Skip to content

[container-image-scan] grafana/mcp-grafana CVE burn-down #65797

Description

@github-actions

Overview

grafana/mcp-grafana family, scan of 2026-10-11. Owner: grafana/mcp-grafana (third party, Upstream — tracked only).

Image (pinned) Status Crit High Med Low Negl Unk License
grafana/mcp-grafana:1.1.0-alpine@sha256:e0eb29cdf8effbbebf115ea99a5f654a44681dfd293661b0991498d651ca6cb4 upstream 6 34 14 11 0 4 0

Counts are raw scanner rows. Details list [severity] ID: package@installed (fix: fixed versions), Critical first. License status: clean.

Details

Findings: graf (Critical, High, Medium, Low, Unknown; one row per CVE and package)
[Critical] CVE-2026-63073: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[Critical] CVE-2026-63073: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[Critical] CVE-2026-75803: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[Critical] CVE-2026-75803: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[Critical] GO-2026-6612: golang.org/x/net@v0.55.0 (fix: 0.60.0)
[Critical] GO-2026-6612: stdlib@go1.26.5 (fix: 1.26.9)
[High] CVE-2026-14456: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-14456: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-14457: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-14457: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-18798: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-18798: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-54873: libcrypto3@3.5.7-r0
[High] CVE-2026-54873: libssl3@3.5.7-r0
[High] CVE-2026-54874: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-54874: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-63072: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-63072: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-63075: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-63075: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-63076: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-63076: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[High] CVE-2026-72897: libcrypto3@3.5.7-r0
[High] CVE-2026-72897: libssl3@3.5.7-r0
[High] CVE-2026-84782: libcrypto3@3.5.7-r0
[High] CVE-2026-84782: libssl3@3.5.7-r0
[High] CVE-2026-84784: libcrypto3@3.5.7-r0
[High] CVE-2026-84784: libssl3@3.5.7-r0
[High] CVE-2026-85091: zlib@1.3.2-r0 (fix: 1.3.2-r1)
[High] GHSA-2v4p-qf9q-27wj: google.golang.org/grpc@v1.80.0 (fix: 1.82.2)
[High] GHSA-vp52-pcj8-j9qc: google.golang.org/grpc@v1.80.0 (fix: 1.83.1)
[High] GO-2026-6603: golang.org/x/net@v0.55.0 (fix: 0.60.0)
[High] GO-2026-6603: stdlib@go1.26.5 (fix: 1.26.9)
[High] GO-2026-6605: stdlib@go1.26.5 (fix: 1.26.9, 1.27.2)
[High] GO-2026-6607: stdlib@go1.26.5 (fix: 1.26.9, 1.27.2)
[High] GO-2026-6608: stdlib@go1.26.5 (fix: 1.26.9, 1.27.2)
[High] GO-2026-6610: stdlib@go1.26.5 (fix: 1.26.9)
[High] GO-2026-6611: golang.org/x/net@v0.55.0 (fix: 0.60.0)
[High] GO-2026-6611: stdlib@go1.26.5 (fix: 1.26.9)
[High] GO-2026-6613: stdlib@go1.26.5 (fix: 1.26.9, 1.27.2)
[Medium] CVE-2026-35189: libcrypto3@3.5.7-r0
[Medium] CVE-2026-35189: libssl3@3.5.7-r0
[Medium] CVE-2026-42772: libcrypto3@3.5.7-r0
[Medium] CVE-2026-42772: libssl3@3.5.7-r0
[Medium] CVE-2026-63074: libcrypto3@3.5.7-r0 (fix: 3.5.8-r0)
[Medium] CVE-2026-63074: libssl3@3.5.7-r0 (fix: 3.5.8-r0)
[Medium] CVE-2026-75804: libcrypto3@3.5.7-r0
[Medium] CVE-2026-75804: libssl3@3.5.7-r0
[Medium] CVE-2026-75805: libcrypto3@3.5.7-r0
[Medium] CVE-2026-75805: libssl3@3.5.7-r0
[Medium] CVE-2026-75806: libcrypto3@3.5.7-r0
[Medium] CVE-2026-75806: libssl3@3.5.7-r0
[Medium] GHSA-hjf4-fphr-2h65: go.opentelemetry.io/otel/sdk/log@v0.19.0 (fix: 0.21.0)
[Medium] GHSA-w34q-cm8f-9c5x: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc@v0.19.0 (fix: 0.21.0)
[Low] CVE-2026-35191: libcrypto3@3.5.7-r0
[Low] CVE-2026-35191: libssl3@3.5.7-r0
[Low] CVE-2026-54872: libcrypto3@3.5.7-r0
[Low] CVE-2026-54872: libssl3@3.5.7-r0
[Low] CVE-2026-54875: libcrypto3@3.5.7-r0
[Low] CVE-2026-54875: libssl3@3.5.7-r0
[Low] CVE-2026-77696: libcrypto3@3.5.7-r0
[Low] CVE-2026-77696: libssl3@3.5.7-r0
[Low] GHSA-8wmf-6v46-5gfg: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.42.0 (fix: 1.45.0)
[Low] GHSA-8wmf-6v46-5gfg: go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.42.0 (fix: 1.45.0)
[Low] GHSA-8wmf-6v46-5gfg: go.opentelemetry.io/otel/sdk@v1.43.0 (fix: 1.45.0)
[Unknown] GO-2026-6599: stdlib@go1.26.5 (fix: 1.26.9, 1.27.2)
[Unknown] GO-2026-6600: stdlib@go1.26.5 (fix: 1.26.9, 1.27.2)
[Unknown] GO-2026-6617: golang.org/x/net@v0.55.0 (fix: 0.60.0)
[Unknown] GO-2026-6617: stdlib@go1.26.5 (fix: 1.26.9)

Negligible (IDs only):

Remediation and SLA

  • Cadence: Critical findings are remediated or explicitly risk-accepted within 7 days; High within 30 days; every scanned image is rebuilt on a refreshed base image at least weekly.
  • Default step: the daily gh aw compile --force-refresh-container-pins run opens a pin-refresh PR once the owner publishes a fixed image. No local code-fix PR is requested: the build config for these images is not in github/gh-aw.
  • Fixed package versions in the details identify what the upstream rebuild must contain. No fixed image tag/digest is known yet and none is invented here.
  • Exception (rows with no fix listed): responsible project = owner named above; advisory = scanner URL for the CVE/GHSA/GO id; next review = 2026-10-18; status = tracked, not risk-accepted (no maintainer approval recorded).
  • Every finding is Upstream — tracked only. License rows need a maintainer policy decision (allow-list or upstream change).

Index: #52657

Generated by 🛡️ Daily Container Image Security Scan · copilot · auto · 237.6 AIC · ⌖ 1.03 AIC · ⊞ 8.5K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions