CVE-2021-31879: wget@1.25.0-2
CVE-2025-12781: python@3.11.15 (fix: 3.13.10, 3.14.1, 3.15.0a2)
CVE-2025-15366: python@3.11.15 (fix: 3.13.15, 3.14.7, 3.15.0a6)
CVE-2025-15367: python@3.11.15 (fix: 3.15.0a6)
CVE-2025-15649: libperl5.40@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2025-15649: perl-base@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2025-15649: perl-modules-5.40@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2025-15649: perl@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2025-55132: node@22.18.0 (fix: 20.20.0, 22.22.0, 24.13.0, 25.3.0)
CVE-2025-6141: libncursesw6@6.5+20250216-2
CVE-2025-6141: libtinfo6@6.5+20250216-2
CVE-2025-6141: ncurses-base@6.5+20250216-2
CVE-2025-6141: ncurses-bin@6.5+20250216-2
CVE-2025-66382: libexpat1@2.8.2-1~deb13u1
CVE-2026-0864: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.15, 3.14.7, 3.15.0b4)
CVE-2026-102633: libexpat1@2.8.2-1~deb13u1
CVE-2026-12003: python@3.11.15 (fix: 3.11.16, 3.12.14, 3.13.15, 3.14.7, 3.15.0b3)
CVE-2026-12345: python@3.11.15 (fix: 3.15.0)
CVE-2026-13595: bsdutils@1:2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: libblkid1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: liblastlog2-2@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: libmount1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: libsmartcols1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: libuuid1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: login@1:4.16.0-2+really2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: mount@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13595: util-linux@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-13757: libp11-kit0@0.25.5-3
CVE-2026-1502: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.14, 3.14.5rc1, 3.15.0b1)
CVE-2026-15059: libsystemd-shared@257.13-1~deb13u1
CVE-2026-15059: libsystemd0@257.13-1~deb13u1
CVE-2026-15059: libudev1@257.13-1~deb13u1
CVE-2026-15059: systemd@257.13-1~deb13u1
CVE-2026-15146: wget@1.25.0-2
CVE-2026-15534: libperl5.40@5.40.1-6
CVE-2026-15534: perl-base@5.40.1-6
CVE-2026-15534: perl-modules-5.40@5.40.1-6
CVE-2026-15534: perl@5.40.1-6
CVE-2026-15806: python@3.11.15 (fix: 3.10.22, 3.11.17, 3.12.15, 3.13.16, 3.14.8, 3.15.0rc2)
CVE-2026-16742: libsystemd-shared@257.13-1~deb13u1
CVE-2026-16742: libsystemd0@257.13-1~deb13u1
CVE-2026-16742: libudev1@257.13-1~deb13u1
CVE-2026-16742: systemd@257.13-1~deb13u1
CVE-2026-17084: python@3.11.15 (fix: 3.10.22, 3.11.17, 3.12.15, 3.13.16, 3.14.8, 3.15.0rc2)
CVE-2026-18374: libc-bin@2.41-12+deb13u3
CVE-2026-18374: libc-dev-bin@2.41-12+deb13u3
CVE-2026-18374: libc6-dev@2.41-12+deb13u3
CVE-2026-18374: libc6@2.41-12+deb13u3
CVE-2026-18477: tar@1.35+dfsg-3.1
CVE-2026-18508: tar@1.35+dfsg-3.1
CVE-2026-18938: libp11-kit0@0.25.5-3
CVE-2026-19487: libperl5.40@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-19487: perl-base@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-19487: perl-modules-5.40@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-19487: perl@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-19542: libc-bin@2.41-12+deb13u3
CVE-2026-19542: libc-dev-bin@2.41-12+deb13u3
CVE-2026-19542: libc6-dev@2.41-12+deb13u3
CVE-2026-19542: libc6@2.41-12+deb13u3
CVE-2026-19672: python@3.11.15 (fix: 3.10.22, 3.11.17, 3.12.15, 3.13.16, 3.14.8, 3.15.0rc2)
CVE-2026-21713: node@22.18.0 (fix: 20.20.2, 22.22.2, 24.14.1, 25.8.2)
CVE-2026-21714: node@22.18.0 (fix: 20.20.2, 22.22.2, 24.14.1, 25.8.2)
CVE-2026-21717: node@22.18.0 (fix: 20.20.2, 22.22.2, 24.14.1, 25.8.2)
CVE-2026-2297: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.13, 3.14.4, 3.15.0a7)
CVE-2026-27171: zlib1g@1:1.3.dfsg+really1.3.1-1+b1
CVE-2026-27456: bsdutils@1:2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: libblkid1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: liblastlog2-2@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: libmount1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: libsmartcols1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: libuuid1@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: login@1:4.16.0-2+really2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: mount@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-27456: util-linux@2.41-5 (fix: 2.41.5-0+deb13u1)
CVE-2026-3184: bsdutils@1:2.41-5
CVE-2026-3184: libblkid1@2.41-5
CVE-2026-3184: liblastlog2-2@2.41-5
CVE-2026-3184: libmount1@2.41-5
CVE-2026-3184: libsmartcols1@2.41-5
CVE-2026-3184: libuuid1@2.41-5
CVE-2026-3184: login@1:4.16.0-2+really2.41-5
CVE-2026-3184: mount@2.41-5
CVE-2026-3184: util-linux@2.41-5
CVE-2026-3276: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.14, 3.14.6, 3.15.0b2)
CVE-2026-3446: python@3.11.15 (fix: 3.13.13, 3.14.4, 3.15.0a8)
CVE-2026-35189: libssl3t64@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-35189: openssl-provider-legacy@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-35189: openssl@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-41991: gzip@1.13-1 (fix: 1.13-1+deb13u1)
CVE-2026-42250: bzip2@1.0.8-6
CVE-2026-42250: libbz2-1.0@1.0.8-6
CVE-2026-42772: libssl3t64@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-42772: openssl-provider-legacy@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-42772: openssl@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-4360: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.15, 3.14.7, 3.15.0b4)
CVE-2026-50812: libsqlite3-0@3.46.1-7+deb13u1
CVE-2026-50813: libsqlite3-0@3.46.1-7+deb13u1
CVE-2026-54371: libattr1@1:2.5.2-3
CVE-2026-54411: libpam-modules-bin@1.7.0-5
CVE-2026-54411: libpam-modules@1.7.0-5
CVE-2026-54411: libpam-runtime@1.7.0-5
CVE-2026-54411: libpam0g@1.7.0-5
CVE-2026-56847: node@22.18.0 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-56850: node@22.18.0 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-5704: tar@1.35+dfsg-3.1
CVE-2026-58040: node@22.18.0 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-58041: node@22.18.0 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-58042: node@22.18.0 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-58045: node@22.18.0 (fix: 22.23.2, 24.18.1, 26.5.1)
CVE-2026-58055: libnghttp2-14@1.64.0-1.1+deb13u1
CVE-2026-58470: wget@1.25.0-2
CVE-2026-59995: openssh-client@1:10.0p1-7+deb13u4
CVE-2026-59995: openssh-server@1:10.0p1-7+deb13u4
CVE-2026-59995: openssh-sftp-server@1:10.0p1-7+deb13u4
CVE-2026-59995: ssh@1:10.0p1-7+deb13u4
CVE-2026-59996: openssh-client@1:10.0p1-7+deb13u4
CVE-2026-59996: openssh-server@1:10.0p1-7+deb13u4
CVE-2026-59996: openssh-sftp-server@1:10.0p1-7+deb13u4
CVE-2026-59996: ssh@1:10.0p1-7+deb13u4
CVE-2026-59997: openssh-client@1:10.0p1-7+deb13u4
CVE-2026-59997: openssh-server@1:10.0p1-7+deb13u4
CVE-2026-59997: openssh-sftp-server@1:10.0p1-7+deb13u4
CVE-2026-59997: ssh@1:10.0p1-7+deb13u4
CVE-2026-59998: openssh-client@1:10.0p1-7+deb13u4
CVE-2026-59998: openssh-server@1:10.0p1-7+deb13u4
CVE-2026-59998: openssh-sftp-server@1:10.0p1-7+deb13u4
CVE-2026-59998: ssh@1:10.0p1-7+deb13u4
CVE-2026-60001: openssh-client@1:10.0p1-7+deb13u4
CVE-2026-60001: openssh-server@1:10.0p1-7+deb13u4
CVE-2026-60001: openssh-sftp-server@1:10.0p1-7+deb13u4
CVE-2026-60001: ssh@1:10.0p1-7+deb13u4
CVE-2026-6019: python@3.11.15 (fix: 3.13.14, 3.14.5rc1, 3.15.0b1)
CVE-2026-6238: libc-bin@2.41-12+deb13u3
CVE-2026-6238: libc-dev-bin@2.41-12+deb13u3
CVE-2026-6238: libc6-dev@2.41-12+deb13u3
CVE-2026-6238: libc6@2.41-12+deb13u3
CVE-2026-63074: libssl3t64@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u2)
CVE-2026-63074: openssl-provider-legacy@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u2)
CVE-2026-63074: openssl@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u2)
CVE-2026-6791: libc-bin@2.41-12+deb13u3
CVE-2026-6791: libc-dev-bin@2.41-12+deb13u3
CVE-2026-6791: libc6-dev@2.41-12+deb13u3
CVE-2026-6791: libc6@2.41-12+deb13u3
CVE-2026-7010: libperl5.40@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-7010: perl-base@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-7010: perl-modules-5.40@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-7010: perl@5.40.1-6 (fix: 5.40.1-6+deb13u1)
CVE-2026-72522: libexpat1@2.8.2-1~deb13u1 (fix: 2.8.3-1~deb13u1)
CVE-2026-73282: openssh-client@1:10.0p1-7+deb13u4
CVE-2026-73282: openssh-server@1:10.0p1-7+deb13u4
CVE-2026-73282: openssh-sftp-server@1:10.0p1-7+deb13u4
CVE-2026-73282: ssh@1:10.0p1-7+deb13u4
CVE-2026-75804: libssl3t64@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75804: openssl-provider-legacy@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75804: openssl@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75805: libssl3t64@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75805: openssl-provider-legacy@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75805: openssl@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75806: libssl3t64@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75806: openssl-provider-legacy@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-75806: openssl@3.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u3)
CVE-2026-77117: libc-bin@2.41-12+deb13u3
CVE-2026-77117: libc-dev-bin@2.41-12+deb13u3
CVE-2026-77117: libc6-dev@2.41-12+deb13u3
CVE-2026-77117: libc6@2.41-12+deb13u3
CVE-2026-7774: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.14, 3.14.6, 3.15.0b2)
CVE-2026-80489: libc-bin@2.41-12+deb13u3
CVE-2026-80489: libc-dev-bin@2.41-12+deb13u3
CVE-2026-80489: libc6-dev@2.41-12+deb13u3
CVE-2026-80489: libc6@2.41-12+deb13u3
CVE-2026-8328: python@3.11.15 (fix: 3.10.21, 3.11.16, 3.12.14, 3.13.14, 3.14.6, 3.15.0b2)
CVE-2026-8458: curl@8.14.1-2+deb13u4
CVE-2026-8458: libcurl3t64-gnutls@8.14.1-2+deb13u4
CVE-2026-8458: libcurl4t64@8.14.1-2+deb13u4
CVE-2026-8674: libc-bin@2.41-12+deb13u3
CVE-2026-8674: libc-dev-bin@2.41-12+deb13u3
CVE-2026-8674: libc6-dev@2.41-12+deb13u3
CVE-2026-8674: libc6@2.41-12+deb13u3
CVE-2026-86805: libc-bin@2.41-12+deb13u3
CVE-2026-86805: libc-dev-bin@2.41-12+deb13u3
CVE-2026-86805: libc6-dev@2.41-12+deb13u3
CVE-2026-86805: libc6@2.41-12+deb13u3
CVE-2026-87910: python@3.11.15 (fix: 3.10.22, 3.11.17, 3.12.15, 3.13.16, 3.15.0)
CVE-2026-89092: libc-bin@2.41-12+deb13u3
CVE-2026-89092: libc-dev-bin@2.41-12+deb13u3
CVE-2026-89092: libc6-dev@2.41-12+deb13u3
CVE-2026-89092: libc6@2.41-12+deb13u3
CVE-2026-89156: libpcre2-8-0@10.46-1~deb13u1 (fix: 10.46-1~deb13u2)
CVE-2026-89158: libpcre2-8-0@10.46-1~deb13u1 (fix: 10.46-1~deb13u2)
CVE-2026-89160: libpcre2-8-0@10.46-1~deb13u1 (fix: 10.46-1~deb13u2)
GHSA-2gx3-rcp4-g85q: pyjwt@2.13.0 (fix: 2.14.0)
GHSA-2mjx-qc3c-rqvc: rustls@0.23.42 (fix: 0.23.45)
GHSA-3v7f-55p6-f55p: picomatch@4.0.2 (fix: 4.0.4)
GHSA-42vr-xj54-vc7v: pyjwt@2.13.0 (fix: 2.15.0)
GHSA-4xh5-x5gv-qwph: pip@24.0 (fix: 25.3)
GHSA-58qw-9mgm-455v: pip@24.0 (fix: 26.1)
GHSA-8wjv-2p76-3863: pyjwt@2.13.0 (fix: 2.14.0)
GHSA-f886-m6hf-6m8v: brace-expansion@2.0.2 (fix: 2.0.3)
GHSA-g6x2-hccm-hh4m: werkzeug@3.1.7 (fix: 3.1.9)
GHSA-gh4c-6fx4-qh6g: urllib3@2.7.0 (fix: 2.8.0)
GHSA-gvp8-978c-rx2q: pyjwt@2.13.0
GHSA-gvwx-54wh-qm9j: tar@6.2.1 (fix: 7.5.17)
GHSA-gvwx-54wh-qm9j: tar@7.4.3 (fix: 7.5.17)
GHSA-h35f-9h28-mq5c: setuptools@79.0.1 (fix: 83.0.0)
GHSA-h3mg-xc3c-68pw: ip-address@9.0.5 (fix: 10.7.1)
GHSA-hp3w-g68c-fv3c: sprintf-js@1.1.3
GHSA-hxm8-2xgr-2p9m: pyjwt@2.13.0 (fix: 2.14.0)
GHSA-j6r3-76f7-8jcv: ip-address@9.0.5 (fix: 10.7.1)
GHSA-jfc7-64v2-mr8c: @sigstore/core@2.0.0 (fix: 3.2.1)
GHSA-jp4c-xjxw-mgf9: pip@24.0 (fix: 26.1)
GHSA-jwrc-g2q2-pq5p: pyjwt@2.13.0 (fix: 2.14.0)
GHSA-q2hr-2g5m-vwhr: brace-expansion@2.0.2 (fix: 2.1.7)
GHSA-qwm4-qh6w-59xr: pip@24.0 (fix: 26.2.0)
GHSA-rj75-hqrm-r3gf: postcss-selector-parser@7.1.0 (fix: 7.1.6)
GHSA-rpw4-54j3-4h4q: ip-address@9.0.5 (fix: 10.5.1)
GHSA-v2v4-37r5-5v8g: ip-address@9.0.5 (fix: 10.1.1)
GHSA-vmf3-w455-68vh: tar@6.2.1 (fix: 7.5.16)
GHSA-vmf3-w455-68vh: tar@7.4.3 (fix: 7.5.16)
GHSA-w6j9-cwv2-h6wq: pyjwt@2.13.0 (fix: 2.14.0)
GHSA-w8wr-v893-vjvp: tar@6.2.1 (fix: 7.5.18)
GHSA-w8wr-v893-vjvp: tar@7.4.3 (fix: 7.5.18)
GHSA-wf93-45jw-7689: pip@24.0 (fix: 26.1.2)
GHSA-x33g-cr3x-6449: pyjwt@2.13.0 (fix: 2.15.0)
Serena scan summary
Status: upstream (oraios/serena), tracked only. Scan run 37577104450 (2026-10-07). 14 Critical, 296 High, 237 Medium, 57 Low, 37 Unknown, 721 Negligible (scanner rows); 0 license violations.
ghcr.io/oraios/serena:1.7.0@sha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730Remediation SLA and guidance
gh aw compile --force-refresh-container-pins; the resulting pin-refresh PR is the default remediation step.Critical
High
Medium
Low
Unknown
Negligible