Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/squid:0.27.44 #51022

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/squid:0.27.44

  • Vulnerabilities: 0 Critical / 14 High / 8 Medium / 0 Low / 0 Negligible
  • License policy violations: 37

Vulnerabilities

High

All High findings are in bind-libs@9.20.24-r0 / bind-tools@9.20.24-r0 (fix: 9.20.26-r0):

  • CVE-2026-11605, CVE-2026-11622, CVE-2026-13204, CVE-2026-12617, CVE-2026-11331, CVE-2026-11721, CVE-2026-13321
Medium (8)
  • CVE-2026-10822: bind-libs@9.20.24-r0, bind-tools@9.20.24-r0 (fix: 9.20.26-r0)
  • CVE-2026-10723: bind-libs@9.20.24-r0, bind-tools@9.20.24-r0 (fix: 9.20.26-r0)
  • CVE-2025-60876: busybox@1.37.0-r31, busybox-binsh@1.37.0-r31, ssl_client@1.37.0-r31 (no fix listed)
  • CVE-2026-58055: nghttp2-libs@1.69.0-r0 (no fix listed)

License Policy Violations

37 violations, all standard Alpine base-layer / squid dependency licenses: GPL-2.0/LGPL family (apk-tools, libapk, busybox*, alpine-baselayout*, musl-utils, libgcc, libstdc++, libcap2, zstd-libs, libcom_err, keyutils-libs, net-tools, mii-tool, scanelf, logrotate, squid@7.6-r0, libltdl, acl-libs, libidn2, libunistring, userspace-rcu), GPL-3.0 (bash, readline), X11 (libncursesw, ncurses-terminfo-base), MPL-2.0 (bind-libs, bind-tools, ca-certificates-bundle), curl license (curl, libcurl), Zlib (zlib), plus multi-license combos (libmd: AND/Beerware/Domain/Public; xz-libs: 0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain) and sqlite-libs@3.53.2-r0 under the non-standard "blessing" license identifier. No packages with missing license data.

Remediation

  1. Upgrade bind-libs/bind-tools to 9.20.26-r0 to resolve all 14 High and 2 of the 8 Medium findings.
  2. Monitor upstream for busybox/nghttp2-libs fixes (not yet published) for the remaining Medium CVEs.
  3. Rebuild image from a refreshed Alpine base once packages are updated.
  4. Review Grant policy allowlist for standard Alpine GPL/LGPL/X11/MPL packages that are expected components of a squid-based image; verify the sqlite-libs "blessing" license classification is intentional/acceptable.

Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · ◷

Activity

  1. github-actions commented on Aug 7, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · gpt54 · 2.02 AIC · ⊞ 10.3K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions