Skip to content

Weekly audit refresh: 28355862242#63

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh
Open

Weekly audit refresh: 28355862242#63
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

CVE delta

Net change

Severity Added Removed Net
Critical 6 2 +4
High 274 1 +273
Medium 848 2 +846
Low 150 1 +149

Changed images: 23 of 44

Per-image detail

adguard-adguardhome-v0.107.76

  • Added: C:0 H:15 M:4 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 11 more

baserow-baserow-2.2.2

  • Added: C:1 H:17 M:20 L:11
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-55200 (CRITICAL) — libssh2-1t64
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • ...and 41 more

deluan-navidrome-0.61.2

  • Added: C:0 H:15 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 14 more

docker.io-caddy-2.11.3

  • Added: C:0 H:15 M:4 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 11 more

docker.io-louislam-uptime-kuma-2.3.2

  • Added: C:2 H:27 M:25 L:9
  • Removed: C:1 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-55200 (CRITICAL) — libssh2-1
      • CVE-2026-56123 (CRITICAL) — socat
      • CVE-2025-47913 (HIGH) — golang.org/x/crypto
      • CVE-2026-12019 (HIGH) — chromium
      • CVE-2026-12020 (HIGH) — chromium
      • CVE-2026-12022 (HIGH) — chromium
      • CVE-2026-12027 (HIGH) — chromium
      • CVE-2026-12028 (HIGH) — chromium
      • ...and 55 more
    • [FIXED]:
      • CVE-2026-44170 (CRITICAL) — libmariadb3

docker.io-mariadb-12.2.2

  • Added: C:0 H:0 M:5 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-10879 (MEDIUM) — libdbi-perl
      • CVE-2026-42496 (MEDIUM) — libperl5.38t64
      • CVE-2026-5704 (MEDIUM) — tar
      • CVE-2026-8376 (MEDIUM) — libperl5.38t64
      • CVE-2026-9698 (MEDIUM) — libdbi-perl
      • CVE-2026-27171 (LOW) — zlib1g

docker.io-mongo-8.3.2

  • Added: C:0 H:15 M:14 L:8
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 29 more

fnsys-dockhand-v1.0.29

  • Added: C:0 H:3 M:11 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-50195 (HIGH) — docker-cli-buildx
      • CVE-2026-53489 (HIGH) — docker-cli-buildx
      • CVE-2026-53492 (HIGH) — docker-cli-buildx
      • CVE-2026-41178 (MEDIUM) — docker-compose
      • CVE-2026-47262 (MEDIUM) — docker-cli-buildx
      • CVE-2026-50219 (MEDIUM) — libexpat1
      • CVE-2026-56132 (MEDIUM) — libexpat1
      • CVE-2026-56403 (MEDIUM) — libexpat1
      • ...and 6 more

ghcr.io-goauthentik-server-2026.2.3

  • Added: C:2 H:44 M:223 L:51
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-33815 (CRITICAL) — github.com/jackc/pgx/v5
      • CVE-2026-55200 (CRITICAL) — libssh2-1t64
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-42502 (HIGH) — golang.org/x/net
      • CVE-2026-42506 (HIGH) — golang.org/x/net
      • ...and 312 more

ghcr.io-open-webui-open-webui-0.9.5

  • Added: C:1 H:36 M:198 L:36
  • Removed: C:1 H:1 M:0 L:1
    • [NEW]:
      • CVE-2026-55200 (CRITICAL) — libssh2-1
      • CVE-2026-48802 (HIGH) — python-engineio
      • CVE-2026-48804 (HIGH) — python-socketio
      • CVE-2026-48809 (HIGH) — python-engineio
      • CVE-2026-49839 (HIGH) — jq
      • CVE-2026-52910 (HIGH) — linux-libc-dev
      • CVE-2026-52911 (HIGH) — linux-libc-dev
      • CVE-2026-52923 (HIGH) — linux-libc-dev
      • ...and 263 more
    • [FIXED]:
      • CVE-2026-44170 (CRITICAL) — libmariadb-dev
      • CVE-2026-45852 (HIGH) — linux-libc-dev
      • CVE-2020-36325 (LOW) — libjansson4

ghcr.io-stoatchat-for-web-0b94704

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-48758 (MEDIUM) — @sigstore/core

ghcr.io-stoatchat-livekit-server-v1.9.13

  • Added: C:0 H:15 M:4 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 11 more

ghcr.io-wg-easy-wg-easy-15.3.0

  • Added: C:0 H:17 M:7 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2025-47913 (HIGH) — golang.org/x/crypto
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-33814 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • ...and 16 more

ghcr.io-ylianst-meshcentral-1.1.59-mongodb

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-48758 (MEDIUM) — @sigstore/core

ghcr.io-zulip-zulip-server-12.0-0

  • Added: C:0 H:23 M:290 L:16
  • Removed: C:0 H:0 M:2 L:0
    • [NEW]:
      • CVE-2024-45338 (HIGH) — golang.org/x/net
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • ...and 321 more
    • [FIXED]:
      • CVE-2026-31688 (MEDIUM) — linux-libc-dev
      • CVE-2026-46118 (MEDIUM) — linux-libc-dev

lscr.io-linuxserver-jellyfin-10.11.9

  • Added: C:0 H:0 M:11 L:8
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11856 (MEDIUM) — curl
      • CVE-2026-41256 (MEDIUM) — jq
      • CVE-2026-41257 (MEDIUM) — jq
      • CVE-2026-42496 (MEDIUM) — perl-base
      • CVE-2026-43895 (MEDIUM) — jq
      • CVE-2026-43896 (MEDIUM) — jq
      • CVE-2026-44777 (MEDIUM) — jq
      • CVE-2026-5704 (MEDIUM) — tar
      • ...and 11 more

mongo-8.3.2

  • Added: C:0 H:15 M:14 L:8
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 29 more

nextcloud-33.0.3-fpm-alpine

  • Added: C:0 H:1 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-2100 (HIGH) — p11-kit

postgres-18.4

  • Added: C:0 H:0 M:1 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-6653 (MEDIUM) — libxml2
      • CVE-2026-57062 (LOW) — dirmngr

qbittorrentofficial-qbittorrent-nox-5.2.0-1

  • Added: C:0 H:1 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-2100 (HIGH) — p11-kit

rabbitmq-4.3.0

  • Added: C:0 H:0 M:3 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-42496 (MEDIUM) — perl-base
      • CVE-2026-5704 (MEDIUM) — tar
      • CVE-2026-8376 (MEDIUM) — perl-base
      • CVE-2026-27171 (LOW) — zlib1g

syncthing-syncthing-2.1.0

  • Added: C:0 H:15 M:4 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-25680 (HIGH) — golang.org/x/net
      • CVE-2026-25681 (HIGH) — golang.org/x/net
      • CVE-2026-27136 (HIGH) — golang.org/x/net
      • CVE-2026-39821 (HIGH) — golang.org/x/net
      • CVE-2026-39827 (HIGH) — golang.org/x/crypto
      • CVE-2026-39828 (HIGH) — golang.org/x/crypto
      • CVE-2026-39829 (HIGH) — golang.org/x/crypto
      • CVE-2026-39830 (HIGH) — golang.org/x/crypto
      • ...and 11 more

towfiqi-serpbear-3.1.0

  • Added: C:0 H:0 M:1 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-48758 (MEDIUM) — @sigstore/core

@github-actions github-actions Bot enabled auto-merge (squash) June 15, 2026 07:46
@github-actions github-actions Bot changed the title Weekly audit refresh: 27531642510 Weekly audit refresh: 27937554468 Jun 22, 2026
@github-actions github-actions Bot force-pushed the chore/weekly-audit-refresh branch from abd8448 to b731738 Compare June 22, 2026 07:48
@github-actions github-actions Bot force-pushed the chore/weekly-audit-refresh branch from b731738 to ee0b4cb Compare June 29, 2026 07:31
@github-actions github-actions Bot changed the title Weekly audit refresh: 27937554468 Weekly audit refresh: 28355862242 Jun 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant