Skip to content

Weekly audit refresh: 32000254350 - #63

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh
Open

Weekly audit refresh: 32000254350#63
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

CVE delta

Net change

Severity Added Removed Net
Critical 0 0 0
High 212 1 +211
Medium 856 8 +848
Low 113 3 +110

Changed images: 33 of 44

Per-image detail

adguard-adguardhome-v0.107.76

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

baserow-baserow-2.2.2

  • Added: C:0 H:8 M:6 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-58050 (HIGH) — libssh2-1t64
      • ...and 6 more

deluan-navidrome-0.61.2

  • Added: C:0 H:7 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-42500 (MEDIUM) — golang.org/x/image

docker.io-caddy-2.11.3

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

docker.io-library-postgres-18.4-alpine3.23

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-39821 (HIGH) — stdlib
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

docker.io-louislam-uptime-kuma-2.3.2

  • Added: C:0 H:45 M:9 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-19137 (HIGH) — chromium
      • CVE-2026-19138 (HIGH) — chromium
      • CVE-2026-19140 (HIGH) — chromium
      • CVE-2026-19141 (HIGH) — chromium
      • CVE-2026-19142 (HIGH) — chromium
      • CVE-2026-19143 (HIGH) — chromium
      • CVE-2026-19144 (HIGH) — chromium
      • CVE-2026-19145 (HIGH) — chromium
      • ...and 46 more
    • [FIXED]:
      • CVE-2026-9375 (MEDIUM) — python3-urllib3

docker.io-mariadb-12.2.2

  • Added: C:0 H:7 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-39821 (HIGH) — stdlib
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • ...and 1 more

docker.io-mongo-8.3.2

  • Added: C:0 H:7 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • ...and 1 more

docuseal-docuseal-3.0.0

  • Added: C:0 H:0 M:2 L:1
  • Removed: C:0 H:0 M:2 L:1
    • [NEW]:
      • CVE-2026-73490 (MEDIUM) — loofah
      • CVE-2026-73648 (MEDIUM) — rails-html-sanitizer
      • CVE-2026-73491 (LOW) — loofah
    • [FIXED]:
      • GHSA-9wjq-cp2p-hrgf (MEDIUM) — loofah
      • GHSA-cj75-f6xr-r4g7 (MEDIUM) — rails-html-sanitizer
      • GHSA-8whx-365g-h9vv (LOW) — loofah

fnsys-dockhand-v1.0.29

  • Added: C:0 H:8 M:19 L:11
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-45447 (HIGH) — libcrypto3
      • CVE-2026-56408 (HIGH) — libexpat1
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • ...and 30 more

freshrss-freshrss-1.29.1-alpine

  • Added: C:0 H:1 M:3 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-34191 (HIGH) — apr-util
      • CVE-2026-32327 (MEDIUM) — apr-util
      • CVE-2026-34501 (MEDIUM) — apr-util
      • CVE-2026-34502 (MEDIUM) — apr-util
      • CVE-2025-49506 (LOW) — apr-util

ghcr.io-goauthentik-server-2026.2.3

  • Added: C:0 H:32 M:257 L:54
  • Removed: C:0 H:0 M:1 L:1
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-58050 (HIGH) — libssh2-1t64
      • ...and 335 more
    • [FIXED]:
      • CVE-2026-46194 (MEDIUM) — linux-libc-dev
      • CVE-2026-63872 (LOW) — linux-libc-dev

ghcr.io-open-webui-open-webui-0.9.5

  • Added: C:0 H:20 M:196 L:44
  • Removed: C:0 H:0 M:1 L:1
    • [NEW]:
      • CVE-2026-12243 (HIGH) — nltk
      • CVE-2026-29036 (HIGH) — libcjson1
      • CVE-2026-58050 (HIGH) — libssh2-1
      • CVE-2026-68099 (HIGH) — linux-libc-dev
      • CVE-2026-68123 (HIGH) — linux-libc-dev
      • CVE-2026-68136 (HIGH) — linux-libc-dev
      • CVE-2026-68140 (HIGH) — linux-libc-dev
      • CVE-2026-68144 (HIGH) — linux-libc-dev
      • ...and 252 more
    • [FIXED]:
      • CVE-2023-52485 (MEDIUM) — linux-libc-dev
      • CVE-2026-63872 (LOW) — linux-libc-dev

ghcr.io-stoatchat-api-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-crond-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-events-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-file-server-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-gifbox-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-livekit-server-v1.9.13

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

ghcr.io-stoatchat-proxy-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-pushd-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-stoatchat-voice-ingress-v0.13.6

  • Added: C:0 H:0 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-14456 (MEDIUM) — libssl3
      • CVE-2026-6368 (MEDIUM) — libc6
      • CVE-2026-6791 (MEDIUM) — libc6

ghcr.io-wg-easy-wg-easy-15.3.0

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

ghcr.io-ylianst-meshcentral-1.1.59-mongodb

  • Added: C:0 H:0 M:4 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-58041 (MEDIUM) — nodejs
      • CVE-2026-58042 (MEDIUM) — nodejs
      • CVE-2026-58044 (MEDIUM) — nodejs
      • CVE-2026-58045 (MEDIUM) — nodejs

ghcr.io-zulip-zulip-server-12.0-0

  • Added: C:0 H:7 M:318 L:0
  • Removed: C:0 H:0 M:3 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-15059 (MEDIUM) — libsystemd-shared
      • ...and 317 more
    • [FIXED]:
      • CVE-2026-46194 (MEDIUM) — linux-libc-dev
      • CVE-2026-63872 (MEDIUM) — linux-libc-dev
      • CVE-2026-9375 (MEDIUM) — python3-pip

lscr.io-linuxserver-jellyfin-10.11.9

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • CVE-2026-16742 (MEDIUM) — libsystemd0

mongo-8.3.2

  • Added: C:0 H:7 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • ...and 1 more

n8nio-runners-2.22.1

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-39821 (HIGH) — stdlib
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

postgres-18.4

  • Added: C:0 H:7 M:3 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-39821 (HIGH) — stdlib
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib
      • CVE-2026-14456 (MEDIUM) — libssl3t64
      • ...and 2 more

qbittorrentofficial-qbittorrent-nox-5.2.0-1

  • Added: C:0 H:6 M:4 L:2
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11940 (HIGH) — pyc
      • CVE-2026-15308 (HIGH) — pyc
      • CVE-2026-3644 (HIGH) — pyc
      • CVE-2026-4786 (HIGH) — pyc
      • CVE-2026-6100 (HIGH) — pyc
      • CVE-2026-7210 (HIGH) — pyc
      • CVE-2026-0864 (MEDIUM) — pyc
      • CVE-2026-11972 (MEDIUM) — pyc
      • ...and 4 more

rabbitmq-4.3.0

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-15059 (MEDIUM) — libsystemd0
      • CVE-2026-16742 (MEDIUM) — libsystemd0

syncthing-syncthing-2.1.0

  • Added: C:0 H:7 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33818 (HIGH) — stdlib
      • CVE-2026-46600 (HIGH) — golang.org/x/net
      • CVE-2026-56853 (HIGH) — stdlib
      • CVE-2026-56858 (HIGH) — stdlib
      • CVE-2026-56859 (HIGH) — stdlib
      • CVE-2026-56860 (HIGH) — stdlib
      • CVE-2026-56862 (HIGH) — stdlib

towfiqi-serpbear-3.1.0

  • Added: C:0 H:1 M:0 L:0
  • Removed: C:0 H:1 M:0 L:0
    • [NEW]:
      • CVE-2026-73646 (HIGH) — postcss
    • [FIXED]:
      • GHSA-r28c-9q8g-f849 (HIGH) — postcss

@github-actions
github-actions Bot enabled auto-merge (squash) June 15, 2026 07:46
@github-actions github-actions Bot changed the title Weekly audit refresh: 27531642510 Weekly audit refresh: 27937554468 Jun 22, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch 2 times, most recently from b731738 to ee0b4cb Compare June 29, 2026 07:31
@github-actions github-actions Bot changed the title Weekly audit refresh: 27937554468 Weekly audit refresh: 28355862242 Jun 29, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from ee0b4cb to f74a280 Compare July 6, 2026 07:24
@github-actions github-actions Bot changed the title Weekly audit refresh: 28355862242 Weekly audit refresh: 28774870590 Jul 6, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from f74a280 to dd640f5 Compare July 13, 2026 08:41
@github-actions github-actions Bot changed the title Weekly audit refresh: 28774870590 Weekly audit refresh: 29236242866 Jul 13, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from dd640f5 to bf5d844 Compare July 20, 2026 08:33
@github-actions github-actions Bot changed the title Weekly audit refresh: 29236242866 Weekly audit refresh: 29728216532 Jul 20, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from bf5d844 to 816e6d7 Compare July 27, 2026 09:22
@github-actions github-actions Bot changed the title Weekly audit refresh: 29728216532 Weekly audit refresh: 30253527123 Jul 27, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 816e6d7 to 9cf054d Compare August 3, 2026 08:56
@github-actions github-actions Bot changed the title Weekly audit refresh: 30253527123 Weekly audit refresh: 30799210887 Aug 3, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 9cf054d to ac8c576 Compare August 10, 2026 06:23
@github-actions github-actions Bot changed the title Weekly audit refresh: 30799210887 Weekly audit refresh: 31361726896 Aug 10, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from ac8c576 to 0cab591 Compare August 17, 2026 06:06
@github-actions github-actions Bot changed the title Weekly audit refresh: 31361726896 Weekly audit refresh: 32000254350 Aug 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant