Sicherheitsstatus
Diese Seite zeigt die aktuellen Ergebnisse automatisierter Schwachstellen-Scans von Container-Images (Trivy) über die neuesten Versionen der msg.ZenTestAI-Dienste.
Scans werden täglich automatisch durchgeführt. Jeder Dienstabschnitt unten listet die Befunde mit den Schweregraden „Kritisch“ und „Hoch“ auf für:
- latest — das neueste Release (main branch)
- Vorherige Releases — der letzte Patch jedes der beiden vorangegangenen Minor-Releases
Nur CVEs mit den Schweregraden Kritisch und Hoch werden auf dieser Seite verfolgt. Befunde mit den Schweregraden „Mittel“ und „Niedrig“ werden intern überwacht und im Rahmen der regulären Wartung behoben.
Individuelle Befunde, die überprüft und als nicht ausnutzbar eingestuft wurden, sind pro Dienst dokumentiert. Korrekturen werden mit dem nächsten regulären Release bereitgestellt.
Der Zeitstempel in jedem Abschnitt zeigt an, wann der jeweilige Scan zuletzt ausgeführt wurde. Wenn der Zeitstempel älter als 48 Stunden ist, wenden Sie sich bitte an den Support.
Übersicht
| Modul | Kritisch | Hoch | Gescant (UTC) |
|---|---|---|---|
| Frontend | 0 | 2 | 2026-07-12T05:09:06Z |
| Backend | 0 | 0 | 2026-07-09T11:21:51Z |
| Runner | 0 | 2 | 2026-09-20T04:04:08Z |
Frontend
Schweregrad-Filter: KRITISCH, HOCH (MITTEL/NIEDRIG werden nicht verfolgt)
Neueste Versionen
| Ziel | Kritisch | Hoch | Gescant (UTC) |
|---|---|---|---|
| latest | 0 | 2 | 2026-07-12T05:09:06Z |
| 1.20.1 | 0 | 5 | 2026-07-12T05:07:46Z |
| 1.19.28 | 0 | 5 | 2026-07-12T05:08:19Z |
Offene Befunde
latest
| CVE | Schweregrad | Paket | Installiert | Behoben | Titel |
|---|---|---|---|---|---|
| CVE-2026-33630 | HIGH | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| CVE-2026-39822 | HIGH | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
1.20.1
| CVE | Schweregrad | Paket | Installiert | Behoben | Titel |
|---|---|---|---|---|---|
| CVE-2026-33630 | HIGH | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| CVE-2026-56131 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 lacks handler call depth tracking for calls to X ... |
| CVE-2026-56407 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in doProlog that is rela ... |
| CVE-2026-56408 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-39822 | HIGH | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
1.19.28
| CVE | Schweregrad | Paket | Installiert | Behoben | Titel |
|---|---|---|---|---|---|
| CVE-2026-33630 | HIGH | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| CVE-2026-56131 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 lacks handler call depth tracking for calls to X ... |
| CVE-2026-56407 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in doProlog that is rela ... |
| CVE-2026-56408 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-39822 | HIGH | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
Backend
Schweregrad-Filter: KRITISCH, HOCH (MITTEL/NIEDRIG werden nicht verfolgt)
Neueste Versionen
| Ziel | Kritisch | Hoch | Gescant (UTC) |
|---|---|---|---|
| latest | 0 | 0 | 2026-07-09T11:21:51Z |
| 1.20.1 | 0 | 0 | 2026-07-09T11:22:15Z |
Offene Befunde
Keine offenen KRITISCHEN oder HOHEN Befunde.
Runner
Schweregrad-Filter: KRITISCH, HOCH (MITTEL/NIEDRIG werden nicht verfolgt)
Neueste Versionen
| Ziel | Kritisch | Hoch | Gescant (UTC) |
|---|---|---|---|
| latest | 0 | 2 | 2026-09-20T04:04:08Z |
| 1.23.20 | 0 | 23 | 2026-09-20T04:06:09Z |
| 1.22.6 | 0 | 29 | 2026-09-20T04:06:06Z |
Offene Befunde
latest
| CVE | Schweregrad | Paket | Installiert | Behoben | Titel |
|---|---|---|---|---|---|
| CVE-2026-39244 | HIGH | adm-zip | 0.5.17 | 0.6.0 | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation |
| CVE-2026-77301 | HIGH | adm-zip | 0.5.17 | 0.6.1 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
1.23.20
| CVE | Schweregrad | Paket | Installiert | Behoben | Titel |
|---|---|---|---|---|---|
| CVE-2026-53612 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-53612 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-53612 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-39244 | HIGH | adm-zip | 0.5.17 | 0.6.0 | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation |
| CVE-2026-77301 | HIGH | adm-zip | 0.5.17 | 0.6.1 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
1.22.6
| CVE | Schweregrad | Paket | Installiert | Behoben | Titel |
|---|---|---|---|---|---|
| CVE-2026-53612 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-14456 | HIGH | libcrypto3 | 3.5.7-r1 | 3.5.8-r0 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-66046 | HIGH | libexpat | 2.8.2-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via quadratic complexity in attribute processing |
| CVE-2026-76956 | HIGH | libexpat | 2.8.2-r0 | 2.8.4-r0 | libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML |
| CVE-2026-76957 | HIGH | libexpat | 2.8.2-r0 | 2.8.4-r0 | libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service |
| CVE-2026-53612 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-14456 | HIGH | libssl3 | 3.5.7-r1 | 3.5.8-r0 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-53612 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-39244 | HIGH | adm-zip | 0.5.17 | 0.6.0 | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation |
| CVE-2026-77301 | HIGH | adm-zip | 0.5.17 | 0.6.1 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
| GHSA-rgj7-g3m4-5g8c | HIGH | sharp | 0.35.3 | 0.35.4 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |