Skip to content

[container-image-scan] Node CVE burn-down #65791

Description

@github-actions

Node scan summary

Status: Upstream (Alpine-based gh-aw-node / node:lts-alpine; no Dockerfile in this repo). Unique finding rows: 0 Critical, 29 High, 40 Medium, 17 Low, 0 Unknown; 0 license violations.

Image Status Crit High Med Low Unk License
gh-aw-node upstream 0 12 15 8 0 0
node:lts-alpine upstream 0 17 25 9 0 0

Images

Image Pinned reference Status
gh-aw-node ghcr.io/github/gh-aw-node@sha256:11c2c544876cdbaffefe0f7f1283b74838c209654b4934a78e23ed11f750490f upstream
node:lts-alpine node:lts-alpine@sha256:ebfe2f90462722a7a4de65e91990e97fe0d401c70e0e762c5b53302f905ec1c1 upstream

Findings by severity

gh-aw-node

High
CVE-2026-103111: pcre2@10.48-r0 (fix: 10.49-r0)
CVE-2026-54873: libcrypto3@3.5.8-r0
CVE-2026-54873: libssl3@3.5.8-r0
CVE-2026-72897: libcrypto3@3.5.8-r0
CVE-2026-72897: libssl3@3.5.8-r0
CVE-2026-84782: libcrypto3@3.5.8-r0
CVE-2026-84782: libssl3@3.5.8-r0
CVE-2026-84784: libcrypto3@3.5.8-r0
CVE-2026-84784: libssl3@3.5.8-r0
CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
CVE-2026-93990: libexpat@2.8.4-r0 (fix: 2.8.5-r0)
GHSA-ch52-4w7c-c8xp: http-cache-semantics@4.2.0
Medium
CVE-2025-60876: busybox-binsh@1.37.0-r31
CVE-2025-60876: busybox@1.37.0-r31
CVE-2025-60876: ssl_client@1.37.0-r31
CVE-2026-35189: libcrypto3@3.5.8-r0
CVE-2026-35189: libssl3@3.5.8-r0
CVE-2026-42772: libcrypto3@3.5.8-r0
CVE-2026-42772: libssl3@3.5.8-r0
CVE-2026-58055: nghttp2-libs@1.69.0-r0 (fix: 1.70.0-r0)
CVE-2026-75804: libcrypto3@3.5.8-r0
CVE-2026-75804: libssl3@3.5.8-r0
CVE-2026-75805: libcrypto3@3.5.8-r0
CVE-2026-75805: libssl3@3.5.8-r0
CVE-2026-75806: libcrypto3@3.5.8-r0
CVE-2026-75806: libssl3@3.5.8-r0
GHSA-rj75-hqrm-r3gf: postcss-selector-parser@7.1.4 (fix: 7.1.6)
Low
CVE-2026-35191: libcrypto3@3.5.8-r0
CVE-2026-35191: libssl3@3.5.8-r0
CVE-2026-54872: libcrypto3@3.5.8-r0
CVE-2026-54872: libssl3@3.5.8-r0
CVE-2026-54875: libcrypto3@3.5.8-r0
CVE-2026-54875: libssl3@3.5.8-r0
CVE-2026-77696: libcrypto3@3.5.8-r0
CVE-2026-77696: libssl3@3.5.8-r0

node-lts-alpine

High
CVE-2026-54873: libcrypto3@3.5.8-r0
CVE-2026-54873: libssl3@3.5.8-r0
CVE-2026-72897: libcrypto3@3.5.8-r0
CVE-2026-72897: libssl3@3.5.8-r0
CVE-2026-84782: libcrypto3@3.5.8-r0
CVE-2026-84782: libssl3@3.5.8-r0
CVE-2026-84784: libcrypto3@3.5.8-r0
CVE-2026-84784: libssl3@3.5.8-r0
CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
GHSA-6j4f-fj2g-mc7p: brace-expansion@5.0.7 (fix: 5.0.10)
GHSA-ch52-4w7c-c8xp: http-cache-semantics@4.2.0
GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8)
GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1)
GHSA-qhr7-859c-m2p7: brace-expansion@5.0.7 (fix: 5.0.11)
GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21)
GHSA-rfgv-xxqx-mfg5: undici@6.27.0 (fix: 6.28.1)
GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9)
Medium
CVE-2025-60876: busybox-binsh@1.37.0-r31
CVE-2025-60876: busybox@1.37.0-r31
CVE-2025-60876: ssl_client@1.37.0-r31
CVE-2026-35189: libcrypto3@3.5.8-r0
CVE-2026-35189: libssl3@3.5.8-r0
CVE-2026-42772: libcrypto3@3.5.8-r0
CVE-2026-42772: libssl3@3.5.8-r0
CVE-2026-75804: libcrypto3@3.5.8-r0
CVE-2026-75804: libssl3@3.5.8-r0
CVE-2026-75805: libcrypto3@3.5.8-r0
CVE-2026-75805: libssl3@3.5.8-r0
CVE-2026-75806: libcrypto3@3.5.8-r0
CVE-2026-75806: libssl3@3.5.8-r0
GHSA-22jq-vg5j-6vgg: ip-address@10.2.0 (fix: 10.2.1)
GHSA-2vr4-cq9g-pvrc: ip-address@10.2.0 (fix: 10.5.1)
GHSA-3wwx-pv8p-q78v: undici@6.27.0 (fix: 6.28.1)
GHSA-4xrf-jv44-h6hh: ip-address@10.2.0 (fix: 10.2.2)
GHSA-8xcm-r25x-g524: undici@6.27.0 (fix: 6.28.0)
GHSA-h3mg-xc3c-68pw: ip-address@10.2.0 (fix: 10.7.1)
GHSA-j6r3-76f7-8jcv: ip-address@10.2.0 (fix: 10.7.1)
GHSA-m8rv-5g2x-5cg5: undici@6.27.0 (fix: 6.28.0)
GHSA-q2hr-2g5m-vwhr: brace-expansion@5.0.7 (fix: 5.0.12)
GHSA-rj75-hqrm-r3gf: postcss-selector-parser@7.1.4 (fix: 7.1.6)
GHSA-rpw4-54j3-4h4q: ip-address@10.2.0 (fix: 10.5.1)
GHSA-v3r7-h72x-cjcm: undici@6.27.0 (fix: 6.28.0)
Low
CVE-2026-35191: libcrypto3@3.5.8-r0
CVE-2026-35191: libssl3@3.5.8-r0
CVE-2026-54872: libcrypto3@3.5.8-r0
CVE-2026-54872: libssl3@3.5.8-r0
CVE-2026-54875: libcrypto3@3.5.8-r0
CVE-2026-54875: libssl3@3.5.8-r0
CVE-2026-77696: libcrypto3@3.5.8-r0
CVE-2026-77696: libssl3@3.5.8-r0
GHSA-r53p-7pc4-xj5r: undici@6.27.0 (fix: 6.28.1)

Remediation and SLA

  • SLA cadence: Critical findings are remediated or explicitly risk-accepted (by a maintainer) within 7 days; High within 30 days; every scanned image is rebuilt on a refreshed base image at least weekly. The daily scan runs gh aw compile --force-refresh-container-pins, so a pin-refresh PR is the default remediation step.
  • Status: Upstream — tracked only. These images are not built from a Dockerfile in github/gh-aw; a code-level fix cannot land here. Do not request a local patch PR. The daily pin refresh picks up upstream fixes once released.
  • Fixed versions: rows shown as pkg@installed => fixed list the fixed package version reported by Grype. The image release/digest containing each fix has not been confirmed from this scan; rows with no fix listed have no fixed package version reported.
  • Exceptions (not risk-accepted; pending maintainer approval): every finding above is awaiting a refreshed upstream image. Responsible project: the image's owning repository (see family summary). Next review: 2026-10-17 (weekly rebuild cadence).
  • Findings are ordered by severity (Critical, High, Medium, Low, Unknown); rows are unique ID pkg@version entries from the scan.

Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 190.8 AIC · ⌖ 0.9 AIC · ⊞ 8.5K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions