Skip to content

[container-image-scan] xberg-io/xberg CVE burn-down #65796

Description

@github-actions

xberg-io/xberg scan summary

Status: Upstream — owned by xberg-io/xberg. Findings: 18 Critical, 105 High, 78 Medium, 16 Low, 1 Unknown, 114 Negligible; 47 license violations (GPL/LGPL/other copyleft or multi-license packages, full list below).

Image Pinned reference Status Crit High Med Low Unk Neg License
xberg ghcr.io/xberg-io/xberg:1.3.6@sha256:f8dd1d18b97a883b235b70ca3765b9e526cf5436764a89b6401a5d32ab96ada9 upstream 18 105 78 16 1 114 47

Critical: curl/libcurl4t64 (CVE-2026-19931, -11856, -8924, -10536, -9079, -18924, -8927, -8926), libtiff6 CVE-2026-52490, libxml2 CVE-2026-6653; none list a fixed version in the scan.

findings: xberg

Critical (18 unique rows)

CVE-2026-10536: curl@8.14.1-2+deb13u5
CVE-2026-10536: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-11856: curl@8.14.1-2+deb13u5
CVE-2026-11856: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-18924: curl@8.14.1-2+deb13u5
CVE-2026-18924: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-19931: curl@8.14.1-2+deb13u5
CVE-2026-19931: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-52490: libtiff6@4.7.0-3+deb13u3
CVE-2026-6653: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-8924: curl@8.14.1-2+deb13u5
CVE-2026-8924: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-8926: curl@8.14.1-2+deb13u5
CVE-2026-8926: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-8927: curl@8.14.1-2+deb13u5
CVE-2026-8927: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-9079: curl@8.14.1-2+deb13u5
CVE-2026-9079: libcurl4t64@8.14.1-2+deb13u5

High (105 unique rows)

CVE-2025-69720: libtinfo6@6.5+20250216-2
CVE-2025-69720: ncurses-base@6.5+20250216-2
CVE-2025-69720: ncurses-bin@6.5+20250216-2
CVE-2026-102010: gcc-14-base@14.2.0-19
CVE-2026-102010: libatomic1@14.2.0-19
CVE-2026-102010: libgcc-s1@14.2.0-19
CVE-2026-102010: libgomp1@14.2.0-19
CVE-2026-102010: libstdc++6@14.2.0-19
CVE-2026-12064: curl@8.14.1-2+deb13u5
CVE-2026-12064: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-13608: curl@8.14.1-2+deb13u5
CVE-2026-13608: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-14164: libarchive13t64@3.7.4-4+deb13u1
CVE-2026-19499: libc-bin@2.41-12+deb13u4
CVE-2026-19499: libc6@2.41-12+deb13u4
CVE-2026-5435: libc-bin@2.41-12+deb13u4
CVE-2026-5435: libc6@2.41-12+deb13u4
CVE-2026-54369: libacl1@2.3.2-2+b1
CVE-2026-54370: libacl1@2.3.2-2+b1
CVE-2026-66046: libexpat1@2.8.3-1~deb13u1
CVE-2026-74860: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-76642: bsdutils@1:2.41.5-0+deb13u1
CVE-2026-76642: libblkid1@2.41.5-0+deb13u1
CVE-2026-76642: liblastlog2-2@2.41.5-0+deb13u1
CVE-2026-76642: libmount1@2.41.5-0+deb13u1
CVE-2026-76642: libsmartcols1@2.41.5-0+deb13u1
CVE-2026-76642: libuuid1@2.41.5-0+deb13u1
CVE-2026-76642: login@1:4.16.0-2+really2.41.5-0+deb13u1
CVE-2026-76642: mount@2.41.5-0+deb13u1
CVE-2026-76642: util-linux@2.41.5-0+deb13u1
CVE-2026-76956: libexpat1@2.8.3-1~deb13u1
CVE-2026-76957: libexpat1@2.8.3-1~deb13u1
CVE-2026-77214: libexpat1@2.8.3-1~deb13u1
CVE-2026-78408: bsdutils@1:2.41.5-0+deb13u1
CVE-2026-78408: libblkid1@2.41.5-0+deb13u1
CVE-2026-78408: liblastlog2-2@2.41.5-0+deb13u1
CVE-2026-78408: libmount1@2.41.5-0+deb13u1
CVE-2026-78408: libsmartcols1@2.41.5-0+deb13u1
CVE-2026-78408: libuuid1@2.41.5-0+deb13u1
CVE-2026-78408: login@1:4.16.0-2+really2.41.5-0+deb13u1
CVE-2026-78408: mount@2.41.5-0+deb13u1
CVE-2026-78408: util-linux@2.41.5-0+deb13u1
CVE-2026-78409: bsdutils@1:2.41.5-0+deb13u1
CVE-2026-78409: libblkid1@2.41.5-0+deb13u1
CVE-2026-78409: liblastlog2-2@2.41.5-0+deb13u1
CVE-2026-78409: libmount1@2.41.5-0+deb13u1
CVE-2026-78409: libsmartcols1@2.41.5-0+deb13u1
CVE-2026-78409: libuuid1@2.41.5-0+deb13u1
CVE-2026-78409: login@1:4.16.0-2+really2.41.5-0+deb13u1
CVE-2026-78409: mount@2.41.5-0+deb13u1
CVE-2026-78409: util-linux@2.41.5-0+deb13u1
CVE-2026-78410: bsdutils@1:2.41.5-0+deb13u1
CVE-2026-78410: libblkid1@2.41.5-0+deb13u1
CVE-2026-78410: liblastlog2-2@2.41.5-0+deb13u1
CVE-2026-78410: libmount1@2.41.5-0+deb13u1
CVE-2026-78410: libsmartcols1@2.41.5-0+deb13u1
CVE-2026-78410: libuuid1@2.41.5-0+deb13u1
CVE-2026-78410: login@1:4.16.0-2+really2.41.5-0+deb13u1
CVE-2026-78410: mount@2.41.5-0+deb13u1
CVE-2026-78410: util-linux@2.41.5-0+deb13u1
CVE-2026-80229: curl@8.14.1-2+deb13u5
CVE-2026-80229: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-80230: curl@8.14.1-2+deb13u5
CVE-2026-80230: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-80255: curl@8.14.1-2+deb13u5
CVE-2026-80255: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-82209: curl@8.14.1-2+deb13u5
CVE-2026-82209: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-82560: perl-base@5.40.1-6+deb13u1
CVE-2026-8286: curl@8.14.1-2+deb13u5
CVE-2026-8286: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-85091: zlib1g@1:1.3.dfsg+really1.3.1-1+b1
CVE-2026-86138: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-86139: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-86140: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-86142: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-86143: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-86144: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-88047: libtesseract5@5.5.0-1+b1
CVE-2026-88047: tesseract-ocr@5.5.0-1+b1
CVE-2026-88048: libtesseract5@5.5.0-1+b1
CVE-2026-88048: tesseract-ocr@5.5.0-1+b1
CVE-2026-88051: libtesseract5@5.5.0-1+b1
CVE-2026-88051: tesseract-ocr@5.5.0-1+b1
CVE-2026-88052: libtesseract5@5.5.0-1+b1
CVE-2026-88052: tesseract-ocr@5.5.0-1+b1
CVE-2026-88053: libtesseract5@5.5.0-1+b1
CVE-2026-88053: tesseract-ocr@5.5.0-1+b1
CVE-2026-88373: libde265-0@1.0.15-1+deb13u2
CVE-2026-88806: libx11-6@2:1.8.12-1
CVE-2026-88806: libx11-data@2:1.8.12-1
CVE-2026-88807: libxrender1@1:0.9.12-1
CVE-2026-8932: curl@8.14.1-2+deb13u5
CVE-2026-8932: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-9080: curl@8.14.1-2+deb13u5
CVE-2026-9080: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-93990: libexpat1@2.8.3-1~deb13u1
CVE-2026-9538: perl-base@5.40.1-6+deb13u1
CVE-2026-9545: curl@8.14.1-2+deb13u5
CVE-2026-9545: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-95619: gcc-14-base@14.2.0-19
CVE-2026-95619: libatomic1@14.2.0-19
CVE-2026-95619: libgcc-s1@14.2.0-19
CVE-2026-95619: libgomp1@14.2.0-19
CVE-2026-95619: libstdc++6@14.2.0-19

Medium (78 unique rows)

CVE-2023-39327: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2023-39328: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2023-39329: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2025-6141: libtinfo6@6.5+20250216-2
CVE-2025-6141: ncurses-base@6.5+20250216-2
CVE-2025-6141: ncurses-bin@6.5+20250216-2
CVE-2025-66382: libexpat1@2.8.3-1~deb13u1
CVE-2026-102633: libexpat1@2.8.3-1~deb13u1
CVE-2026-13757: libp11-kit0@0.25.5-3
CVE-2026-15059: libsystemd0@257.13-1~deb13u1
CVE-2026-15059: libudev1@257.13-1~deb13u1
CVE-2026-15534: perl-base@5.40.1-6+deb13u1
CVE-2026-16742: libsystemd0@257.13-1~deb13u1
CVE-2026-16742: libudev1@257.13-1~deb13u1
CVE-2026-18374: libc-bin@2.41-12+deb13u4
CVE-2026-18374: libc6@2.41-12+deb13u4
CVE-2026-18477: tar@1.35+dfsg-3.1
CVE-2026-18495: libtiff6@4.7.0-3+deb13u3
CVE-2026-18508: tar@1.35+dfsg-3.1
CVE-2026-18938: libp11-kit0@0.25.5-3
CVE-2026-19542: libc-bin@2.41-12+deb13u4
CVE-2026-19542: libc6@2.41-12+deb13u4
CVE-2026-27171: zlib1g@1:1.3.dfsg+really1.3.1-1+b1
CVE-2026-3184: bsdutils@1:2.41.5-0+deb13u1
CVE-2026-3184: libblkid1@2.41.5-0+deb13u1
CVE-2026-3184: liblastlog2-2@2.41.5-0+deb13u1
CVE-2026-3184: libmount1@2.41.5-0+deb13u1
CVE-2026-3184: libsmartcols1@2.41.5-0+deb13u1
CVE-2026-3184: libuuid1@2.41.5-0+deb13u1
CVE-2026-3184: login@1:4.16.0-2+really2.41.5-0+deb13u1
CVE-2026-3184: mount@2.41.5-0+deb13u1
CVE-2026-3184: util-linux@2.41.5-0+deb13u1
CVE-2026-42250: libbz2-1.0@1.0.8-6
CVE-2026-50812: libsqlite3-0@3.46.1-7+deb13u2
CVE-2026-50813: libsqlite3-0@3.46.1-7+deb13u2
CVE-2026-54371: libattr1@1:2.5.2-3
CVE-2026-54411: libpam-modules-bin@1.7.0-5
CVE-2026-54411: libpam-modules@1.7.0-5
CVE-2026-54411: libpam-runtime@1.7.0-5
CVE-2026-54411: libpam0g@1.7.0-5
CVE-2026-5704: tar@1.35+dfsg-3.1
CVE-2026-58055: libnghttp2-14@1.64.0-1.1+deb13u1
CVE-2026-6238: libc-bin@2.41-12+deb13u4
CVE-2026-6238: libc6@2.41-12+deb13u4
CVE-2026-6791: libc-bin@2.41-12+deb13u4
CVE-2026-6791: libc6@2.41-12+deb13u4
CVE-2026-73066: libtesseract5@5.5.0-1+b1
CVE-2026-73066: tesseract-ocr@5.5.0-1+b1
CVE-2026-73067: libtesseract5@5.5.0-1+b1
CVE-2026-73067: tesseract-ocr@5.5.0-1+b1
CVE-2026-76781: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-77117: libc-bin@2.41-12+deb13u4
CVE-2026-77117: libc6@2.41-12+deb13u4
CVE-2026-80489: libc-bin@2.41-12+deb13u4
CVE-2026-80489: libc6@2.41-12+deb13u4
CVE-2026-8458: curl@8.14.1-2+deb13u5
CVE-2026-8458: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-86137: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-86469: libglib2.0-0t64@2.84.4-3~deb13u5
CVE-2026-8674: libc-bin@2.41-12+deb13u4
CVE-2026-8674: libc6@2.41-12+deb13u4
CVE-2026-86805: libc-bin@2.41-12+deb13u4
CVE-2026-86805: libc6@2.41-12+deb13u4
CVE-2026-88049: libtesseract5@5.5.0-1+b1
CVE-2026-88049: tesseract-ocr@5.5.0-1+b1
CVE-2026-88050: libtesseract5@5.5.0-1+b1
CVE-2026-88050: tesseract-ocr@5.5.0-1+b1
CVE-2026-88054: libtesseract5@5.5.0-1+b1
CVE-2026-88054: tesseract-ocr@5.5.0-1+b1
CVE-2026-89092: libc-bin@2.41-12+deb13u4
CVE-2026-89092: libc6@2.41-12+deb13u4
CVE-2026-94283: libx11-6@2:1.8.12-1
CVE-2026-94283: libx11-data@2:1.8.12-1
CVE-2026-94284: libx11-6@2:1.8.12-1
CVE-2026-94284: libx11-data@2:1.8.12-1
CVE-2026-94285: libx11-6@2:1.8.12-1
CVE-2026-94285: libx11-data@2:1.8.12-1
CVE-2026-95512: libfreetype6@2.13.3+dfsg-1+deb13u1

Low (16 unique rows)

CVE-2017-7475: libcairo2@1.18.4-1+b1
CVE-2019-6988: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2024-56433: login.defs@1:4.17.4-2
CVE-2024-56433: passwd@1:4.17.4-2
CVE-2025-50422: libcairo2@1.18.4-1+b1
CVE-2026-15028: libarchive13t64@3.7.4-4+deb13u1
CVE-2026-16517: libarchive13t64@3.7.4-4+deb13u1
CVE-2026-40228: libsystemd0@257.13-1~deb13u1
CVE-2026-40228: libudev1@257.13-1~deb13u1
CVE-2026-6368: libc-bin@2.41-12+deb13u4
CVE-2026-6368: libc6@2.41-12+deb13u4
CVE-2026-86141: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-95818: libc-bin@2.41-12+deb13u4
CVE-2026-95818: libc6@2.41-12+deb13u4
CVE-2026-97399: libc-bin@2.41-12+deb13u4
CVE-2026-97399: libc6@2.41-12+deb13u4

Unknown (1 unique rows)

CVE-2026-36849: libtiff6@4.7.0-3+deb13u3

Negligible (114 unique rows)

CVE-2005-2541: tar@1.35+dfsg-3.1
CVE-2007-5686: login.defs@1:4.17.4-2
CVE-2007-5686: passwd@1:4.17.4-2
CVE-2010-4756: libc-bin@2.41-12+deb13u4
CVE-2010-4756: libc6@2.41-12+deb13u4
CVE-2011-3374: apt@3.0.3
CVE-2011-3374: libapt-pkg7.0@3.0.3
CVE-2011-3389: libgnutls30t64@3.8.9-3+deb13u4
CVE-2011-4116: perl-base@5.40.1-6+deb13u1
CVE-2012-0039: libglib2.0-0t64@2.84.4-3~deb13u5
CVE-2013-4392: libsystemd0@257.13-1~deb13u1
CVE-2013-4392: libudev1@257.13-1~deb13u1
CVE-2015-3276: libldap2@2.6.10+dfsg-1
CVE-2016-10505: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9113: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9114: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9115: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9116: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9117: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9580: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2016-9581: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2017-14159: libldap2@2.6.10+dfsg-1
CVE-2017-16232: libtiff6@4.7.0-3+deb13u3
CVE-2017-17740: libldap2@2.6.10+dfsg-1
CVE-2017-18018: coreutils@9.7-3
CVE-2017-9937: libjbig0@2.1-6.1+b2
CVE-2018-10126: libtiff6@4.7.0-3+deb13u3
CVE-2018-16376: libopenjp2-7@2.5.3-2.1~deb13u2
CVE-2018-18064: libcairo2@1.18.4-1+b1
CVE-2018-20796: libc-bin@2.41-12+deb13u4
CVE-2018-20796: libc6@2.41-12+deb13u4
CVE-2018-5709: libgssapi-krb5-2@1.21.3-5+deb13u1
CVE-2018-5709: libk5crypto3@1.21.3-5+deb13u1
CVE-2018-5709: libkrb5-3@1.21.3-5+deb13u1
CVE-2018-5709: libkrb5support0@1.21.3-5+deb13u1
CVE-2019-1010022: libc-bin@2.41-12+deb13u4
CVE-2019-1010022: libc6@2.41-12+deb13u4
CVE-2019-1010023: libc-bin@2.41-12+deb13u4
CVE-2019-1010023: libc6@2.41-12+deb13u4
CVE-2019-1010024: libc-bin@2.41-12+deb13u4
CVE-2019-1010024: libc6@2.41-12+deb13u4
CVE-2019-1010025: libc-bin@2.41-12+deb13u4
CVE-2019-1010025: libc6@2.41-12+deb13u4
CVE-2019-9192: libc-bin@2.41-12+deb13u4
CVE-2019-9192: libc6@2.41-12+deb13u4
CVE-2020-15719: libldap2@2.6.10+dfsg-1
CVE-2021-4214: libpng16-16t64@1.6.48-1+deb13u6
CVE-2021-45346: libsqlite3-0@3.46.1-7+deb13u2
CVE-2022-0563: bsdutils@1:2.41.5-0+deb13u1
CVE-2022-0563: libblkid1@2.41.5-0+deb13u1
CVE-2022-0563: liblastlog2-2@2.41.5-0+deb13u1
CVE-2022-0563: libmount1@2.41.5-0+deb13u1
CVE-2022-0563: libsmartcols1@2.41.5-0+deb13u1
CVE-2022-0563: libuuid1@2.41.5-0+deb13u1
CVE-2022-0563: login@1:4.16.0-2+really2.41.5-0+deb13u1
CVE-2022-0563: mount@2.41.5-0+deb13u1
CVE-2022-0563: util-linux@2.41.5-0+deb13u1
CVE-2022-1210: libtiff6@4.7.0-3+deb13u3
CVE-2023-30571: libarchive13t64@3.7.4-4+deb13u1
CVE-2023-31437: libsystemd0@257.13-1~deb13u1
CVE-2023-31437: libudev1@257.13-1~deb13u1
CVE-2023-31438: libsystemd0@257.13-1~deb13u1
CVE-2023-31438: libudev1@257.13-1~deb13u1
CVE-2023-31439: libsystemd0@257.13-1~deb13u1
CVE-2023-31439: libudev1@257.13-1~deb13u1
CVE-2023-37769: libpixman-1-0@0.44.0-3
CVE-2023-39742: libgif7@5.2.2-1+deb13u1
CVE-2024-26458: libgssapi-krb5-2@1.21.3-5+deb13u1
CVE-2024-26458: libk5crypto3@1.21.3-5+deb13u1
CVE-2024-26458: libkrb5-3@1.21.3-5+deb13u1
CVE-2024-26458: libkrb5support0@1.21.3-5+deb13u1
CVE-2024-26461: libgssapi-krb5-2@1.21.3-5+deb13u1
CVE-2024-26461: libk5crypto3@1.21.3-5+deb13u1
CVE-2024-26461: libkrb5-3@1.21.3-5+deb13u1
CVE-2024-26461: libkrb5support0@1.21.3-5+deb13u1
CVE-2024-45993: libgif7@5.2.2-1+deb13u1
CVE-2025-10966: curl@8.14.1-2+deb13u5
CVE-2025-10966: libcurl4t64@8.14.1-2+deb13u5
CVE-2025-14017: curl@8.14.1-2+deb13u5
CVE-2025-14017: libcurl4t64@8.14.1-2+deb13u5
CVE-2025-15079: curl@8.14.1-2+deb13u5
CVE-2025-15079: libcurl4t64@8.14.1-2+deb13u5
CVE-2025-15224: curl@8.14.1-2+deb13u5
CVE-2025-15224: libcurl4t64@8.14.1-2+deb13u5
CVE-2025-25724: libarchive13t64@3.7.4-4+deb13u1
CVE-2025-31344: libgif7@5.2.2-1+deb13u1
CVE-2025-5278: coreutils@9.7-3
CVE-2025-60753: libarchive13t64@3.7.4-4+deb13u1
CVE-2025-61143: libtiff6@4.7.0-3+deb13u3
CVE-2025-61144: libtiff6@4.7.0-3+deb13u3
CVE-2025-61145: libtiff6@4.7.0-3+deb13u3
CVE-2025-70873: libsqlite3-0@3.46.1-7+deb13u2
CVE-2025-8176: libtiff6@4.7.0-3+deb13u3
CVE-2025-8177: libtiff6@4.7.0-3+deb13u3
CVE-2025-8534: libtiff6@4.7.0-3+deb13u3
CVE-2026-102473: dash@0.5.12-12
CVE-2026-102474: dash@0.5.12-12
CVE-2026-11850: libgssapi-krb5-2@1.21.3-5+deb13u1
CVE-2026-11850: libk5crypto3@1.21.3-5+deb13u1
CVE-2026-11850: libkrb5-3@1.21.3-5+deb13u1
CVE-2026-11850: libkrb5support0@1.21.3-5+deb13u1
CVE-2026-11979: libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3
CVE-2026-22185: libldap2@2.6.10+dfsg-1
CVE-2026-3713: libpng16-16t64@1.6.48-1+deb13u6
CVE-2026-52491: libtiff6@4.7.0-3+deb13u3
CVE-2026-52492: libtiff6@4.7.0-3+deb13u3
CVE-2026-53910: diffutils@1:3.10-4
CVE-2026-56391: coreutils@9.7-3
CVE-2026-56392: coreutils@9.7-3
CVE-2026-5745: libarchive13t64@3.7.4-4+deb13u1
CVE-2026-82208: curl@8.14.1-2+deb13u5
CVE-2026-82208: libcurl4t64@8.14.1-2+deb13u5
CVE-2026-9547: curl@8.14.1-2+deb13u5
CVE-2026-9547: libcurl4t64@8.14.1-2+deb13u5

License violations

libhogweed6t64@3.10.1-1 (Expat, GAP, GPL, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-or-later, LGPL, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-3.0-or-later, public-domain)
libpangoft2-1.0-0@1.56.3-1 (Bitstream-Vera, Chromium-BSD-style, Example, ICU, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, OFL-1.1, TCL, Unicode)
libfribidi0@1.0.16-1 (LGPL-2.1-only, LGPL-2.1-or-later)
libnettle8t64@3.10.1-1 (Expat, GAP, GPL, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-or-later, LGPL, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-3.0-or-later, public-domain)
liblastlog2-2@2.41.5-0+deb13u1 (BSD-4-Clause, BSLA, Expat, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or
libffi8@3.4.8-2 (Expat, GPL, GPL-2.0-or-later, GPL-3.0-or-later, MPL-1.1, X11, public-domain)
libgraphite2-3@1.3.14-2+deb13u1 (Artistic, GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, MPL-1.1, custom-sil-open-font-license, public-do
login.defs@1:4.17.4-2 (GPL-1.0-only, GPL-2.0-only, GPL-2.0-or-later)
libde265-0@1.0.15-1+deb13u2 (BSD-4-Clause, GPL-3.0-only, GPL-3.0-or-later, LGPL-3.0-only, LGPL-3.0-or-later, other-1, public-domain-1)
libpcre2-8-0@10.46-1~deb13u3 (BSD-3-clause-Cambridge, X11, public-domain)
fontconfig@2.15.0-2.3 (HPND-sell-variant)
libatomic1@14.2.0-19 (BSD-4-Clause-UC, GPL-3.0-or-later, HPND, LGPL-2.0-or-later, LGPL-2.1-or-later, NCSA, Spencer-94, Unicode-DFS-2015, Zlib)
libthai-data@0.1.29-2 (GPL-2.0-only, GPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later)
libapt-pkg7.0@3.0.3 (Expat, GPL-2.0-only, GPL-2.0-or-later, curl)
libthai0@0.1.29-2+b1 (GPL-2.0-only, GPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later)
libgnutls30t64@3.8.9-3+deb13u4 (CC0-1.0, FSFAP, GPL-3.0-or-later, LGPL-2.1-or-later)
openssl-provider-legacy@3.5.7-1~deb13u3 (Artistic, GPL-1.0-only, GPL-1.0-or-later)
libgomp1@14.2.0-19 (BSD-4-Clause-UC, GPL-3.0-or-later, HPND, LGPL-2.0-or-later, LGPL-2.1-or-later, NCSA, Spencer-94, Unicode-DFS-2015, Zlib)
libunistring5@1.3-2 (FreeSoftware, GFDL-1.2-or-later, GFDL-1.3-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGP
libldap2@2.6.10+dfsg-1 (BSD-3-clause-California, BSD-3-clause-variant, BSD-4-clause-California, Beerware, Expat, Expat-ISC, Expat-UNM, F5, FSF-unlimited, GPL-2.0-only, GPL-2.0-or-later, GPL
libglib2.0-0t64@2.84.4-3~deb13u5 (AFL-2.0, CC-BY-SA-3.0, CC0-1.0, Expat, FSFULLR, GPL-2.0-only, GPL-2.0-or-later, Iconv-PD, Janik-permissive, Kuchling-PD, LGPL-2.0-only, LGPL-2.0-or-later, 
libopenjp2-7@2.5.3-2.1~deb13u2 (BSD-2, BSD-3, Libpng, libtiff, LIBTIFF-GLARSON, LIBTIFF-PIXAR, Zlib)
libssh2-1t64@1.11.1-1+deb13u2 (BSD3)
libpango-1.0-0@1.56.3-1 (Bitstream-Vera, Chromium-BSD-style, Example, ICU, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, OFL-1.1, TCL, Unicode)
libcurl4t64@8.14.1-2+deb13u5 (BSD-4-Clause-UC, FSFULLR, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-or-later, OLDAP-2.8, X11, curl)
libpsl5t64@0.21.2-1.1+b1 (Chromium, gnulib)
libarchive13t64@3.7.4-4+deb13u1 (BSD-1-clause-UCB, BSD-124-clause-UCB, BSD-3-clause-UCB, BSD-4-clause-UCB, CC0-1.0, Expat, OpenSSL+SSLeay, PD)
libx265-215@4.1-2 (Expat, GPL-2.0-only, GPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later)
libdebconfclient0@0.280 (GPL-2.0-only, GPL-2.0-or-later)
libpng16-16t64@1.6.48-1+deb13u6 (BSD-like-with-advertising-clause, GPL-2.0-only, GPL-2.0-or-later, expat, Libpng)
gcc-14-base@14.2.0-19 (BSD-4-Clause-UC, GPL-3.0-or-later, HPND, LGPL-2.0-or-later, LGPL-2.1-or-later, NCSA, Spencer-94, Unicode-DFS-2015, Zlib)
libjpeg62-turbo@1:2.1.5-4 (BSD-BY-LC-NE, Expat, NTP, Zlib)
libdatrie1@0.2.13-3+b1 (GPL-2.0-only, GPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later)
sqv@1.3.0-3+b2 (LGPL-2.0-only, LGPL-2.0-or-later)
libnghttp3-9@1.8.0-1 (FSFAP, FSFUL, FSFULLR, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later)
libpangocairo-1.0-0@1.56.3-1 (Bitstream-Vera, Chromium-BSD-style, Example, ICU, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, OFL-1.1, TCL, Unicode)
fonts-dejavu-mono@2.37-8 (GPL-2.0-only, GPL-2.0-or-later, Bitstream-Vera)
libtiff6@4.7.0-3+deb13u3 (Hylafax)
libdav1d7@1.5.1-1 (public-domain)
libnuma1@2.0.19-1 (GPL-2.0-or-later)
debian-archive-keyring@2025.1 (GPL-2.0-or-later)
libicu76@76.1-4 (GPL-3.0-only)
libdb5.3t64@5.3.28+dfsg2-9 (Artistic, BSD-3-clause-fjord, GPL, GPL-3.0-only, MIT-old, MS-PL, Sleepycat, TCL-like, X11, Zlib)
libharfbuzz0b@10.2.0-1+deb13u1 (CC0-1.0, Expat, FSFAP, FSFUL, FSFULLR, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, Monotype, OFL-1.1, U
tini@0.19.0-3+b8 (Expat)
libssl3t64@3.5.7-1~deb13u3 (Artistic, GPL-1.0-only, GPL-1.0-or-later)
libaom3@3.12.1-1+deb13u1 (Expat, public-domain-md5)

Remediation SLA and next actions

  • Critical findings: remediate or explicitly risk-accept (maintainer approval required) within 7 days. High: within 30 days. Every scanned image is rebuilt on a refreshed base image at least weekly.
  • This workflow runs gh aw compile --force-refresh-container-pins daily; a pin-refresh PR is the default remediation step.
  • Upstream — tracked only: no code-fix PR is requested here and the image is not patched in this repo. Fixes land in the owning project; the daily pin refresh picks them up once released. Where a fixed package version is listed, the image version/digest containing it is not yet identified in this scan; where none is listed, no fix is recorded by the scanner. Exceptions are not risk-accepted without maintainer approval.
  • Exception record for every finding without a fixed image: responsible project = the image owner above; advisory = per-CVE link from the distro/GHSA tracker (CVE/GHSA ID is the lookup key); next review = 2026-10-16 (weekly pin refresh).
  • Source: Daily Container Image Security Scan, run 37889440852 (2026-10-09). Counts are scanner package rows.

Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 213.1 AIC · ⌖ 0.804 AIC · ⊞ 8.5K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions