3.6.4 — Security fixes
For the live, searchable view of all CVE advisories with remediation status, see the Security Advisories.
Fixes provided in 3.6.4
42 CVE(s) fixed compared to the previous release.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| admin-center | CVE-2026-44249 | HIGH | netty-handler | 3.6.2 |
| admin-center | CVE-2026-45416 | HIGH | netty-handler | 3.6.2 |
| admin-center | CVE-2026-45674 | HIGH | netty-resolver-dns | 3.6.2 |
| admin-center | CVE-2026-47691 | HIGH | netty-resolver-dns | 3.6.2 |
| admin-center | CVE-2026-50010 | HIGH | netty-handler | 3.6.3 |
| ai-service | CVE-2026-45447 | HIGH | libssl3t64 | 3.6.3 |
| ai-service | GHSA-537c-gmf6-5ccf | HIGH | cryptography | 3.6.3 |
| ai-service | GHSA-f4xh-w4cj-qxq8 | HIGH | langsmith | 3.6.2 |
| ai-service | GHSA-rpj2-4hq8-938g | HIGH | vcrpy | 3.6.2 |
| analysis-node | CVE-2026-45447 | HIGH | libssl3t64 | 3.6.3 |
| analysis-node | CVE-2026-45591 | HIGH | Microsoft.AspNetCore.App.Runtime.linux-x64 | 3.6.3 |
| auth-service | CVE-2026-44249 | HIGH | netty-handler | 3.6.2 |
| auth-service | CVE-2026-45416 | HIGH | netty-handler | 3.6.2 |
| auth-service | CVE-2026-45674 | HIGH | netty-resolver-dns | 3.6.2 |
| auth-service | CVE-2026-47691 | HIGH | netty-resolver-dns | 3.6.2 |
| auth-service | CVE-2026-50010 | HIGH | netty-handler | 3.6.2 |
| etl-service | CVE-2026-42504 | HIGH | stdlib | 3.6.3 |
| etl-service | CVE-2026-45447 | HIGH | libcrypto3 | 3.6.3 |
| gateway | CVE-2026-44249 | HIGH | netty-handler | 3.6.2 |
| gateway | CVE-2026-45416 | HIGH | netty-handler | 3.6.2 |
| gateway | CVE-2026-45674 | HIGH | netty-resolver-dns | 3.6.2 |
| gateway | CVE-2026-47691 | HIGH | netty-resolver-dns | 3.6.2 |
| gateway | CVE-2026-50010 | HIGH | netty-handler | 3.6.3 |
| imaging-apis | CVE-2026-42504 | HIGH | stdlib | 3.6.3 |
| imaging-apis | CVE-2026-45447 | HIGH | libcrypto3 | 3.6.3 |
| neo4j | CVE-2026-42504 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-45447 | HIGH | libssl3t64 | 3.6.2 |
| neo4j | CVE-2026-55851 | HIGH | netty-codec-haproxy | 3.6.3 |
| sso-service | CVE-2026-44249 | HIGH | netty-handler | 3.6.2 |
| sso-service | CVE-2026-44893 | HIGH | netty-codec-haproxy | 3.6.2 |
| sso-service | CVE-2026-45416 | HIGH | netty-handler | 3.6.2 |
| sso-service | CVE-2026-45447 | HIGH | libssl3t64 | 3.6.2 |
| sso-service | CVE-2026-45674 | HIGH | netty-resolver-dns | 3.6.2 |
| sso-service | CVE-2026-47691 | HIGH | netty-resolver-dns | 3.6.2 |
| sso-service | CVE-2026-48059 | HIGH | netty-codec-haproxy | 3.6.2 |
| sso-service | CVE-2026-50010 | HIGH | netty-handler | 3.6.3 |
| sso-service | CVE-2026-7307 | HIGH | keycloak-saml-core | 3.6.2 |
| sso-service | CVE-2026-7504 | HIGH | keycloak-services | 3.6.2 |
| sso-service | CVE-2026-7507 | HIGH | keycloak-services | 3.6.2 |
| sso-service | CVE-2026-7571 | HIGH | keycloak-services | 3.6.2 |
| viewer | CVE-2026-42504 | HIGH | stdlib | 3.6.3 |
| viewer | CVE-2026-45447 | HIGH | libcrypto3 | 3.6.3 |
Security patch 3.6.4.1
1 CVE(s) fixed in the 3.6.4.1 security patch.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| ai-service | GHSA-f4xh-w4cj-qxq8 | HIGH | langsmith | 3.6.4 |
Pre-existing — assessed
The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.
| Service | CVE | Severity | Package | Status | Justification |
|---|---|---|---|---|---|
| ai-service | CVE-2025-69720 | HIGH | libncursesw6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| ai-service | CVE-2026-11822 | HIGH | libsqlite3-0 | OS Vendor | libsqlite3-0 is a Debian system package. No fix available from the OS vendor yet. CAST integrates the update as soon as the base image is updated. |
| ai-service | CVE-2026-11824 | HIGH | libsqlite3-0 | OS Vendor | libsqlite3-0 is a Debian system package. No fix available from the OS vendor yet. CAST integrates the update as soon as the base image is updated. |
| analysis-node | CVE-2025-26646 | HIGH | Microsoft.Build.Tasks.Core | Not Affected | –no-restore skips the NuGet restore pipeline where this CVE lives. |
| analysis-node | CVE-2025-55247 | HIGH | Microsoft.Build.Tasks.Core | Not Affected | MSBuild input comes exclusively from CAST’s own tooling — no external input. |
| analysis-node | CVE-2025-67030 | HIGH | plexus-utils | Not Affected | The vulnerable code path is never invoked at runtime. |
| analysis-node | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| analysis-node | CVE-2026-23949 | HIGH | jaraco.context | Not Affected | jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service. |
| analysis-node | CVE-2026-24049 | HIGH | wheel | Not Affected | wheel is a build-time tool only — not used at runtime. |
| analysis-node | CVE-2026-26171 | HIGH | System.Security.Cryptography.Xml | Not Affected | Not loaded during any runtime code path. |
| analysis-node | CVE-2026-44432 | HIGH | urllib3 | Not Affected | Not used in any production code path. |
| dashboards-v3 | CVE-2026-2100 | HIGH | p11-kit | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| dashboards-v3 | CVE-2026-45186 | HIGH | libexpat | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| dashboards-v3 | CVE-2026-45447 | HIGH | libcrypto3 | OS Vendor | OpenSSL vulnerability in DHI (Docker Hardened Image) base image. Waiting for fix. |
| neo4j | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| neo4j | CVE-2026-10050 | HIGH | jetty-ee8-security | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-59901 | HIGH | netty-codec-compression | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| sso-service | CVE-2025-59250 | HIGH | mssql-jdbc | False Positive | Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier. |
| sso-service | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |