Zum Hauptinhalt springen

Sicherheitsstatus

Diese Seite zeigt die aktuellen Ergebnisse automatisierter Schwachstellen-Scans von Container-Images (Trivy) über die neuesten Versionen der msg.ZenTestAI-Dienste.

Scans werden täglich automatisch durchgeführt. Jeder Dienstabschnitt unten listet die Befunde mit den Schweregraden „Kritisch“ und „Hoch“ auf für:

  • latest — das neueste Release (main branch)
  • Vorherige Releases — der letzte Patch jedes der beiden vorangegangenen Minor-Releases

Nur CVEs mit den Schweregraden Kritisch und Hoch werden auf dieser Seite verfolgt. Befunde mit den Schweregraden „Mittel“ und „Niedrig“ werden intern überwacht und im Rahmen der regulären Wartung behoben.

Individuelle Befunde, die überprüft und als nicht ausnutzbar eingestuft wurden, sind pro Dienst dokumentiert. Korrekturen werden mit dem nächsten regulären Release bereitgestellt.

hinweis

Der Zeitstempel in jedem Abschnitt zeigt an, wann der jeweilige Scan zuletzt ausgeführt wurde. Wenn der Zeitstempel älter als 48 Stunden ist, wenden Sie sich bitte an den Support.

Übersicht

ModulKritischHochGescant (UTC)
Frontend082026-05-27T05:32:54Z
Backend002026-05-27T05:30:26Z
Runner242026-05-27T05:28:09Z

Frontend

Schweregrad-Filter: KRITISCH, HOCH (MITTEL/NIEDRIG werden nicht verfolgt)

Neueste Versionen

ZielKritischHochGescant (UTC)
latest082026-05-27T05:32:54Z
1.15.16082026-05-27T05:33:14Z
1.14.18082026-05-27T05:32:30Z

Offene Befunde

latest

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
CVE-2026-6321HIGHfast-uri3.1.03.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322HIGHfast-uri3.1.03.1.2fast-uri normalize() decoded percent-encoded authority delimiters insi ...
CVE-2026-33811HIGHstdlibv1.25.91.25.10, 1.26.3When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33814HIGHstdlibv1.25.91.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
CVE-2026-39820HIGHstdlibv1.25.91.25.10, 1.26.3Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39836HIGHstdlibv1.25.91.25.10, 1.26.3Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-42499HIGHstdlibv1.25.91.25.10, 1.26.3Pathological inputs could cause DoS through consumePhrase when parsing ...

1.15.16

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
CVE-2026-6321HIGHfast-uri3.1.03.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322HIGHfast-uri3.1.03.1.2fast-uri normalize() decoded percent-encoded authority delimiters insi ...
CVE-2026-33811HIGHstdlibv1.25.91.25.10, 1.26.3When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33814HIGHstdlibv1.25.91.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
CVE-2026-39820HIGHstdlibv1.25.91.25.10, 1.26.3Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39836HIGHstdlibv1.25.91.25.10, 1.26.3Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-42499HIGHstdlibv1.25.91.25.10, 1.26.3Pathological inputs could cause DoS through consumePhrase when parsing ...

1.14.18

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
CVE-2026-6321HIGHfast-uri3.1.03.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322HIGHfast-uri3.1.03.1.2fast-uri normalize() decoded percent-encoded authority delimiters insi ...
CVE-2026-33811HIGHstdlibv1.25.91.25.10, 1.26.3When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33814HIGHstdlibv1.25.91.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
CVE-2026-39820HIGHstdlibv1.25.91.25.10, 1.26.3Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39836HIGHstdlibv1.25.91.25.10, 1.26.3Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-42499HIGHstdlibv1.25.91.25.10, 1.26.3Pathological inputs could cause DoS through consumePhrase when parsing ...

Backend

Schweregrad-Filter: KRITISCH, HOCH (MITTEL/NIEDRIG werden nicht verfolgt)

Neueste Versionen

ZielKritischHochGescant (UTC)
latest002026-05-27T05:30:26Z
1.15.17002026-05-27T05:30:05Z
1.14.19012026-05-27T05:30:04Z

Offene Befunde

1.14.19

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

Runner

Schweregrad-Filter: KRITISCH, HOCH (MITTEL/NIEDRIG werden nicht verfolgt)

Neueste Versionen

ZielKritischHochGescant (UTC)
latest242026-05-27T05:28:09Z
1.15.20242026-05-27T05:27:59Z
1.14.274102026-05-27T05:26:28Z

Offene Befunde

latest

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-3593CRITICALbind-libs9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-libs9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-libs9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-3593CRITICALbind-tools9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-tools9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-tools9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN

1.15.20

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-3593CRITICALbind-libs9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-libs9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-libs9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-3593CRITICALbind-tools9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-tools9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-tools9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN

1.14.27

CVESchweregradPaketInstalliertBehobenTitel
CVE-2026-3593CRITICALbind-libs9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-libs9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-libs9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-3593CRITICALbind-tools9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-tools9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-tools9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-34980HIGHcups-libs2.4.16-r02.4.18-r0cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
CVE-2026-33845CRITICALgnutls3.8.12-r03.8.13-r0gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
CVE-2026-42010CRITICALgnutls3.8.12-r03.8.13-r0gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-33846HIGHgnutls3.8.12-r03.8.13-r0gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly
CVE-2026-3833HIGHgnutls3.8.12-r03.8.13-r0gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-42009HIGHgnutls3.8.12-r03.8.13-r0gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-41254HIGHlcms22.16-r02.19-r0Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination