3.6.4 — Security fixes



Fixes provided in 3.6.4

42 CVE(s) fixed compared to the previous release.

Service CVE Severity Package Previously affected
admin-center CVE-2026-44249 HIGH netty-handler 3.6.2
admin-center CVE-2026-45416 HIGH netty-handler 3.6.2
admin-center CVE-2026-45674 HIGH netty-resolver-dns 3.6.2
admin-center CVE-2026-47691 HIGH netty-resolver-dns 3.6.2
admin-center CVE-2026-50010 HIGH netty-handler 3.6.3
ai-service CVE-2026-45447 HIGH libssl3t64 3.6.3
ai-service GHSA-537c-gmf6-5ccf HIGH cryptography 3.6.3
ai-service GHSA-f4xh-w4cj-qxq8 HIGH langsmith 3.6.2
ai-service GHSA-rpj2-4hq8-938g HIGH vcrpy 3.6.2
analysis-node CVE-2026-45447 HIGH libssl3t64 3.6.3
analysis-node CVE-2026-45591 HIGH Microsoft.AspNetCore.App.Runtime.linux-x64 3.6.3
auth-service CVE-2026-44249 HIGH netty-handler 3.6.2
auth-service CVE-2026-45416 HIGH netty-handler 3.6.2
auth-service CVE-2026-45674 HIGH netty-resolver-dns 3.6.2
auth-service CVE-2026-47691 HIGH netty-resolver-dns 3.6.2
auth-service CVE-2026-50010 HIGH netty-handler 3.6.2
etl-service CVE-2026-42504 HIGH stdlib 3.6.3
etl-service CVE-2026-45447 HIGH libcrypto3 3.6.3
gateway CVE-2026-44249 HIGH netty-handler 3.6.2
gateway CVE-2026-45416 HIGH netty-handler 3.6.2
gateway CVE-2026-45674 HIGH netty-resolver-dns 3.6.2
gateway CVE-2026-47691 HIGH netty-resolver-dns 3.6.2
gateway CVE-2026-50010 HIGH netty-handler 3.6.3
imaging-apis CVE-2026-42504 HIGH stdlib 3.6.3
imaging-apis CVE-2026-45447 HIGH libcrypto3 3.6.3
neo4j CVE-2026-42504 HIGH stdlib 3.6.2
neo4j CVE-2026-45447 HIGH libssl3t64 3.6.2
neo4j CVE-2026-55851 HIGH netty-codec-haproxy 3.6.3
sso-service CVE-2026-44249 HIGH netty-handler 3.6.2
sso-service CVE-2026-44893 HIGH netty-codec-haproxy 3.6.2
sso-service CVE-2026-45416 HIGH netty-handler 3.6.2
sso-service CVE-2026-45447 HIGH libssl3t64 3.6.2
sso-service CVE-2026-45674 HIGH netty-resolver-dns 3.6.2
sso-service CVE-2026-47691 HIGH netty-resolver-dns 3.6.2
sso-service CVE-2026-48059 HIGH netty-codec-haproxy 3.6.2
sso-service CVE-2026-50010 HIGH netty-handler 3.6.3
sso-service CVE-2026-7307 HIGH keycloak-saml-core 3.6.2
sso-service CVE-2026-7504 HIGH keycloak-services 3.6.2
sso-service CVE-2026-7507 HIGH keycloak-services 3.6.2
sso-service CVE-2026-7571 HIGH keycloak-services 3.6.2
viewer CVE-2026-42504 HIGH stdlib 3.6.3
viewer CVE-2026-45447 HIGH libcrypto3 3.6.3

Security patch 3.6.4.1

1 CVE(s) fixed in the 3.6.4.1 security patch.

Service CVE Severity Package Previously affected
ai-service GHSA-f4xh-w4cj-qxq8 HIGH langsmith 3.6.4

Pre-existing — assessed

The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.

Service CVE Severity Package Status Justification
ai-service CVE-2025-69720 HIGH libncursesw6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
ai-service CVE-2026-11822 HIGH libsqlite3-0 OS Vendor libsqlite3-0 is a Debian system package. No fix available from the OS vendor yet. CAST integrates the update as soon as the base image is updated.
ai-service CVE-2026-11824 HIGH libsqlite3-0 OS Vendor libsqlite3-0 is a Debian system package. No fix available from the OS vendor yet. CAST integrates the update as soon as the base image is updated.
analysis-node CVE-2025-26646 HIGH Microsoft.Build.Tasks.Core Not Affected –no-restore skips the NuGet restore pipeline where this CVE lives.
analysis-node CVE-2025-55247 HIGH Microsoft.Build.Tasks.Core Not Affected MSBuild input comes exclusively from CAST’s own tooling — no external input.
analysis-node CVE-2025-67030 HIGH plexus-utils Not Affected The vulnerable code path is never invoked at runtime.
analysis-node CVE-2025-69720 HIGH libtinfo6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
analysis-node CVE-2026-23949 HIGH jaraco.context Not Affected jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service.
analysis-node CVE-2026-24049 HIGH wheel Not Affected wheel is a build-time tool only — not used at runtime.
analysis-node CVE-2026-26171 HIGH System.Security.Cryptography.Xml Not Affected Not loaded during any runtime code path.
analysis-node CVE-2026-44432 HIGH urllib3 Not Affected Not used in any production code path.
dashboards-v3 CVE-2026-2100 HIGH p11-kit OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
dashboards-v3 CVE-2026-45186 HIGH libexpat OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
dashboards-v3 CVE-2026-45447 HIGH libcrypto3 OS Vendor OpenSSL vulnerability in DHI (Docker Hardened Image) base image. Waiting for fix.
neo4j CVE-2025-69720 HIGH libtinfo6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
neo4j CVE-2026-10050 HIGH jetty-ee8-security Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-59901 HIGH netty-codec-compression Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
sso-service CVE-2025-59250 HIGH mssql-jdbc False Positive Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier.
sso-service CVE-2025-69720 HIGH libtinfo6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.