Skip to content

[vuln-scan] HIGH/CRITICAL findings in cds-dagster #485

Description

@github-actions

HIGH/CRITICAL vulnerabilities detected

  • Scanned target: ghcr.io/ronaldhensbergen/cds-dagster@sha256:dd5aec785cbbc9f840908c2f976d84918dd04282250c8d27785cb01f21176da9
  • Pipeline run: Image Security Scan

https://github.com/RonaldHensbergen/composable-data-stack/actions/runs/32550448352

  • SLA: HIGH and CRITICAL findings must be remediated by 2026-08-25 (see docs/image-scanning.md). Open a Renovate/dependency bump or a rebuild PR, or file an exception per docs/image-scanning.md.

Findings


Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬────────────┬─────────────────┐
│                                      Target                                      │    Type    │ Vulnerabilities │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ ghcr.io/ronaldhensbergen/cds-dagster@sha256:dd5aec785cbbc9f840908c2f976d84918dd- │   debian   │       27        │
│ 04282250c8d27785cb01f21176da9 (debian 13.6)                                      │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/alembic-1.19.1.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/annotated_types-0.8.0.dist-info/METADATA   │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/antlr4_python3_runtime-4.13.2.dist-info/M- │ python-pkg │        0        │
│ ETADATA                                                                          │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/anyio-4.14.2.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/backoff-2.2.1.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/certifi-2026.7.22.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/charset_normalizer-3.5.1.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/click-8.4.2.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/coloredlogs-14.0.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dagster-1.13.18.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dagster_graphql-1.13.18.dist-info/METADATA │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dagster_pipes-1.13.18.dist-info/METADATA   │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dagster_postgres-0.29.18.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dagster_shared-1.13.18.dist-info/METADATA  │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/dagster_webserver-1.13.18.dist-info/METAD- │ python-pkg │        0        │
│ ATA                                                                              │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/docstring_parser-0.18.0.dist-info/METADATA │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/filelock-3.32.3.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/fsspec-2026.7.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/gql-4.0.0.dist-info/METADATA               │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/graphene-3.4.3.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/graphql_core-3.2.11.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/graphql_relay-3.2.0.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/greenlet-3.5.5.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/grpcio-1.83.0.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/grpcio_health_checking-1.81.1.dist-info/M- │ python-pkg │        0        │
│ ETADATA                                                                          │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/h11-0.16.0.dist-info/METADATA              │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/httptools-0.8.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/humanfriendly-10.0.dist-info/METADATA      │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/idna-3.19.dist-info/METADATA               │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/jinja2-3.1.6.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/mako-1.4.1.dist-info/METADATA              │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/markdown_it_py-4.2.0.dist-info/METADATA    │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/markupsafe-3.0.3.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/mdurl-0.1.2.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/msgpack-1.2.1.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/multidict-6.7.1.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/packaging-26.3.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pathlib_abc-0.5.2.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/platformdirs-4.11.3.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/propcache-0.5.2.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/protobuf-6.33.6.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/psycopg2_binary-2.9.12.dist-info/METADATA  │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pydantic-2.13.4.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pydantic_core-2.46.4.dist-info/METADATA    │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pygments-2.21.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/python_dateutil-2.9.0.post0.dist-info/MET- │ python-pkg │        0        │
│ ADATA                                                                            │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/python_dotenv-1.2.3.dist-info/METADATA     │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pytz-2026.3.post1.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/pyyaml-6.0.3.dist-info/METADATA            │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/requests-2.34.2.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/requests_toolbelt-1.0.0.dist-info/METADATA │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/rich-15.0.0.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools-84.0.0.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/autocommand-2.2.2.dist- │ python-pkg │        0        │
│ -info/METADATA                                                                   │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/backports.tarfile-1.2.- │ python-pkg │        0        │
│ 0.dist-info/METADATA                                                             │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/importlib_metadata-8.7- │ python-pkg │        0        │
│ .1.dist-info/METADATA                                                            │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/jaraco.text-4.0.0.dist- │ python-pkg │        0        │
│ -info/METADATA                                                                   │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/jaraco_context-6.1.0.d- │ python-pkg │        0        │
│ ist-info/METADATA                                                                │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/jaraco_functools-4.4.0- │ python-pkg │        0        │
│ .dist-info/METADATA                                                              │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/more_itertools-10.8.0.- │ python-pkg │        0        │
│ dist-info/METADATA                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/packaging-26.0.dist-in- │ python-pkg │        0        │
│ fo/METADATA                                                                      │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/platformdirs-4.4.0.dis- │ python-pkg │        0        │
│ t-info/METADATA                                                                  │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/tomli-2.4.0.dist-info/- │ python-pkg │        0        │
│ METADATA                                                                         │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/wheel-0.46.3.dist-info- │ python-pkg │        0        │
│ /METADATA                                                                        │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/setuptools/_vendor/zipp-3.23.0.dist-info/- │ python-pkg │        0        │
│ METADATA                                                                         │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/six-1.17.0.dist-info/METADATA              │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/sqlalchemy-2.0.52.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/starlette-1.6.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/structlog-26.1.0.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/tabulate-0.10.0.dist-info/METADATA         │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/tomli-2.4.1.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/tomlkit-0.15.1.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/toposort-1.10.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/tqdm-4.70.0.dist-info/METADATA             │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/typing_extensions-4.16.0.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/typing_inspection-0.4.4.dist-info/METADATA │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/tzdata-2026.3.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/universal_pathlib-0.3.10.dist-info/METADA- │ python-pkg │        0        │
│ TA                                                                               │            │                 │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/urllib3-2.7.0.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/uvicorn-0.52.4.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/uvloop-0.22.1.dist-info/METADATA           │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/watchdog-6.0.0.dist-info/METADATA          │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/watchfiles-1.2.0.dist-info/METADATA        │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/websockets-17.0.1.dist-info/METADATA       │ python-pkg │        0        │
├──────────────────────────────────────────────────────────────────────────────────┼────────────┼─────────────────┤
│ opt/venv/lib/python3.14/site-packages/yarl-1.24.5.dist-info/METADATA             │ python-pkg │        0        │
└──────────────────────────────────────────────────────────────────────────────────┴────────────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.74/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


ghcr.io/ronaldhensbergen/cds-dagster@sha256:dd5aec785cbbc9f840908c2f976d84918dd04282250c8d27785cb01f21176da9 (debian 13.6)
==========================================================================================================================
Total: 27 (HIGH: 27, CRITICAL: 0)

┌───────────────┬────────────────┬──────────┬────────┬─────────────────────────┬──────────────────┬────────────────────────────────────────────────────────────┐
│    Library    │ Vulnerability  │ Severity │ Status │    Installed Version    │  Fixed Version   │                           Title                            │
├───────────────┼────────────────┼──────────┼────────┼─────────────────────────┼──────────────────┼────────────────────────────────────────────────────────────┤
│ bsdutils      │ CVE-2026-53612 │ HIGH     │ fixed  │ 1:2.41-5                │ 2.41.5-0+deb13u1 │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        ├─────────────────────────┤                  ├────────────────────────────────────────────────────────────┤
│ libblkid1     │ CVE-2026-53612 │          │        │ 2.41-5                  │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ liblastlog2-2 │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ libmount1     │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ libsmartcols1 │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ libuuid1      │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        ├─────────────────────────┤                  ├────────────────────────────────────────────────────────────┤
│ login         │ CVE-2026-53612 │          │        │ 1:4.16.0-2+really2.41-5 │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        ├─────────────────────────┤                  ├────────────────────────────────────────────────────────────┤
│ mount         │ CVE-2026-53612 │          │        │ 2.41-5                  │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
├───────────────┼────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│ util-linux    │ CVE-2026-53612 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program when   │
│               │                │          │        │                         │                  │ applying post-mount ownership/mode changes...              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53612                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53613 │          │        │                         │                  │ util-linux: util-linux: TOCTOU in the mount program via    │
│               │                │          │        │                         │                  │ ancestor directory swap on...                              │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53613                 │
│               ├────────────────┤          │        │                         │                  ├────────────────────────────────────────────────────────────┤
│               │ CVE-2026-53614 │          │        │                         │                  │ util-linux: util-linux: SUID mount(8) allows nosuid/noexec │
│               │                │          │        │                         │                  │ bypass via LIBMOUNT_FORCE_MOUNT2                           │
│               │                │          │        │                         │                  │ https://avd.aquasec.com/nvd/cve-2026-53614                 │
└───────────────┴────────────────┴──────────┴────────┴─────────────────────────┴──────────────────┴────────────────────────────────────────────────────────────┘

Metadata

Metadata

Assignees

No one assigned

    Labels

    vuln-scanScheduled image scan found HIGH/CRITICAL vulnerabilities

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions