3.6.7 — Security fixes
For the live, searchable view of all CVE advisories with remediation status, see the Security Advisories.
Fixes provided in 3.6.7
36 CVE(s) fixed compared to the previous release.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| ai-service | CVE-2026-69247 | HIGH | cryptography | 3.6.2 |
| ai-service | CVE-2026-9856 | HIGH | transformers | 3.6.3 |
| analysis-node | CVE-2026-54291 | HIGH | postgresql | 3.6.2 |
| analysis-node | CVE-2026-62901 | HIGH | Microsoft.NETCore.App.Runtime.linux-x64 | 3.6.2 |
| auth-service | CVE-2026-54399 | HIGH | httpcore5 | 3.6.2 |
| auth-service | CVE-2026-54428 | HIGH | httpcore5-h2 | 3.6.2 |
| console | CVE-2026-41855 | HIGH | spring-jms | 3.6.3 |
| etl-service | CVE-2026-39821 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-46600 | HIGH | stdlib | 3.6.3 |
| extend-proxy | CVE-2024-10491 | HIGH | express | 2.2.11 |
| extend-proxy | sonatype-2016-0121 | HIGH | multer | 2.2.11 |
| extend-proxy | sonatype-2019-0159 | HIGH | lunr | 2.2.11 |
| extend-proxy | sonatype-2021-0078 | HIGH | express | 2.2.11 |
| extend-proxy | sonatype-2021-1683 | HIGH | lunr | 2.2.11 |
| gateway | CVE-2026-65182 | CRITICAL | tomcat-embed-core | 3.6.3 |
| gateway | CVE-2026-65905 | CRITICAL | tomcat-embed-core | 3.6.3 |
| gateway | CVE-2026-68525 | CRITICAL | tomcat-embed-core | 3.6.3 |
| imaging-apis | CVE-2026-39821 | HIGH | stdlib | 3.6.6 |
| imaging-apis | CVE-2026-46600 | HIGH | stdlib | 3.6.6 |
| imaging-apis | CVE-2026-56854 | CRITICAL | golang.org/x/crypto | 3.6.2 |
| neo4j | CVE-2026-39821 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-46600 | HIGH | stdlib | 3.6.3 |
| sso-service | CVE-2026-18963 | CRITICAL | keycloak-services | 3.6.2 |
| sso-service | CVE-2026-40983 | HIGH | micrometer-core | 3.6.2 |
| sso-service | CVE-2026-40984 | HIGH | micrometer-core | 3.6.2 |
| sso-service | CVE-2026-50559 | HIGH | quarkus-vertx-http | 3.6.2 |
| sso-service | CVE-2026-54291 | HIGH | postgresql | 3.6.2 |
| sso-service | CVE-2026-55831 | HIGH | netty-codec-http | 3.6.2 |
| sso-service | CVE-2026-55833 | HIGH | netty-codec-http | 3.6.2 |
| sso-service | CVE-2026-55851 | HIGH | netty-codec-haproxy | 3.6.2 |
| sso-service | CVE-2026-56745 | HIGH | netty-codec-http | 3.6.2 |
| sso-service | CVE-2026-56819 | HIGH | netty-codec-http2 | 3.6.2 |
| sso-service | CVE-2026-59901 | HIGH | netty-codec | 3.6.2 |
| sso-service | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | 3.6.2 |
| viewer | CVE-2026-39821 | HIGH | stdlib | 3.6.6 |
| viewer | CVE-2026-46600 | HIGH | stdlib | 3.6.6 |
Security patch 3.6.7.1
8 CVE(s) fixed in the 3.6.7.1 security patch.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| ai-service | CVE-2026-63349 | HIGH | anyio | 3.6.3 |
| auth-service | CVE-2026-54512 | HIGH | 3.6.7 | |
| auth-service | CVE-2026-54513 | HIGH | 3.6.7 | |
| gateway | CVE-2026-54512 | HIGH | 3.6.7 | |
| gateway | CVE-2026-54513 | HIGH | 3.6.7 | |
| sso-service | CVE-2026-54512 | HIGH | 3.6.7 | |
| sso-service | CVE-2026-54513 | HIGH | 3.6.7 | |
| sso-service | CVE-2026-75595 | CRITICAL | netty-handler | 3.6.2 |
Security patch 3.6.7.2
1 CVE(s) fixed in the 3.6.7.2 security patch.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| viewer | CVE-2026-59161 | HIGH | github.com/xuri/excelize/v2 | 3.6.3 |
Pre-existing — assessed
The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.
| Service | CVE | Severity | Package | Status | Justification |
|---|---|---|---|---|---|
| admin-center | CVE-2026-54512 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| admin-center | CVE-2026-54513 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| ai-service | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-11822 | HIGH | libsqlite3-0 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| ai-service | CVE-2026-11824 | HIGH | libsqlite3-0 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2020-27225 | HIGH | Fix Incoming | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| analysis-node | CVE-2025-55247 | HIGH | Not Affected | Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). Microsoft.Build 17.11.31 is no longer present in the image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2026-14456 | HIGH | libssl3t64 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2026-23949 | HIGH | jaraco.context | Not Affected | jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service. |
| analysis-node | CVE-2026-24049 | HIGH | wheel | Not Affected | wheel is a build-time tool only — not used at runtime. |
| analysis-node | CVE-2026-26171 | HIGH | Not Affected | Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). System.Security.Cryptography.Xml 8.0.0 is no longer present in the image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2026-33116 | HIGH | Not Affected | Resolved by upgrading .NET SDK from 8.0 to 10.0 (AIPCORE-5920). System.Security.Cryptography.Xml 8.0.0 is no longer present in the image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2026-41992 | HIGH | gzip | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2026-44432 | HIGH | Not Affected | Sphinx moved to optional-dependencies in cast_application_api (EXTSDK-5), eliminating the Sphinx → requests → urllib3 transitive chain. urllib3 is no longer installed in the Linux image as of 3.6.4_core8.4.11. | |
| analysis-node | CVE-2026-54284 | HIGH | sqlparse | Not Affected | sqlparse is used by cast_application_api (sql_tool / _execute_raw_query) only to split and format SQL text that comes from the extension’s own bundled SQL scripts. No analyzer extension builds these query strings dynamically from external or source-code-derived input, so no adversary can supply the crafted SQL needed to trigger this parser CPU-exhaustion bug. Tracked for upgrade to sqlparse 0.6.0 once impact of the bump on analyzer extensions is validated (EXTSDK-9). |
| analysis-node | CVE-2026-54369 | HIGH | libacl1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| analysis-node | CVE-2026-59893 | HIGH | sqlparse | Not Affected | sqlparse is used by cast_application_api (sql_tool / _execute_raw_query) only to split and format SQL text that comes from the extension’s own bundled SQL scripts. No analyzer extension builds these query strings dynamically from external or source-code-derived input, so no adversary can supply the crafted dollar-quoted SQL needed to trigger this parser ReDoS bug. Tracked for upgrade to sqlparse 0.6.0 once impact of the bump on analyzer extensions is validated (EXTSDK-9). |
| analysis-node | CVE-2026-71491 | HIGH | sqlparse | Not Affected | sqlparse is used by cast_application_api (sql_tool / _execute_raw_query) only to split and format SQL text that comes from the extension’s own bundled SQL scripts. No analyzer extension builds these query strings dynamically from external or source-code-derived input, so no adversary can supply the crafted comment-only SQL needed to trigger this parser CPU-exhaustion bug. Tracked for upgrade to sqlparse 0.6.0 once impact of the bump on analyzer extensions is validated (EXTSDK-9). |
| auth-service | CVE-2026-14456 | HIGH | libcrypto3 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| auth-service | CVE-2026-54512 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| auth-service | CVE-2026-54513 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| console | CVE-2017-0247 | HIGH | Not Affected | False Positive; Actual implementation uses Mono, which is not affected by this CVE | |
| console | CVE-2017-0249 | HIGH | Not Affected | False Positive; Actual implementation uses Mono, which is not affected by this CVE | |
| console | CVE-2017-11770 | HIGH | Not Affected | False Positive; Actual implementation uses Mono, which is not affected by this CVE | |
| console | CVE-2024-0056 | HIGH | Not Affected | ||
| console | CVE-2025-60876 | HIGH | Not Affected | added to test temporary if VEX is working (IMAGKSL-4923) | |
| dashboards-v3 | CVE-2026-14456 | HIGH | libcrypto3 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| dashboards-v3 | CVE-2026-65182 | CRITICAL | tomcat-embed-core | Fix Incoming | Pending review. |
| dashboards-v3 | CVE-2026-65905 | CRITICAL | tomcat-embed-core | Fix Incoming | Pending review. |
| dashboards-v3 | CVE-2026-66046 | HIGH | libexpat | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| dashboards-v3 | CVE-2026-68525 | CRITICAL | tomcat-embed-core | Fix Incoming | Pending review. |
| dashboards-v3 | CVE-2026-76641 | HIGH | libexpat | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| extend-proxy | CVE-2024-10491 | HIGH | express | Not Affected | Version-range false positive. The authoritative advisory (GitHub Advisory Database GHSA-cm5g-3pgc-8rg4, and Snyk SNYK-JS-EXPRESS-8310337) scopes this vulnerability to express 3.0.0-alpha1 through 3.21.4 inclusive, with the fix released in express 4.0.0-rc1. The image ships express 5.2.1, which is two major versions beyond the patched release, so the vulnerable revision of the response.links implementation is not present in the product. Independently corroborated by this image’s own scan results: Trivy indexed every npm package in /opt/cast_extend_proxy/app and raised no finding against express, as did Grype. |
| extend-proxy | sonatype-2016-0121 | HIGH | multer | Not Affected | RESOLVED BY RISK ACCEPTANCE - not suppressed; residual gaps are disclosed below. multer 2.2.0 is present and on the execute path of both upload endpoints, and the underlying behaviour the advisory describes (multer consuming the full stream before enforcing a fileSize limit) is unchanged in this version - no upgrade exists or would change it, 2.2.0 is the latest published release. CAST product ownership judges the vulnerability class adequately mitigated in this product by the combination of: (1) both the primary upload endpoint (package-controller.js, POST /upload) and the bundle upload endpoint (bundle-controller.js) require a valid proxy API key, so neither is anonymously reachable; (2) the primary endpoint sets limits.fileSize to 1 GB, comfortably above the largest legitimate extension package published to date (192 MB), bounding the heap-exhaustion vector on that path; (3) custom-extension upload is a low-usage feature exercised by a small minority of customers, materially reducing real-world exposure versus a default, high-traffic endpoint. Two gaps remain open and are disclosed rather than hidden: the bundle upload endpoint (bundle-controller.js) still sets no fileSize limit of its own - it is disk-backed rather than memory-backed, so its exposure is disk consumption, not heap exhaustion; and multer’s abortWithError does not unpipe or destroy the request stream on the LIMIT_FILE_SIZE path, so bytes up to the configured cap are still read and discarded rather than the connection being torn down early. If either gap is later judged material - for example if bundle upload usage increases - this statement should be revisited. Tracked in EXTPROXY-198. |
| extend-proxy | sonatype-2019-0159 | HIGH | lunr | Not Affected | RESOLVED - same attribution conflict as sonatype-2021-1683, resolved the same way. CAST confirmed directly with Sonatype that this identifier also matches ‘mocha’, not ’lunr’. Sonatype’s own published advisory page already described this as a ReDoS in mocha (issue 3416 / PR 3686) with a matching CVSS score and vector. mocha is a devDependency removed from the runtime artifact by ’npm prune –production’; there is no node_modules/mocha in the shipped image. See the sonatype-2021-1683 statement for the full reasoning. Tracked in EXTPROXY-198. |
| extend-proxy | sonatype-2021-0078 | HIGH | express | Not Affected | Per Sonatype’s own published advisory text (guide.sonatype.com/vulnerability/sonatype-2021-0078), this is a component-combination vulnerability that requires the ‘hbs’ Handlebars templating engine to be used alongside express. Neither ‘hbs’ nor ‘handlebars’ appears in the extend-proxy dependency manifest, in package-lock.json, or anywhere in the shipped image: a path scan of the exported filesystem for node_modules/hbs and node_modules/handlebars returns no match. The proxy renders no server-side templates. The required co-component is absent, so the vulnerable combination cannot exist in this product. |
| extend-proxy | sonatype-2021-1683 | HIGH | lunr | Not Affected | RESOLVED - CAST queried Sonatype directly on the component-coordinate conflict described in the prior revision of this statement and confirmed the identifier matches ‘mocha’, not ’lunr’. Sonatype’s own published advisory page already described this as a ReDoS in mocha (issue 4766 / PR 4770) with a CVSS score and vector matching this finding exactly; the customer-supplied Nexus IQ report’s attribution to ’lunr : 2.3.9’ is a component mis-attribution in the IQ match result. mocha is declared solely in devDependencies and is removed from the runtime artifact by ’npm prune –production’: a path scan of the exported filesystem of castimaging/extend-proxy confirms there is no node_modules/mocha in the shipped image. The component the advisory defines is therefore not present in this product. Tracked in EXTPROXY-198. |
| gateway | CVE-2026-14456 | HIGH | libcrypto3 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| gateway | CVE-2026-54512 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| gateway | CVE-2026-54513 | HIGH | Not Affected | This service uses jackson-databind only for concrete-type deserialization (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be enabled, which is absent in this codebase. | |
| imaging-apis | CVE-2026-66046 | HIGH | libexpat | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-apis | CVE-2026-76641 | HIGH | libexpat | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2013-7445 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2019-19449 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2019-19814 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2021-3847 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2021-3864 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2024-21803 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2024-58015 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-22104 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-38137 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-38187 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-38204 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-38206 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-38421 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-38636 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-39859 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-39862 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-39958 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-69720 | HIGH | libncursesw6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-11822 | HIGH | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-11824 | HIGH | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-23102 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-23208 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-23327 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-31493 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-31536 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-31568 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-43185 | CRITICAL | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-43198 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-43263 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-46130 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-46181 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-46279 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-52991 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-53000 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-53010 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-53089 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-53091 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-53109 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-53118 | HIGH | linux-libc-dev | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| init-util | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| neo4j | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-10050 | HIGH | jetty-ee8-security | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-14456 | HIGH | libssl3t64 | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-41992 | HIGH | gzip | Fix Incoming | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-54369 | HIGH | libacl1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| neo4j | CVE-2026-54399 | HIGH | httpcore5 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-54428 | HIGH | httpcore5-h2 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-54512 | HIGH | jackson-databind | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-54513 | HIGH | jackson-databind | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-55831 | HIGH | netty-codec-http | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-55833 | HIGH | netty-codec-http | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-55851 | HIGH | netty-codec-haproxy | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-56745 | HIGH | netty-codec-http | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-56816 | HIGH | netty-codec-http3 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-56819 | HIGH | netty-codec-http2 | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-59901 | HIGH | netty-codec-compression | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-75595 | CRITICAL | netty-handler | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | GHSA-r7wm-3cxj-wff9 | HIGH | jackson-core | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| sso-service | CVE-2025-15281 | HIGH | Fix Incoming | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| sso-service | CVE-2025-59250 | HIGH | mssql-jdbc | False Positive | Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier. |
| sso-service | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| sso-service | CVE-2026-0861 | HIGH | Fix Incoming | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| sso-service | CVE-2026-0915 | HIGH | Fix Incoming | No fix version available as of 2026-06-15. Added automatically by CVE auto-fix pipeline (IMAGKSL-4922). | |
| sso-service | CVE-2026-16742 | HIGH | libsystemd0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| sso-service | CVE-2026-54369 | HIGH | libacl1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| sso-service | CVE-2026-54512 | HIGH | Not Affected | CAST-developed code in this Keycloak-based service (themes, API key extension) uses no polymorphic type handling (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be active, which is absent from the CAST codebase bundled here. | |
| sso-service | CVE-2026-54513 | HIGH | Not Affected | CAST-developed code in this Keycloak-based service (themes, API key extension) uses no polymorphic type handling (no activateDefaultTyping or @JsonTypeInfo). The PolymorphicTypeValidator bypass exploited by this CVE requires polymorphic type handling to be active, which is absent from the CAST codebase bundled here. |