3.6.5 — Security fixes



Fixes provided in 3.6.5

50 CVE(s) fixed compared to the previous release.

Service CVE Severity Package Previously affected
admin-center CVE-2026-54512 HIGH jackson-databind 3.6.2
admin-center CVE-2026-54513 HIGH jackson-databind 3.6.2
admin-center GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
ai-service CVE-2026-25087 HIGH pyarrow 3.6.4
ai-service CVE-2026-4372 HIGH transformers 3.6.4
ai-service CVE-2026-5241 HIGH transformers 3.6.4
analysis-node CVE-2025-26646 HIGH Microsoft.Build.Tasks.Core 3.6.3
analysis-node CVE-2025-55247 HIGH Microsoft.Build.Tasks.Core 3.6.3
analysis-node CVE-2025-67030 HIGH plexus-utils 3.6.3
analysis-node CVE-2026-26171 HIGH System.Security.Cryptography.Xml 3.6.3
analysis-node CVE-2026-33116 HIGH System.Security.Cryptography.Xml 3.6.3
analysis-node CVE-2026-42198 HIGH postgresql 3.6.3
analysis-node CVE-2026-44431 HIGH urllib3 3.6.3
analysis-node CVE-2026-44432 HIGH urllib3 3.6.3
analysis-node CVE-2026-54512 HIGH jackson-databind 3.6.2
analysis-node CVE-2026-54513 HIGH jackson-databind 3.6.2
analysis-node GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
auth-service CVE-2026-54512 HIGH jackson-databind 3.6.2
auth-service CVE-2026-54513 HIGH jackson-databind 3.6.2
auth-service GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
console CVE-2026-54512 HIGH jackson-databind 3.6.2
console CVE-2026-54513 HIGH jackson-databind 3.6.2
console GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
dashboards-v3 CVE-2026-54512 HIGH jackson-databind 3.6.2
dashboards-v3 CVE-2026-54513 HIGH jackson-databind 3.6.2
dashboards-v3 GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
gateway CVE-2026-54512 HIGH jackson-databind 3.6.2
gateway CVE-2026-54513 HIGH jackson-databind 3.6.2
gateway GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
imaging-apis CVE-2026-45186 HIGH libexpat 3.6.2
neo4j CVE-2026-33871 HIGH netty-codec-http2 3.6.2
neo4j CVE-2026-42577 HIGH netty-transport-native-epoll 3.6.2
neo4j CVE-2026-42579 HIGH netty-codec-dns 3.6.2
neo4j CVE-2026-42582 HIGH netty-codec-http3 3.6.2
neo4j CVE-2026-42583 HIGH netty-codec-compression 3.6.2
neo4j CVE-2026-42584 HIGH netty-codec-http 3.6.2
neo4j CVE-2026-42587 HIGH netty-codec-http 3.6.2
neo4j CVE-2026-44249 HIGH netty-handler 3.6.3
neo4j CVE-2026-44892 HIGH netty-codec-http3 3.6.2
neo4j CVE-2026-44894 HIGH netty-codec-classes-quic 3.6.2
neo4j CVE-2026-45416 HIGH netty-handler 3.6.3
neo4j CVE-2026-45674 HIGH netty-resolver-dns 3.6.3
neo4j CVE-2026-47691 HIGH netty-resolver-dns 3.6.3
neo4j CVE-2026-48748 HIGH netty-codec-http3 3.6.3
neo4j CVE-2026-49268 HIGH shiro-core 3.6.3
neo4j CVE-2026-50010 HIGH netty-handler 3.6.3
sso-service CVE-2026-54512 HIGH jackson-databind 3.6.2
sso-service CVE-2026-54513 HIGH jackson-databind 3.6.2
sso-service CVE-2026-9795 HIGH keycloak-services 3.6.2
viewer CVE-2026-54063 HIGH github.com/xuri/excelize/v2 3.6.2

Security patch 3.6.5.1

4 CVE(s) fixed in the 3.6.5.1 security patch.

Service CVE Severity Package Previously affected
ai-service CVE-2026-5241 HIGH transformers 3.6.5
ai-service CVE-2026-59885 HIGH pyasn1 3.6.2
ai-service CVE-2026-59886 HIGH pyasn1 3.6.2
ai-service GHSA-xf7x-x43h-rpqh HIGH json_repair 3.6.5

Pre-existing — assessed

The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.

Service CVE Severity Package Status Justification
admin-center CVE-2026-54512 HIGH Not Affected This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase.
admin-center CVE-2026-54513 HIGH Not Affected This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase.
ai-service CVE-2025-15281 HIGH libc-bin OS Vendor libc6 — no upstream fix published yet. Tracking.
ai-service CVE-2025-69720 HIGH libncursesw6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
ai-service CVE-2026-0861 HIGH libc-bin OS Vendor libc6 — no upstream fix published yet. Tracking.
ai-service CVE-2026-0915 HIGH libc-bin OS Vendor libc6 — no upstream fix published yet. Tracking.
ai-service CVE-2026-40467 HIGH gawk OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
ai-service CVE-2026-40468 CRITICAL gawk OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
ai-service CVE-2026-40469 CRITICAL gawk OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
ai-service CVE-2026-40553 HIGH gawk OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
ai-service CVE-2026-53615 HIGH libuuid1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2020-27225 HIGH OS Vendor No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922).
analysis-node CVE-2025-55247 HIGH Not Affected Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). Microsoft.Build 17.11.31 is no longer present in the image as of 3.6.4_core8.4.11.
analysis-node CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2026-23949 HIGH jaraco.context Not Affected jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service.
analysis-node CVE-2026-24049 HIGH wheel Not Affected wheel is a build-time tool only — not used at runtime.
analysis-node CVE-2026-26171 HIGH Not Affected Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). System.Security.Cryptography.Xml 8.0.0 is no longer present in the image as of 3.6.4_core8.4.11.
analysis-node CVE-2026-33116 HIGH Not Affected Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). System.Security.Cryptography.Xml 8.0.0 is no longer present in the image as of 3.6.4_core8.4.11.
analysis-node CVE-2026-41992 HIGH gzip OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2026-44432 HIGH Not Affected Sphinx moved to optional-dependencies in cast_application_api (EXTSDK-5), eliminating the Sphinx → requests → urllib3 transitive chain. urllib3 is no longer installed in the Linux image as of 3.6.4_core8.4.11.
analysis-node CVE-2026-54369 HIGH libacl1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
auth-service CVE-2026-54512 HIGH Not Affected This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase.
auth-service CVE-2026-54513 HIGH Not Affected This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase.
console CVE-2017-0247 HIGH Not Affected False Positive; Actual implementation uses Mono, which is not affected by this CVE
console CVE-2017-0249 HIGH Not Affected False Positive; Actual implementation uses Mono, which is not affected by this CVE
console CVE-2017-11770 HIGH Not Affected False Positive; Actual implementation uses Mono, which is not affected by this CVE
console CVE-2024-0056 HIGH Not Affected
console CVE-2025-60876 HIGH Not Affected added to test temporary if VEX is working (IMAGKSL-4923)
dashboards-v3 CVE-2025-15281 HIGH libc-bin OS Vendor libc6 — no fixed Debian package yet. Tracking upstream.
dashboards-v3 CVE-2025-69720 HIGH ncurses OS Vendor libncursesw6/libtinfo6/ncurses-base/ncurses-bin — no fixed Debian package yet. Tracking upstream.
dashboards-v3 CVE-2025-9086 HIGH OS Vendor Upgrade curl to >= 8.16.0. Pending base image rebuild.
dashboards-v3 CVE-2026-0861 HIGH libc-bin OS Vendor libc6 — no fixed Debian package yet. Tracking upstream.
dashboards-v3 CVE-2026-0915 HIGH libc-bin OS Vendor libc6 — no fixed Debian package yet. Tracking upstream.
dashboards-v3 CVE-2026-2100 HIGH p11-kit OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
gateway CVE-2026-54512 HIGH Not Affected This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase.
gateway CVE-2026-54513 HIGH Not Affected This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase.
neo4j CVE-2025-15281 HIGH libc-bin OS Vendor libc6 — no upstream fix published yet. Not directly exploitable in Neo4j operation. Tracking.
neo4j CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
neo4j CVE-2026-0861 HIGH libc-bin OS Vendor libc6 — no upstream fix published yet. Tracking.
neo4j CVE-2026-0915 HIGH libc-bin OS Vendor libc6 — no upstream fix published yet. Tracking.
neo4j CVE-2026-10050 HIGH jetty-ee8-security Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-33871 HIGH netty-codec-http2 Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-41992 HIGH gzip OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
neo4j CVE-2026-42577 HIGH netty-transport-native-epoll Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-42579 HIGH netty-codec-dns Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-42582 HIGH netty-codec-http3 Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-42583 HIGH netty-codec-compression Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-42584 HIGH netty-codec-http Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-42587 HIGH netty-codec-http Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-44249 HIGH netty-handler Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-44892 HIGH netty-codec-http3 Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-44894 HIGH netty-codec-classes-quic Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-45416 HIGH netty-handler Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-45674 HIGH netty-resolver-dns Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-47691 HIGH netty-resolver-dns Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-48748 HIGH netty-codec-http3 Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-49268 HIGH shiro-core Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-50010 HIGH netty-handler Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-54369 HIGH libacl1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
neo4j CVE-2026-54512 HIGH jackson-databind Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-54513 HIGH jackson-databind Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-59901 HIGH netty-codec-compression Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
sso-service CVE-2025-15281 HIGH OS Vendor No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922).
sso-service CVE-2025-59250 HIGH mssql-jdbc False Positive Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier.
sso-service CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
sso-service CVE-2026-0861 HIGH OS Vendor No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922).
sso-service CVE-2026-0915 HIGH OS Vendor No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922).
sso-service CVE-2026-54369 HIGH libacl1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
sso-service CVE-2026-54512 HIGH Not Affected CAST-developed code in this Keycloak-based service (themes, API key extension) uses no polymorphic type handling (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be active, which is absent from the CAST codebase bundled here.
sso-service CVE-2026-54513 HIGH Not Affected CAST-developed code in this Keycloak-based service (themes, API key extension) uses no polymorphic type handling (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be active, which is absent from the CAST codebase bundled here.