3.6.5 — Security fixes
For the live, searchable view of all CVE advisories with remediation status, see the Security Advisories.
Fixes provided in 3.6.5
50 CVE(s) fixed compared to the previous release.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| admin-center | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| admin-center | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| admin-center | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| ai-service | CVE-2026-25087 | HIGH | pyarrow | 3.6.4 |
| ai-service | CVE-2026-4372 | HIGH | transformers | 3.6.4 |
| ai-service | CVE-2026-5241 | HIGH | transformers | 3.6.4 |
| analysis-node | CVE-2025-26646 | HIGH | Microsoft.Build.Tasks.Core | 3.6.3 |
| analysis-node | CVE-2025-55247 | HIGH | Microsoft.Build.Tasks.Core | 3.6.3 |
| analysis-node | CVE-2025-67030 | HIGH | plexus-utils | 3.6.3 |
| analysis-node | CVE-2026-26171 | HIGH | System.Security.Cryptography.Xml | 3.6.3 |
| analysis-node | CVE-2026-33116 | HIGH | System.Security.Cryptography.Xml | 3.6.3 |
| analysis-node | CVE-2026-42198 | HIGH | postgresql | 3.6.3 |
| analysis-node | CVE-2026-44431 | HIGH | urllib3 | 3.6.3 |
| analysis-node | CVE-2026-44432 | HIGH | urllib3 | 3.6.3 |
| analysis-node | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| analysis-node | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| analysis-node | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| auth-service | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| auth-service | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| auth-service | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| console | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| console | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| console | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| dashboards-v3 | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| dashboards-v3 | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| dashboards-v3 | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| gateway | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| gateway | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| gateway | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| imaging-apis | CVE-2026-45186 | HIGH | libexpat | 3.6.2 |
| neo4j | CVE-2026-33871 | HIGH | netty-codec-http2 | 3.6.2 |
| neo4j | CVE-2026-42577 | HIGH | netty-transport-native-epoll | 3.6.2 |
| neo4j | CVE-2026-42579 | HIGH | netty-codec-dns | 3.6.2 |
| neo4j | CVE-2026-42582 | HIGH | netty-codec-http3 | 3.6.2 |
| neo4j | CVE-2026-42583 | HIGH | netty-codec-compression | 3.6.2 |
| neo4j | CVE-2026-42584 | HIGH | netty-codec-http | 3.6.2 |
| neo4j | CVE-2026-42587 | HIGH | netty-codec-http | 3.6.2 |
| neo4j | CVE-2026-44249 | HIGH | netty-handler | 3.6.3 |
| neo4j | CVE-2026-44892 | HIGH | netty-codec-http3 | 3.6.2 |
| neo4j | CVE-2026-44894 | HIGH | netty-codec-classes-quic | 3.6.2 |
| neo4j | CVE-2026-45416 | HIGH | netty-handler | 3.6.3 |
| neo4j | CVE-2026-45674 | HIGH | netty-resolver-dns | 3.6.3 |
| neo4j | CVE-2026-47691 | HIGH | netty-resolver-dns | 3.6.3 |
| neo4j | CVE-2026-48748 | HIGH | netty-codec-http3 | 3.6.3 |
| neo4j | CVE-2026-49268 | HIGH | shiro-core | 3.6.3 |
| neo4j | CVE-2026-50010 | HIGH | netty-handler | 3.6.3 |
| sso-service | CVE-2026-54512 | HIGH | jackson-databind | 3.6.2 |
| sso-service | CVE-2026-54513 | HIGH | jackson-databind | 3.6.2 |
| sso-service | CVE-2026-9795 | HIGH | keycloak-services | 3.6.2 |
| viewer | CVE-2026-54063 | HIGH | github.com/xuri/excelize/v2 | 3.6.2 |
Security patch 3.6.5.1
4 CVE(s) fixed in the 3.6.5.1 security patch.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| ai-service | CVE-2026-5241 | HIGH | transformers | 3.6.5 |
| ai-service | CVE-2026-59885 | HIGH | pyasn1 | 3.6.2 |
| ai-service | CVE-2026-59886 | HIGH | pyasn1 | 3.6.2 |
| ai-service | GHSA-xf7x-x43h-rpqh | HIGH | json_repair | 3.6.5 |
Pre-existing — assessed
The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.
| Service | CVE | Severity | Package | Status | Justification |
|---|---|---|---|---|---|
| admin-center | CVE-2026-54512 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| admin-center | CVE-2026-54513 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| ai-service | CVE-2025-15281 | HIGH | libc-bin | OS Vendor | libc6 — no upstream fix published yet. Tracking. |
| ai-service | CVE-2025-69720 | HIGH | libncursesw6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-0861 | HIGH | libc-bin | OS Vendor | libc6 — no upstream fix published yet. Tracking. |
| ai-service | CVE-2026-0915 | HIGH | libc-bin | OS Vendor | libc6 — no upstream fix published yet. Tracking. |
| ai-service | CVE-2026-40467 | HIGH | gawk | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-40468 | CRITICAL | gawk | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-40469 | CRITICAL | gawk | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-40553 | HIGH | gawk | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-53615 | HIGH | libuuid1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2020-27225 | HIGH | OS Vendor | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| analysis-node | CVE-2025-55247 | HIGH | Not Affected | Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). Microsoft.Build 17.11.31 is no longer present in the image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2026-23949 | HIGH | jaraco.context | Not Affected | jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service. |
| analysis-node | CVE-2026-24049 | HIGH | wheel | Not Affected | wheel is a build-time tool only — not used at runtime. |
| analysis-node | CVE-2026-26171 | HIGH | Not Affected | Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). System.Security.Cryptography.Xml 8.0.0 is no longer present in the image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2026-33116 | HIGH | Not Affected | Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). System.Security.Cryptography.Xml 8.0.0 is no longer present in the image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2026-41992 | HIGH | gzip | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2026-44432 | HIGH | Not Affected | Sphinx moved to optional-dependencies in cast_application_api (EXTSDK-5), eliminating the Sphinx → requests → urllib3 transitive chain. urllib3 is no longer installed in the Linux image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2026-54369 | HIGH | libacl1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| auth-service | CVE-2026-54512 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| auth-service | CVE-2026-54513 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| console | CVE-2017-0247 | HIGH | Not Affected | False Positive; Actual implementation uses Mono, which is not affected by this CVE | |
| console | CVE-2017-0249 | HIGH | Not Affected | False Positive; Actual implementation uses Mono, which is not affected by this CVE | |
| console | CVE-2017-11770 | HIGH | Not Affected | False Positive; Actual implementation uses Mono, which is not affected by this CVE | |
| console | CVE-2024-0056 | HIGH | Not Affected | ||
| console | CVE-2025-60876 | HIGH | Not Affected | added to test temporary if VEX is working (IMAGKSL-4923) | |
| dashboards-v3 | CVE-2025-15281 | HIGH | libc-bin | OS Vendor | libc6 — no fixed Debian package yet. Tracking upstream. |
| dashboards-v3 | CVE-2025-69720 | HIGH | ncurses | OS Vendor | libncursesw6/libtinfo6/ncurses-base/ncurses-bin — no fixed Debian package yet. Tracking upstream. |
| dashboards-v3 | CVE-2025-9086 | HIGH | OS Vendor | Upgrade curl to >= 8.16.0. Pending base image rebuild. | |
| dashboards-v3 | CVE-2026-0861 | HIGH | libc-bin | OS Vendor | libc6 — no fixed Debian package yet. Tracking upstream. |
| dashboards-v3 | CVE-2026-0915 | HIGH | libc-bin | OS Vendor | libc6 — no fixed Debian package yet. Tracking upstream. |
| dashboards-v3 | CVE-2026-2100 | HIGH | p11-kit | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| gateway | CVE-2026-54512 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| gateway | CVE-2026-54513 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| neo4j | CVE-2025-15281 | HIGH | libc-bin | OS Vendor | libc6 — no upstream fix published yet. Not directly exploitable in Neo4j operation. Tracking. |
| neo4j | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-0861 | HIGH | libc-bin | OS Vendor | libc6 — no upstream fix published yet. Tracking. |
| neo4j | CVE-2026-0915 | HIGH | libc-bin | OS Vendor | libc6 — no upstream fix published yet. Tracking. |
| neo4j | CVE-2026-10050 | HIGH | jetty-ee8-security | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-33871 | HIGH | netty-codec-http2 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-41992 | HIGH | gzip | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-42577 | HIGH | netty-transport-native-epoll | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-42579 | HIGH | netty-codec-dns | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-42582 | HIGH | netty-codec-http3 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-42583 | HIGH | netty-codec-compression | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-42584 | HIGH | netty-codec-http | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-42587 | HIGH | netty-codec-http | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-44249 | HIGH | netty-handler | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-44892 | HIGH | netty-codec-http3 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-44894 | HIGH | netty-codec-classes-quic | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-45416 | HIGH | netty-handler | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-45674 | HIGH | netty-resolver-dns | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-47691 | HIGH | netty-resolver-dns | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-48748 | HIGH | netty-codec-http3 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-49268 | HIGH | shiro-core | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-50010 | HIGH | netty-handler | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-54369 | HIGH | libacl1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-54512 | HIGH | jackson-databind | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-54513 | HIGH | jackson-databind | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-59901 | HIGH | netty-codec-compression | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| sso-service | CVE-2025-15281 | HIGH | OS Vendor | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| sso-service | CVE-2025-59250 | HIGH | mssql-jdbc | False Positive | Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier. |
| sso-service | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| sso-service | CVE-2026-0861 | HIGH | OS Vendor | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| sso-service | CVE-2026-0915 | HIGH | OS Vendor | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| sso-service | CVE-2026-54369 | HIGH | libacl1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| sso-service | CVE-2026-54512 | HIGH | Not Affected | CAST-developed code in this Keycloak-based service (themes, API key extension) uses no polymorphic type handling (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be active, which is absent from the CAST codebase bundled here. | |
| sso-service | CVE-2026-54513 | HIGH | Not Affected | CAST-developed code in this Keycloak-based service (themes, API key extension) uses no polymorphic type handling (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be active, which is absent from the CAST codebase bundled here. |