Correct scan summary for #52657 (workflow run 35822817812)
Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
Scan run
Compiled with gh aw compile --force-refresh-container-pins. Workflow run: 35822817812.
Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)
| Image |
Pinned ref |
Class |
Critical |
High |
Medium |
Low |
Unknown |
Negligible |
License violations |
ghcr.io/oraios/serena |
1.7.0@sha256:6c9459e... |
Upstream (oraios/serena, 3rd-party) |
12 |
227 raw / 98 unique |
188 |
37 |
36 |
719 |
0 |
ghcr.io/xberg-io/xberg |
latest@sha256:1d9e51a... |
Upstream (xberg-io, kreuzberg MCP, 3rd-party) |
18 |
90 raw / 39 unique |
69 |
12 |
1 |
112 |
47 |
ghcr.io/github/gh-aw-mcpg |
v0.4.25@sha256:9be0a86... |
Upstream (github/gh-aw-mcpg) |
4 |
55 raw / 50 unique |
21 |
7 |
7 |
0 |
0 |
grafana/mcp-grafana |
1.1.0-alpine@sha256:e0eb29c... |
Upstream (Grafana Labs, 3rd-party) |
4 |
21 raw / 19 unique |
3 |
3 |
0 |
0 |
0 |
node (base for gh-aw-node) |
lts-alpine@sha256:ebfe2f9... |
Upstream (Docker Official node) |
0 |
5 |
8 |
0 |
0 |
0 |
0 |
ghcr.io/github/github-mcp-server |
v1.12.2@sha256:508a085... |
Upstream (github/github-mcp-server, 3rd-party build) |
1 |
4 |
10 |
1 |
0 |
8 |
0 |
ghcr.io/github/gh-aw-firewall/api-proxy |
0.28.23@sha256:c15c3d1... |
Upstream (github/gh-aw-firewall) |
0 |
5 |
9 |
0 |
0 |
0 |
1 |
ghcr.io/github/gh-aw-firewall/cli-proxy |
0.28.23@sha256:9e31a6e... |
Upstream (github/gh-aw-firewall) |
0 |
5 |
9 |
0 |
0 |
0 |
1 |
ghcr.io/github/gh-aw-firewall/agent |
0.28.23@sha256:2c78aab... |
Upstream (github/gh-aw-firewall) |
0 |
4 |
313 |
47 |
0 |
19 |
32 |
ghcr.io/github/gh-aw-firewall/squid |
0.28.23@sha256:02ffc56... |
Upstream (github/gh-aw-firewall) |
0 |
1 |
4 |
0 |
0 |
0 |
11 |
ghcr.io/github/gh-aw-node |
sha256:11c2c54... (base: node:lts-alpine, refreshed this run) |
Vendored (built from /actions/setup/js/Dockerfile.safe-outputs-mcp in this repo) |
0 |
1 |
4 |
0 |
0 |
0 |
0 |
Totals: 39 Critical, 445 raw High findings (≈257 unique advisories) across 11 scanned images. License policy violations: 92, across 5 images (all upstream, no vendored-code fix possible here).
Per-image detail
ghcr.io/oraios/serena — Upstream — 12 Critical, 98 unique High
Classification: Upstream — tracked only. Image is owned/built by oraios/serena (third party, Debian trixie base). No code-level fix can land in github/gh-aw.
Critical (12 rows, 4 unique advisories):
- CVE-2026-19931 —
curl/libcurl3t64-gnutls/libcurl4t64 @8.14.1-2+deb13u4 (no fix yet)
- CVE-2026-18924 —
curl/libcurl3t64-gnutls/libcurl4t64 @8.14.1-2+deb13u4 (no fix yet)
- CVE-2026-63073 —
libssl3t64/openssl/openssl-provider-legacy @3.5.6-1deb13u2 (fix: 3.5.7-1deb13u2)
- CVE-2026-75803 —
libssl3t64/openssl/openssl-provider-legacy @3.5.6-1deb13u2 (fix: 3.5.7-1deb13u2)
High (98 unique advisory IDs, selected highlights — full list omitted for compactness):
- Debian
curl/libcurl@8.14.1-2+deb13u4 (no fix yet): CVE-2026-9080, CVE-2026-9545, CVE-2026-8932, CVE-2026-12064, CVE-2026-8286
- Debian
perl @5.40.1-6 (no fix yet): CVE-2026-9538, CVE-2026-42497, CVE-2026-7017, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432
- Debian
libssh2-1t64 @1.11.1-1+deb13u1 (no fix yet): CVE-2026-66032/66033/66034/66035, CVE-2026-58050/58051
- Debian
openssh-* @1:10.0p1-7+deb13u4 (no fix yet): CVE-2026-60000, CVE-2026-59999
- Debian glibc
libc6/libc-bin @2.41-12+deb13u4 (no fix yet): CVE-2026-5928, CVE-2026-5435, CVE-2026-19499
- Debian
util-linux/libblkid1/libmount1/login/mount @2.41-5 (no fix yet): CVE-2026-78408, CVE-2026-78409, CVE-2026-78410, CVE-2026-76642
- Debian
libacl1 @2.3.2-2+b1 (no fix yet): CVE-2026-54369, CVE-2026-54370
- Debian
libexpat1 @2.8.2-1~deb13u1 (no fix yet): CVE-2026-66046, CVE-2026-76956, CVE-2026-76957
- Node.js@22.18.0 (fix: 20.20.x/22.22.x/24.13-14.x/25.3-8.x): CVE-2026-21710, CVE-2025-59465, CVE-2025-55131, CVE-2026-21637, CVE-2025-59466, CVE-2026-56846, CVE-2026-56848, CVE-2026-58043, CVE-2026-48617, CVE-2026-48937
- Python 3.11.15 (fix: 3.13.x/3.14.x/3.15.0): CVE-2026-11940, CVE-2026-15308, CVE-2026-4224, CVE-2026-7210, CVE-2026-6100, CVE-2026-11972, CVE-2026-3644, CVE-2026-9669, CVE-2026-4786
- npm
tar bundled (fix: 7.5.3–7.5.21 across advisories): GHSA-34x7-hfp2-rc4v, GHSA-qffp-2rhf-9h96, GHSA-8x88-c5mf-7j5w, GHSA-r292-9mhp-454m, GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, GHSA-9ppj-qmqm-q256, GHSA-r6q2-hw4h-h46w
brace-expansion (fix: 2.1.2–2.1.4): GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, GHSA-3jxr-9vmj-r5cp
minimatch@9.0.5 (fix: 9.0.6/9.0.7): GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74
glob@10.4.5 → 10.5.0: GHSA-5j98-mcp5-4vw2; picomatch@4.0.2 → 4.0.4: GHSA-c2c7-rcm5-vvqj
ip-address@9.0.5 → 10.3.1: GHSA-mwp4-54f8-5fhr; sigstore@3.1.0 → 4.1.1: GHSA-52v5-jr5w-gjxr
wheel@0.45.1 → 0.46.2: GHSA-8rrh-rw8j-w5fx; jaraco-context@5.3.0 → 6.1.0: GHSA-58pv-8j8x-9vj2
- Debian
ncurses @6.5+20250216-2 (no fix yet): CVE-2025-69720
- Debian
wget @1.25.0-2 (no fix yet): CVE-2026-58469, CVE-2026-58471, CVE-2026-58472
- Alpine-style OpenSSL family recurring across image (no fix yet): CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076
- Misc: CVE-2026-41992 (gzip), CVE-2026-11822/11824 (libsqlite3-0), GHSA-w4pp-8pjf-rmxw
Remediation: Upstream — tracked only. Awaiting oraios/serena to rebuild 1.7.0/latest on a refreshed Debian trixie + Node.js + Python base and bump bundled npm/pip deps. Daily pin-refresh workflow will pick up a new digest automatically once published. No advisory/issue link found yet in the oraios/serena upstream tracker for these specific CVEs.
ghcr.io/xberg-io/xberg — Upstream — 18 Critical, 39 unique High, 47 license violations
Classification: Upstream — tracked only. Image is owned by xberg-io (third-party kreuzberg MCP image, referenced from .github/workflows/shared/mcp/kreuzberg.md). No code-level fix can land in github/gh-aw.
Critical (18 rows, 8 unique advisories) — all Debian trixie packages, no fix yet unless noted:
High (39 unique advisories, highlights):
curl/libcurl4t64 @8.14.1-2+deb13u5: CVE-2026-80229, CVE-2026-80255, CVE-2026-13608, CVE-2026-80230, CVE-2026-82209, CVE-2026-12064, CVE-2026-8932, CVE-2026-8286, CVE-2026-9080, CVE-2026-9545
libxml2 @2.12.7...: CVE-2026-74860, CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144
tesseract-ocr/libtesseract5 @5.5.0-1+b1: CVE-2026-88047, CVE-2026-88048, CVE-2026-88051, CVE-2026-88052, CVE-2026-88053
util-linux/libblkid1/libmount1/login/mount @2.41.5: CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410
libexpat1 @2.8.3-1~deb13u1: CVE-2026-66046, CVE-2026-93990, CVE-2026-76956, CVE-2026-76957
libc6/libc-bin @2.41-12+deb13u4: CVE-2026-19499, CVE-2026-5435
perl-base @5.40.1-6+deb13u1: CVE-2026-9538, CVE-2026-82560
ncurses-base/ncurses-bin/libtinfo6 @6.5+20250216-2: CVE-2025-69720
libacl1 @2.3.2-2+b1: CVE-2026-54369, CVE-2026-54370
libarchive13t64 @3.7.4-4+deb13u1: CVE-2026-14164
zlib1g @1:1.3.dfsg+really1.3.1-1+b1: CVE-2026-85091
License violations (47): copyleft/weak-copyleft (GPL/LGPL/MPL family) and permissive-with-notice licenses on Debian system packages bundled in the image (libglib2.0-0t64, libssl3t64, fontconfig, libpango*, libnghttp3-9, libpsl5t64, tini, login.defs, libaom3, libx265-215, libldap2, and others) — none introduced by this repo.
Remediation: Upstream — tracked only. Requires xberg-io/xberg to rebuild on a refreshed Debian trixie base with bumped curl, libxml2, tesseract-ocr, util-linux, and libexpat1 packages. Daily pin-refresh picks up a new digest automatically once published; no advisory/issue link found yet in the upstream xberg-io tracker.
ghcr.io/github/gh-aw-mcpg — Upstream — 4 Critical, 50 unique High
Classification: Upstream — tracked only (owned by github/gh-aw-mcpg).
Critical (4 rows, 2 unique advisories):
High (50 unique advisories, highlights):
- Go stdlib@go1.26.3/go1.26.4 (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.2/3): GO-2026-5026, GO-2026-6089, GO-2026-6090, GO-2026-5972, GO-2026-5942, GO-2026-4970, GO-2026-5037
golang.org/x/text @v0.38.0 (fix: 0.39.0): GO-2026-5970
golang.org/x/crypto @v0.53.0 (fix: 0.56.0): GO-2026-6354, GO-2026-6355
google.golang.org/grpc @v1.81.1/v1.83.1 (fix: 1.82.1–1.83.2): GHSA-2v4p-qf9q-27wj, GHSA-hrxh-6v49-42gf, GHSA-vp52-pcj8-j9qc
github.com/sigstore/fulcio @v1.8.5 (fix: 1.8.6): GHSA-f5mr-q85p-6hh6
github.com/moby/go-archive @v0.2.0 (fix: 0.3.0): GHSA-hfg8-hc9c-6c3h
- Alpine
libcrypto3/libssl3 @3.5.7-r0 (fix: 3.5.8-r0): CVE-2026-18798, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-14456, CVE-2026-14457, CVE-2026-54874
- Alpine
libblkid/libmount @2.42.1-r0 (fix: 2.42.3-r0/r1): CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410
- Alpine
pcre2 @10.47-r1 (no fix yet): CVE-2026-89157, CVE-2026-89161
docker-cli @29.5.3-r0 (no fix yet): CVE-2026-17106
zlib @1.3.2-r0 (no fix yet): CVE-2026-85091
Remediation: Upstream — tracked only. Requires github/gh-aw-mcpg to rebuild with a newer Go toolchain, bumped x/text/x/crypto/fulcio/grpc/moby/go-archive module versions, and an Alpine base bump. Daily pin-refresh in this repo picks up a new gh-aw-mcpg release once published.
grafana/mcp-grafana — Upstream — 4 Critical, 19 unique High
Classification: Upstream — tracked only (Grafana Labs, third party).
Critical (4 rows, 2 unique advisories):
High:
Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild 1.1.0-alpine on a refreshed Alpine base and a newer grpc-go dependency. Daily pin-refresh picks this up automatically once published.
node:lts-alpine (base for gh-aw-node) — Upstream — 0 Critical, 5 High
Classification: Upstream — tracked only (Docker Official Images node; also the base layer for the vendored ghcr.io/github/gh-aw-node image).
Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the node:lts-alpine Docker Official Image. The daily pin-refresh already bumps node:lts-alpine as new tags publish; no local code fix applies to this base layer. The prior Critical tar advisory (GHSA-23hp-3jrh-7fpw) is no longer present in this scan.
ghcr.io/github/github-mcp-server — Upstream — 1 Critical, 4 High
Classification: Upstream — tracked only (owned by github/github-mcp-server, third-party build, Debian-based).
Also 10 Medium, 1 Low, 8 Negligible (mostly libc6/libssl3 legacy CVEs with limited practical impact).
Remediation: Upstream — tracked only. Requires github/github-mcp-server to refresh its Debian base image. Daily pin-refresh picks up a new github-mcp-server release once published.
ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 0 Critical, 5 High each
Classification: Upstream — tracked only (owned by github/gh-aw-firewall).
License violation (1 each): awf-api-proxy@1.0.0 / awf-cli-proxy@1.0.0 — no licenses found (internal package metadata, upstream-owned).
Remediation: Upstream — tracked only. Requires github/gh-aw-firewall to bump brace-expansion/tar/ip-address npm deps and refresh the Alpine base. Daily pin-refresh picks up new gh-aw-firewall releases automatically.
ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by github/gh-aw-firewall).
Also carries 313 Medium and 47 Low findings (predominantly Ubuntu 22.04 bind9-libs, curl/libcurl4, perl family — not itemized here per compactness) plus 32 license policy violations (GPL/LGPL/MPL/HPND system packages such as libpango*, libavahi-*, libnss3, libcups2, fonts-liberation, and one "no licenses found" package fonts-liberation).
Remediation: Upstream — tracked only, same npm-dependency family as api-proxy/cli-proxy. License violations are Alpine/Ubuntu system-package licenses bundled transitively via the upstream image base — not introduced by this repo, and cannot be fixed here.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 0 Critical, 1 High
Classification: Upstream — tracked only (owned by github/gh-aw-firewall).
- CVE-2026-85091 —
zlib @1.3.2-r0 (no fix yet)
License violations (11): xz-libs (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), acl-libs (LGPL-2.1-or-later/GPL-2.0-or-later), mii-tool (GPL-2.0-or-later), keyutils-libs (GPL-2.0-or-later/LGPL-2.0-or-later), bind-libs (MPL-2.0), squid (GPL-2.0-or-later), userspace-rcu (LGPL-2.1-or-later), libcom_err (GPL-2.0-or-later/LGPL-2.0-or-later), logrotate (GPL-2.0-or-later), bind-tools (MPL-2.0), libltdl (LGPL-2.0-or-later/GPL-2.0-or-later).
Remediation: Upstream — tracked only. Alpine base refresh needed for zlib. The license violations are Grant policy flags on copyleft/weak-copyleft licenses bundled transitively via Alpine packages inside the upstream squid image — not introduced by this repo, and expected/acceptable for these system packages unless gh-aw-firewall's Grant policy changes upstream.
ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 1 High
Classification: Vendored. Built from /actions/setup/js/Dockerfile.safe-outputs-mcp in this repository (github/gh-aw), published by .github/workflows/publish-safe-outputs-node.yml. Base pinned to node:lts-alpine, refreshed this run to sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f.
- [High] CVE-2026-85091 —
zlib @1.3.2-r0 (no fix yet)
- Also 4 Medium findings from the same base layer.
All findings are inherited from the node:lts-alpine base layer (Alpine zlib package), not from repo-specific Dockerfile content. Remediation here is limited to relying on the daily --force-refresh-container-pins Alpine base bump; no further vendored code change is actionable until Alpine ships a fixed zlib package.
Remediation SLA
- Critical findings are remediated or explicitly risk-accepted within 7 days.
- High findings are remediated within 30 days.
- Every scanned image is rebuilt on a refreshed base image at least weekly — this workflow runs
gh aw compile --force-refresh-container-pins daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
- For findings on upstream images (all findings in this run except the one High/four Medium items on
ghcr.io/github/gh-aw-node, which are also base-layer-inherited), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled Upstream — tracked only above.
Next actions
ghcr.io/xberg-io/xberg (18 Critical, 39 unique High, 47 license violations) is a newly-scanned image this run and now the second-largest remediation burden after oraios/serena — both fully upstream/third-party.
oraios/serena (98 unique High CVEs, 12 Critical) remains the largest remediation burden — all upstream, awaiting a rebuilt oraios/serena release with refreshed curl/openssl/Node.js/Python.
ghcr.io/github/gh-aw-mcpg and grafana/mcp-grafana share the same Alpine openssl Critical (CVE-2026-63073, CVE-2026-75803) — a single Alpine security update resolves both once published.
gh-aw-firewall/agent, api-proxy, cli-proxy share the same brace-expansion/tar/ip-address npm advisories — a single upstream fix in github/gh-aw-firewall resolves all three.
- License policy violations (92 total: 47 on
xberg-io/xberg, 32 on gh-aw-firewall/agent, 11 on gh-aw-firewall/squid, 1 each on api-proxy/cli-proxy) are all upstream system-package licenses (GPL/LGPL/MPL/HPND) or "no licenses found" internal packages — not fixable from this repo; track only if the respective upstream Grant policy changes.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
Sorry for the noise — this issue documents an internal workflow mistake so the correct content isn't lost, and it can be closed once #52657 is manually corrected.
Operational note: #52657 needs manual correction this cycle
While preparing this run's update to the Container CVE burn-down tracker (#52657), an accidental placeholder
update_issuecall (body:test, operation:prepend) was submitted before the real scan summary could be sent. This workflow'supdate_issuesafe-output is limited to 1 call per run, so that placeholder call consumed the quota and the correct summary below could not be applied to #52657 in this run.Action needed: A maintainer (or the next scheduled run) should:
testtext from the top of [container-image-scan] Container CVE burn-down #52657's body.Correct scan summary for #52657 (workflow run 35822817812)
Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
Scan run
Compiled with
gh aw compile --force-refresh-container-pins. Workflow run: 35822817812.Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)
ghcr.io/oraios/serenaoraios/serena, 3rd-party)ghcr.io/xberg-io/xbergxberg-io, kreuzberg MCP, 3rd-party)ghcr.io/github/gh-aw-mcpggithub/gh-aw-mcpg)grafana/mcp-grafananode(base for gh-aw-node)node)ghcr.io/github/github-mcp-servergithub/github-mcp-server, 3rd-party build)ghcr.io/github/gh-aw-firewall/api-proxygithub/gh-aw-firewall)ghcr.io/github/gh-aw-firewall/cli-proxygithub/gh-aw-firewall)ghcr.io/github/gh-aw-firewall/agentgithub/gh-aw-firewall)ghcr.io/github/gh-aw-firewall/squidgithub/gh-aw-firewall)ghcr.io/github/gh-aw-node/actions/setup/js/Dockerfile.safe-outputs-mcpin this repo)Totals: 39 Critical, 445 raw High findings (≈257 unique advisories) across 11 scanned images. License policy violations: 92, across 5 images (all upstream, no vendored-code fix possible here).
Per-image detail
ghcr.io/oraios/serena — Upstream — 12 Critical, 98 unique High
Classification: Upstream — tracked only. Image is owned/built by
oraios/serena(third party, Debian trixie base). No code-level fix can land ingithub/gh-aw.Critical (12 rows, 4 unique advisories):
curl/libcurl3t64-gnutls/libcurl4t64@8.14.1-2+deb13u4 (no fix yet)curl/libcurl3t64-gnutls/libcurl4t64@8.14.1-2+deb13u4 (no fix yet)libssl3t64/openssl/openssl-provider-legacy@3.5.6-1deb13u2 (fix: 3.5.7-1deb13u2)libssl3t64/openssl/openssl-provider-legacy@3.5.6-1deb13u2 (fix: 3.5.7-1deb13u2)High (98 unique advisory IDs, selected highlights — full list omitted for compactness):
curl/libcurl@8.14.1-2+deb13u4 (no fix yet): CVE-2026-9080, CVE-2026-9545, CVE-2026-8932, CVE-2026-12064, CVE-2026-8286perl@5.40.1-6 (no fix yet): CVE-2026-9538, CVE-2026-42497, CVE-2026-7017, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432libssh2-1t64@1.11.1-1+deb13u1 (no fix yet): CVE-2026-66032/66033/66034/66035, CVE-2026-58050/58051openssh-*@1:10.0p1-7+deb13u4 (no fix yet): CVE-2026-60000, CVE-2026-59999libc6/libc-bin@2.41-12+deb13u4 (no fix yet): CVE-2026-5928, CVE-2026-5435, CVE-2026-19499util-linux/libblkid1/libmount1/login/mount@2.41-5 (no fix yet): CVE-2026-78408, CVE-2026-78409, CVE-2026-78410, CVE-2026-76642libacl1@2.3.2-2+b1 (no fix yet): CVE-2026-54369, CVE-2026-54370libexpat1@2.8.2-1~deb13u1 (no fix yet): CVE-2026-66046, CVE-2026-76956, CVE-2026-76957tarbundled (fix: 7.5.3–7.5.21 across advisories): GHSA-34x7-hfp2-rc4v, GHSA-qffp-2rhf-9h96, GHSA-8x88-c5mf-7j5w, GHSA-r292-9mhp-454m, GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, GHSA-9ppj-qmqm-q256, GHSA-r6q2-hw4h-h46wbrace-expansion(fix: 2.1.2–2.1.4): GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, GHSA-3jxr-9vmj-r5cpminimatch@9.0.5(fix: 9.0.6/9.0.7): GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74glob@10.4.5→ 10.5.0: GHSA-5j98-mcp5-4vw2;picomatch@4.0.2→ 4.0.4: GHSA-c2c7-rcm5-vvqjip-address@9.0.5→ 10.3.1: GHSA-mwp4-54f8-5fhr;sigstore@3.1.0→ 4.1.1: GHSA-52v5-jr5w-gjxrwheel@0.45.1→ 0.46.2: GHSA-8rrh-rw8j-w5fx;jaraco-context@5.3.0→ 6.1.0: GHSA-58pv-8j8x-9vj2ncurses@6.5+20250216-2 (no fix yet): CVE-2025-69720wget@1.25.0-2 (no fix yet): CVE-2026-58469, CVE-2026-58471, CVE-2026-58472Remediation: Upstream — tracked only. Awaiting
oraios/serenato rebuild1.7.0/lateston a refreshed Debian trixie + Node.js + Python base and bump bundled npm/pip deps. Daily pin-refresh workflow will pick up a new digest automatically once published. No advisory/issue link found yet in theoraios/serenaupstream tracker for these specific CVEs.ghcr.io/xberg-io/xberg — Upstream — 18 Critical, 39 unique High, 47 license violations
Classification: Upstream — tracked only. Image is owned by
xberg-io(third-party kreuzberg MCP image, referenced from.github/workflows/shared/mcp/kreuzberg.md). No code-level fix can land ingithub/gh-aw.Critical (18 rows, 8 unique advisories) — all Debian trixie packages, no fix yet unless noted:
curl/libcurl4t64@8.14.1-2+deb13u5libtiff6@4.7.0-3+deb13u3libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3High (39 unique advisories, highlights):
curl/libcurl4t64@8.14.1-2+deb13u5: CVE-2026-80229, CVE-2026-80255, CVE-2026-13608, CVE-2026-80230, CVE-2026-82209, CVE-2026-12064, CVE-2026-8932, CVE-2026-8286, CVE-2026-9080, CVE-2026-9545libxml2@2.12.7...: CVE-2026-74860, CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144tesseract-ocr/libtesseract5@5.5.0-1+b1: CVE-2026-88047, CVE-2026-88048, CVE-2026-88051, CVE-2026-88052, CVE-2026-88053util-linux/libblkid1/libmount1/login/mount@2.41.5: CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410libexpat1@2.8.3-1~deb13u1: CVE-2026-66046, CVE-2026-93990, CVE-2026-76956, CVE-2026-76957libc6/libc-bin@2.41-12+deb13u4: CVE-2026-19499, CVE-2026-5435perl-base@5.40.1-6+deb13u1: CVE-2026-9538, CVE-2026-82560ncurses-base/ncurses-bin/libtinfo6@6.5+20250216-2: CVE-2025-69720libacl1@2.3.2-2+b1: CVE-2026-54369, CVE-2026-54370libarchive13t64@3.7.4-4+deb13u1: CVE-2026-14164zlib1g@1:1.3.dfsg+really1.3.1-1+b1: CVE-2026-85091License violations (47): copyleft/weak-copyleft (GPL/LGPL/MPL family) and permissive-with-notice licenses on Debian system packages bundled in the image (
libglib2.0-0t64,libssl3t64,fontconfig,libpango*,libnghttp3-9,libpsl5t64,tini,login.defs,libaom3,libx265-215,libldap2, and others) — none introduced by this repo.Remediation: Upstream — tracked only. Requires
xberg-io/xbergto rebuild on a refreshed Debian trixie base with bumpedcurl,libxml2,tesseract-ocr,util-linux, andlibexpat1packages. Daily pin-refresh picks up a new digest automatically once published; no advisory/issue link found yet in the upstreamxberg-iotracker.ghcr.io/github/gh-aw-mcpg — Upstream — 4 Critical, 50 unique High
Classification: Upstream — tracked only (owned by
github/gh-aw-mcpg).Critical (4 rows, 2 unique advisories):
libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)High (50 unique advisories, highlights):
golang.org/x/text@v0.38.0 (fix: 0.39.0): GO-2026-5970golang.org/x/crypto@v0.53.0 (fix: 0.56.0): GO-2026-6354, GO-2026-6355google.golang.org/grpc@v1.81.1/v1.83.1 (fix: 1.82.1–1.83.2): GHSA-2v4p-qf9q-27wj, GHSA-hrxh-6v49-42gf, GHSA-vp52-pcj8-j9qcgithub.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6): GHSA-f5mr-q85p-6hh6github.com/moby/go-archive@v0.2.0 (fix: 0.3.0): GHSA-hfg8-hc9c-6c3hlibcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0): CVE-2026-18798, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-14456, CVE-2026-14457, CVE-2026-54874libblkid/libmount@2.42.1-r0 (fix: 2.42.3-r0/r1): CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410pcre2@10.47-r1 (no fix yet): CVE-2026-89157, CVE-2026-89161docker-cli@29.5.3-r0 (no fix yet): CVE-2026-17106zlib@1.3.2-r0 (no fix yet): CVE-2026-85091Remediation: Upstream — tracked only. Requires
github/gh-aw-mcpgto rebuild with a newer Go toolchain, bumpedx/text/x/crypto/fulcio/grpc/moby/go-archivemodule versions, and an Alpine base bump. Daily pin-refresh in this repo picks up a newgh-aw-mcpgrelease once published.grafana/mcp-grafana — Upstream — 4 Critical, 19 unique High
Classification: Upstream — tracked only (Grafana Labs, third party).
Critical (4 rows, 2 unique advisories):
libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)High:
libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0): CVE-2026-18798, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-14456, CVE-2026-14457, CVE-2026-54874zlib@1.3.2-r0 (no fix yet): CVE-2026-85091google.golang.org/grpc@v1.80.0 (fix: 1.82.2/1.83.1): GHSA-2v4p-qf9q-27wj, GHSA-vp52-pcj8-j9qcRemediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild
1.1.0-alpineon a refreshed Alpine base and a newer grpc-go dependency. Daily pin-refresh picks this up automatically once published.node:lts-alpine (base for gh-aw-node) — Upstream — 0 Critical, 5 High
Classification: Upstream — tracked only (Docker Official Images
node; also the base layer for the vendoredghcr.io/github/gh-aw-nodeimage).brace-expansion@5.0.7 (fix: 5.0.8)brace-expansion@5.0.7 (fix: 5.0.9)ip-address@10.2.0 (fix: 10.3.1)zlib@1.3.2-r0 (no fix yet)tar@7.5.19 (fix: 7.5.21)Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the
node:lts-alpineDocker Official Image. The daily pin-refresh already bumpsnode:lts-alpineas new tags publish; no local code fix applies to this base layer. The prior Criticaltaradvisory (GHSA-23hp-3jrh-7fpw) is no longer present in this scan.ghcr.io/github/github-mcp-server — Upstream — 1 Critical, 4 High
Classification: Upstream — tracked only (owned by
github/github-mcp-server, third-party build, Debian-based).libssl3@3.0.20-1~deb12u2 (no fix yet)libssl3@3.0.20-1~deb12u2 (no fix yet)libssl3@3.0.20-1~deb12u2 (no fix yet)libssl3@3.0.20-1~deb12u2 (no fix yet)libc6@2.36-9+deb12u14 (no fix yet)Also 10 Medium, 1 Low, 8 Negligible (mostly
libc6/libssl3legacy CVEs with limited practical impact).Remediation: Upstream — tracked only. Requires
github/github-mcp-serverto refresh its Debian base image. Daily pin-refresh picks up a newgithub-mcp-serverrelease once published.ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 0 Critical, 5 High each
Classification: Upstream — tracked only (owned by
github/gh-aw-firewall).brace-expansion@5.0.7 (fix: 5.0.8)brace-expansion@5.0.7 (fix: 5.0.9)ip-address@10.2.0 (fix: 10.3.1)zlib@1.3.2-r0 (no fix yet)tar@7.5.19 (fix: 7.5.21)License violation (1 each):
awf-api-proxy@1.0.0/awf-cli-proxy@1.0.0— no licenses found (internal package metadata, upstream-owned).Remediation: Upstream — tracked only. Requires
github/gh-aw-firewallto bumpbrace-expansion/tar/ip-addressnpm deps and refresh the Alpine base. Daily pin-refresh picks up newgh-aw-firewallreleases automatically.ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by
github/gh-aw-firewall).brace-expansion@5.0.7 (fix: 5.0.8)brace-expansion@5.0.7 (fix: 5.0.9)ip-address@10.2.0 (fix: 10.3.1)tar@7.5.19 (fix: 7.5.21)Also carries 313 Medium and 47 Low findings (predominantly Ubuntu 22.04
bind9-libs,curl/libcurl4,perlfamily — not itemized here per compactness) plus 32 license policy violations (GPL/LGPL/MPL/HPND system packages such aslibpango*,libavahi-*,libnss3,libcups2,fonts-liberation, and one "no licenses found" packagefonts-liberation).Remediation: Upstream — tracked only, same npm-dependency family as api-proxy/cli-proxy. License violations are Alpine/Ubuntu system-package licenses bundled transitively via the upstream image base — not introduced by this repo, and cannot be fixed here.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 0 Critical, 1 High
Classification: Upstream — tracked only (owned by
github/gh-aw-firewall).zlib@1.3.2-r0 (no fix yet)License violations (11):
xz-libs(0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain),acl-libs(LGPL-2.1-or-later/GPL-2.0-or-later),mii-tool(GPL-2.0-or-later),keyutils-libs(GPL-2.0-or-later/LGPL-2.0-or-later),bind-libs(MPL-2.0),squid(GPL-2.0-or-later),userspace-rcu(LGPL-2.1-or-later),libcom_err(GPL-2.0-or-later/LGPL-2.0-or-later),logrotate(GPL-2.0-or-later),bind-tools(MPL-2.0),libltdl(LGPL-2.0-or-later/GPL-2.0-or-later).Remediation: Upstream — tracked only. Alpine base refresh needed for
zlib. The license violations are Grant policy flags on copyleft/weak-copyleft licenses bundled transitively via Alpine packages inside the upstreamsquidimage — not introduced by this repo, and expected/acceptable for these system packages unlessgh-aw-firewall's Grant policy changes upstream.ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 1 High
Classification: Vendored. Built from
/actions/setup/js/Dockerfile.safe-outputs-mcpin this repository (github/gh-aw), published by.github/workflows/publish-safe-outputs-node.yml. Base pinned tonode:lts-alpine, refreshed this run tosha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f.zlib@1.3.2-r0 (no fix yet)All findings are inherited from the
node:lts-alpinebase layer (Alpinezlibpackage), not from repo-specific Dockerfile content. Remediation here is limited to relying on the daily--force-refresh-container-pinsAlpine base bump; no further vendored code change is actionable until Alpine ships a fixedzlibpackage.Remediation SLA
gh aw compile --force-refresh-container-pinsdaily, so a pin refresh PR is the default remediation step for base-image-sourced findings.ghcr.io/github/gh-aw-node, which are also base-layer-inherited), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled Upstream — tracked only above.Next actions
ghcr.io/xberg-io/xberg(18 Critical, 39 unique High, 47 license violations) is a newly-scanned image this run and now the second-largest remediation burden afteroraios/serena— both fully upstream/third-party.oraios/serena(98 unique High CVEs, 12 Critical) remains the largest remediation burden — all upstream, awaiting a rebuiltoraios/serenarelease with refreshed curl/openssl/Node.js/Python.ghcr.io/github/gh-aw-mcpgandgrafana/mcp-grafanashare the same AlpineopensslCritical (CVE-2026-63073, CVE-2026-75803) — a single Alpine security update resolves both once published.gh-aw-firewall/agent,api-proxy,cli-proxyshare the samebrace-expansion/tar/ip-addressnpm advisories — a single upstream fix ingithub/gh-aw-firewallresolves all three.xberg-io/xberg, 32 ongh-aw-firewall/agent, 11 ongh-aw-firewall/squid, 1 each onapi-proxy/cli-proxy) are all upstream system-package licenses (GPL/LGPL/MPL/HPND) or "no licenses found" internal packages — not fixable from this repo; track only if the respective upstream Grant policy changes.Sorry for the noise — this issue documents an internal workflow mistake so the correct content isn't lost, and it can be closed once #52657 is manually corrected.