Skip to main content

Security Status

This page shows the current results of automated container-image vulnerability scans (Trivy) across the latest versions of the msg.ZenTestAI services.

Scans run automatically every day. Each service section below lists the Critical and High severity findings for:

  • latest — the latest release (main branch)
  • Previous releases — the latest patch of each of the two preceding minor releases

Only Critical and High severity CVEs are tracked on this page. Medium and Low severity findings are monitored internally and addressed during regular maintenance.

Individual findings that have been reviewed and accepted as not exploitable are documented per service. Fixes are shipped with the next regular release.

note

The timestamp in each section shows when the respective scan last ran. If the timestamp is older than 48 hours, please contact support.

Overview

ModuleCriticalHighScanned (UTC)
Frontend082026-05-27T05:32:54Z
Backend002026-05-27T05:30:26Z
Runner242026-05-27T05:28:09Z

Frontend

Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)

Latest versions

TargetCriticalHighScanned (UTC)
latest082026-05-27T05:32:54Z
1.15.16082026-05-27T05:33:14Z
1.14.18082026-05-27T05:32:30Z

Open findings

latest

CVESeverityPackageInstalledFixedTitle
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
CVE-2026-6321HIGHfast-uri3.1.03.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322HIGHfast-uri3.1.03.1.2fast-uri normalize() decoded percent-encoded authority delimiters insi ...
CVE-2026-33811HIGHstdlibv1.25.91.25.10, 1.26.3When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33814HIGHstdlibv1.25.91.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
CVE-2026-39820HIGHstdlibv1.25.91.25.10, 1.26.3Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39836HIGHstdlibv1.25.91.25.10, 1.26.3Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-42499HIGHstdlibv1.25.91.25.10, 1.26.3Pathological inputs could cause DoS through consumePhrase when parsing ...

1.15.16

CVESeverityPackageInstalledFixedTitle
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
CVE-2026-6321HIGHfast-uri3.1.03.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322HIGHfast-uri3.1.03.1.2fast-uri normalize() decoded percent-encoded authority delimiters insi ...
CVE-2026-33811HIGHstdlibv1.25.91.25.10, 1.26.3When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33814HIGHstdlibv1.25.91.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
CVE-2026-39820HIGHstdlibv1.25.91.25.10, 1.26.3Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39836HIGHstdlibv1.25.91.25.10, 1.26.3Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-42499HIGHstdlibv1.25.91.25.10, 1.26.3Pathological inputs could cause DoS through consumePhrase when parsing ...

1.14.18

CVESeverityPackageInstalledFixedTitle
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
CVE-2026-6321HIGHfast-uri3.1.03.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322HIGHfast-uri3.1.03.1.2fast-uri normalize() decoded percent-encoded authority delimiters insi ...
CVE-2026-33811HIGHstdlibv1.25.91.25.10, 1.26.3When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33814HIGHstdlibv1.25.91.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
CVE-2026-39820HIGHstdlibv1.25.91.25.10, 1.26.3Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39836HIGHstdlibv1.25.91.25.10, 1.26.3Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-42499HIGHstdlibv1.25.91.25.10, 1.26.3Pathological inputs could cause DoS through consumePhrase when parsing ...

Backend

Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)

Latest versions

TargetCriticalHighScanned (UTC)
latest002026-05-27T05:30:26Z
1.15.17002026-05-27T05:30:05Z
1.14.19012026-05-27T05:30:04Z

Open findings

1.14.19

CVESeverityPackageInstalledFixedTitle
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

Runner

Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)

Latest versions

TargetCriticalHighScanned (UTC)
latest242026-05-27T05:28:09Z
1.15.20242026-05-27T05:27:59Z
1.14.274102026-05-27T05:26:28Z

Open findings

latest

CVESeverityPackageInstalledFixedTitle
CVE-2026-3593CRITICALbind-libs9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-libs9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-libs9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-3593CRITICALbind-tools9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-tools9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-tools9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN

1.15.20

CVESeverityPackageInstalledFixedTitle
CVE-2026-3593CRITICALbind-libs9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-libs9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-libs9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-3593CRITICALbind-tools9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-tools9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-tools9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN

1.14.27

CVESeverityPackageInstalledFixedTitle
CVE-2026-3593CRITICALbind-libs9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-libs9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-libs9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-3593CRITICALbind-tools9.20.22-r09.20.23-r0bind: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-3039HIGHbind-tools9.20.22-r09.20.23-r0bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-5946HIGHbind-tools9.20.22-r09.20.23-r0bind: Invalid handling of CLASS != IN
CVE-2026-34980HIGHcups-libs2.4.16-r02.4.18-r0cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
CVE-2026-33845CRITICALgnutls3.8.12-r03.8.13-r0gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
CVE-2026-42010CRITICALgnutls3.8.12-r03.8.13-r0gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-33846HIGHgnutls3.8.12-r03.8.13-r0gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly
CVE-2026-3833HIGHgnutls3.8.12-r03.8.13-r0gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-42009HIGHgnutls3.8.12-r03.8.13-r0gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-41254HIGHlcms22.16-r02.19-r0Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
CVE-2026-27135HIGHnghttp2-libs1.65.0-r01.68.1nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination