:28 M:9 L:1
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-70460 (CRITICAL) — rsync
      • CVE-2026-77413 (CRITICAL) — jsonata
      • CVE-2026-77414 (CRITICAL) — jsonata
      • CVE-2026-77415 (CRITICAL) — jsonata
      • CVE-2026-13789 (HIGH) — chromium
      • CVE-2026-53613 (HIGH) — bsdutils
      • CVE-2026-53783 (HIGH) — rsync
      • CVE-2026-53785 (HIGH) — rsync
      • ...and 34 more
    • [FIXED]:
      • GHSA-r292-9mhp-454m (MEDIUM) — tar

docker.io-mongo-8.3.2

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11856 (MEDIUM) — libcurl4t64

docuseal-docuseal-3.0.0

  • Added: C:0 H:0 M:28 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14662 (MEDIUM) — libpq
      • CVE-2026-14663 (MEDIUM) — libpq
      • CVE-2026-14664 (MEDIUM) — libpq
      • CVE-2026-14666 (MEDIUM) — libpq
      • CVE-2026-14668 (MEDIUM) — libpq
      • CVE-2026-14669 (MEDIUM) — libpq
      • CVE-2026-14670 (MEDIUM) — libpq
      • CVE-2026-14671 (MEDIUM) — libpq
      • ...and 20 more

fnsys-dockhand-v1.0.29

  • Added: C:0 H:4 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (HIGH) — libcrypto3
      • CVE-2026-17106 (HIGH) — docker-cli-buildx
      • CVE-2026-38753 (HIGH) — busybox
      • CVE-2026-38754 (HIGH) — busybox
      • CVE-2026-38752 (MEDIUM) — busybox
      • CVE-2026-38755 (MEDIUM) — busybox

freshrss-freshrss-1.29.1-alpine

  • Added: C:0 H:0 M:29 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11822 (MEDIUM) — sqlite-libs
      • CVE-2026-11824 (MEDIUM) — sqlite-libs
      • CVE-2026-14662 (MEDIUM) — libpq
      • CVE-2026-14663 (MEDIUM) — libpq
      • CVE-2026-14664 (MEDIUM) — libpq
      • CVE-2026-14666 (MEDIUM) — libpq
      • CVE-2026-14668 (MEDIUM) — libpq
      • CVE-2026-14669 (MEDIUM) — libpq
      • ...and 21 more

ghcr.io-goauthentik-server-2026.2.3

  • Added: C:0 H:58 M:510 L:121
  • Removed: C:0 H:0 M:2 L:2
    • [NEW]:
      • CVE-2026-53612 (HIGH) — bsdutils
      • CVE-2026-53613 (HIGH) — bsdutils
      • CVE-2026-53614 (HIGH) — bsdutils
      • CVE-2026-54284 (HIGH) — sqlparse
      • CVE-2026-59893 (HIGH) — sqlparse
      • CVE-2026-68457 (HIGH) — linux-libc-dev
      • CVE-2026-68470 (HIGH) — linux-libc-dev
      • CVE-2026-71491 (HIGH) — sqlparse
      • ...and 681 more
    • [FIXED]:
      • CVE-2026-68114 (MEDIUM) — linux-libc-dev
      • CVE-2026-68364 (MEDIUM) — linux-libc-dev
      • CVE-2026-64158 (LOW) — linux-libc-dev
      • CVE-2026-68235 (LOW) — linux-libc-dev

ghcr.io-open-webui-open-webui-0.9.5

  • Added: C:0 H:44 M:390 L:94
  • Removed: C:0 H:1 M:6 L:3
    • [NEW]:
      • CVE-2026-53613 (HIGH) — bsdutils
      • CVE-2026-67215 (HIGH) — libcjson1
      • CVE-2026-68457 (HIGH) — linux-libc-dev
      • CVE-2026-68470 (HIGH) — linux-libc-dev
      • CVE-2026-72042 (HIGH) — linux-libc-dev
      • CVE-2026-72049 (HIGH) — linux-libc-dev
      • CVE-2026-72052 (HIGH) — linux-libc-dev
      • CVE-2026-72054 (HIGH) — linux-libc-dev
      • ...and 520 more
    • [FIXED]:
      • CVE-2026-12243 (HIGH) — nltk
      • CVE-2026-68113 (MEDIUM) — linux-libc-dev
      • CVE-2026-68114 (MEDIUM) — linux-libc-dev
      • CVE-2026-68245 (MEDIUM) — linux-libc-dev
      • CVE-2026-68257 (MEDIUM) — linux-libc-dev
      • CVE-2026-68364 (MEDIUM) — linux-libc-dev
      • CVE-2026-68374 (MEDIUM) — linux-libc-dev
      • CVE-2026-68235 (LOW) — linux-libc-dev
      • ...and 2 more

ghcr.io-stoatchat-for-web-0b94704

  • Added: C:0 H:1 M:0 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-73566 (HIGH) — tar
    • [FIXED]:
      • GHSA-r292-9mhp-454m (MEDIUM) — tar

ghcr.io-stoatchat-livekit-server-v1.9.13

  • Added: C:0 H:2 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56864 (HIGH) — golang.org/x/mod
      • CVE-2026-56865 (HIGH) — golang.org/x/mod

ghcr.io-wg-easy-wg-easy-15.3.0

  • Added: C:0 H:1 M:0 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-73566 (HIGH) — tar
    • [FIXED]:
      • GHSA-r292-9mhp-454m (MEDIUM) — tar

ghcr.io-ylianst-meshcentral-1.1.59-mongodb

  • Added: C:0 H:2 M:2 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-73566 (HIGH) — tar
      • GHSA-c7hr-448w-65px (HIGH) — meshcentral
      • CVE-2026-11822 (MEDIUM) — sqlite-libs
      • CVE-2026-11824 (MEDIUM) — sqlite-libs
    • [FIXED]:
      • GHSA-r292-9mhp-454m (MEDIUM) — tar

ghcr.io-zulip-zulip-server-12.0-0

  • Added: C:1 H:12 M:586 L:5
  • Removed: C:0 H:0 M:6 L:0
    • [NEW]:
      • CVE-2026-74394 (CRITICAL) — linux-libc-dev
      • CVE-2025-10263 (HIGH) — linux-libc-dev
      • CVE-2026-54284 (HIGH) — sqlparse
      • CVE-2026-59893 (HIGH) — sqlparse
      • CVE-2026-68470 (HIGH) — linux-libc-dev
      • CVE-2026-71491 (HIGH) — sqlparse
      • CVE-2026-72111 (HIGH) — linux-libc-dev
      • CVE-2026-72124 (HIGH) — linux-libc-dev
      • ...and 596 more
    • [FIXED]:
      • CVE-2026-64158 (MEDIUM) — linux-libc-dev
      • CVE-2026-68185 (MEDIUM) — linux-libc-dev
      • CVE-2026-68295 (MEDIUM) — linux-libc-dev
      • CVE-2026-68364 (MEDIUM) — linux-libc-dev
      • CVE-2026-68435 (MEDIUM) — linux-libc-dev
      • GHSA-r292-9mhp-454m (MEDIUM) — tar

lscr.io-linuxserver-jellyfin-10.11.9

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11856 (MEDIUM) — curl

mongo-8.3.2

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11856 (MEDIUM) — libcurl4t64

n8nio-runners-2.22.1

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11822 (MEDIUM) — sqlite-libs
      • CVE-2026-11824 (MEDIUM) — sqlite-libs

nextcloud-33.0.3-fpm-alpine

  • Added: C:1 H:0 M:29 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-54133 (CRITICAL) — mtdowling/jmespath.php
      • CVE-2026-11822 (MEDIUM) — sqlite-libs
      • CVE-2026-11824 (MEDIUM) — sqlite-libs
      • CVE-2026-14662 (MEDIUM) — libpq
      • CVE-2026-14663 (MEDIUM) — libpq
      • CVE-2026-14664 (MEDIUM) — libpq
      • CVE-2026-14666 (MEDIUM) — libpq
      • CVE-2026-14668 (MEDIUM) — libpq
      • ...and 22 more

postgres-18.4

  • Added: C:0 H:3 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-53612 (HIGH) — bsdutils
      • CVE-2026-53613 (HIGH) — bsdutils
      • CVE-2026-53614 (HIGH) — bsdutils
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • CVE-2026-16742 (MEDIUM) — libsystemd0

qbittorrentofficial-qbittorrent-nox-5.2.0-1

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11822 (MEDIUM) — sqlite-libs
      • CVE-2026-11824 (MEDIUM) — sqlite-libs

towfiqi-serpbear-3.1.0

  • Added: C:0 H:1 M:0 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-73566 (HIGH) — tar
    • [FIXED]:
      • GHSA-r292-9mhp-454m (MEDIUM) — tar

@github-actions
github-actionsBot enabled auto-merge (squash) June 15, 2026 07:46
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 27531642510Weekly audit refresh: 27937554468Jun 22, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch 2 times, most recently from b731738 to ee0b4cbCompareJune 29, 2026 07:31
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 27937554468Weekly audit refresh: 28355862242Jun 29, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from ee0b4cb to f74a280CompareJuly 6, 2026 07:24
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 28355862242Weekly audit refresh: 28774870590Jul 6, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from f74a280 to dd640f5CompareJuly 13, 2026 08:41
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 28774870590Weekly audit refresh: 29236242866Jul 13, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from dd640f5 to bf5d844CompareJuly 20, 2026 08:33
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 29236242866Weekly audit refresh: 29728216532Jul 20, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from bf5d844 to 816e6d7CompareJuly 27, 2026 09:22
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 29728216532Weekly audit refresh: 30253527123Jul 27, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from 816e6d7 to 9cf054dCompareAugust 3, 2026 08:56
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 30253527123Weekly audit refresh: 30799210887Aug 3, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from 9cf054d to ac8c576CompareAugust 10, 2026 06:23
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 30799210887Weekly audit refresh: 31361726896Aug 10, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from ac8c576 to 0cab591CompareAugust 17, 2026 06:06
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 31361726896Weekly audit refresh: 32000254350Aug 17, 2026
@github-actions
github-actionsBotforce-pushed the chore/weekly-audit-refresh branch from 0cab591 to 2cc93c5CompareAugust 24, 2026 06:08
@github-actionsgithub-actionsBot changed the title Weekly audit refresh: 32000254350Weekly audit refresh: 32696049090Aug 24, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@wnstfy