Skip to main content

Security Status

This page shows the current results of automated container-image vulnerability scans (Trivy) across the latest versions of the msg.ZenTestAI services.

Scans run automatically every day. Each service section below lists the Critical and High severity findings for:

  • latest — the latest release (main branch)
  • Previous releases — the latest patch of each of the two preceding minor releases

Only Critical and High severity CVEs are tracked on this page. Medium and Low severity findings are monitored internally and addressed during regular maintenance.

Individual findings that have been reviewed and accepted as not exploitable are documented per service. Fixes are shipped with the next regular release.

note

The timestamp in each section shows when the respective scan last ran. If the timestamp is older than 48 hours, please contact support.

Overview

ModuleCriticalHighScanned (UTC)
Frontend022026-07-12T05:09:06Z
Backend002026-07-09T11:21:51Z
Runner022026-09-20T04:04:08Z

Frontend

Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)

Latest versions

TargetCriticalHighScanned (UTC)
latest022026-07-12T05:09:06Z
1.20.1052026-07-12T05:07:46Z
1.19.28052026-07-12T05:08:19Z

Open findings

latest

CVESeverityPackageInstalledFixedTitle
CVE-2026-33630HIGHc-ares1.34.6-r01.34.8-r0c-ares: c-ares: Use-after-free / double-free in query-completion handling
CVE-2026-39822HIGHstdlibv1.26.41.25.12, 1.26.5, 1.27.0-rc.2os: golang: Go os.Root: Symlink following vulnerability allows directory traversal

1.20.1

CVESeverityPackageInstalledFixedTitle
CVE-2026-33630HIGHc-ares1.34.6-r01.34.8-r0c-ares: c-ares: Use-after-free / double-free in query-completion handling
CVE-2026-56131HIGHlibexpat2.8.1-r02.8.2-r0libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...
CVE-2026-56407HIGHlibexpat2.8.1-r02.8.2-r0libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...
CVE-2026-56408HIGHlibexpat2.8.1-r02.8.2-r0libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-39822HIGHstdlibv1.26.41.25.12, 1.26.5, 1.27.0-rc.2os: golang: Go os.Root: Symlink following vulnerability allows directory traversal

1.19.28

CVESeverityPackageInstalledFixedTitle
CVE-2026-33630HIGHc-ares1.34.6-r01.34.8-r0c-ares: c-ares: Use-after-free / double-free in query-completion handling
CVE-2026-56131HIGHlibexpat2.8.1-r02.8.2-r0libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...
CVE-2026-56407HIGHlibexpat2.8.1-r02.8.2-r0libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...
CVE-2026-56408HIGHlibexpat2.8.1-r02.8.2-r0libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-39822HIGHstdlibv1.26.41.25.12, 1.26.5, 1.27.0-rc.2os: golang: Go os.Root: Symlink following vulnerability allows directory traversal

Backend

Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)

Latest versions

TargetCriticalHighScanned (UTC)
latest002026-07-09T11:21:51Z
1.20.1002026-07-09T11:22:15Z

Open findings

No open CRITICAL or HIGH findings.


Runner

Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)

Latest versions

TargetCriticalHighScanned (UTC)
latest022026-09-20T04:04:08Z
1.23.200232026-09-20T04:06:09Z
1.22.60292026-09-20T04:06:06Z

Open findings

latest

CVESeverityPackageInstalledFixedTitle
CVE-2026-39244HIGHadm-zip0.5.170.6.0adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation
CVE-2026-77301HIGHadm-zip0.5.170.6.1adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)

1.23.20

CVESeverityPackageInstalledFixedTitle
CVE-2026-53612HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
CVE-2026-53613HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
CVE-2026-53614HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
CVE-2026-76642HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-78408HIGHlibblkid2.42.1-r02.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78409HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78410HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-53612HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
CVE-2026-53613HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
CVE-2026-53614HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
CVE-2026-76642HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-78408HIGHlibmount2.42.1-r02.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78409HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78410HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-53612HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
CVE-2026-53613HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
CVE-2026-53614HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
CVE-2026-76642HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-78408HIGHlibuuid2.42.1-r02.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78409HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78410HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-39244HIGHadm-zip0.5.170.6.0adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation
CVE-2026-77301HIGHadm-zip0.5.170.6.1adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)

1.22.6

CVESeverityPackageInstalledFixedTitle
CVE-2026-53612HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
CVE-2026-53613HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
CVE-2026-53614HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
CVE-2026-76642HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-78408HIGHlibblkid2.42.1-r02.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78409HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78410HIGHlibblkid2.42.1-r02.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-14456HIGHlibcrypto33.5.7-r13.5.8-r0openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
CVE-2026-66046HIGHlibexpat2.8.2-r02.8.4-r0expat: Expat: Denial of Service via quadratic complexity in attribute processing
CVE-2026-76956HIGHlibexpat2.8.2-r02.8.4-r0libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
CVE-2026-76957HIGHlibexpat2.8.2-r02.8.4-r0libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
CVE-2026-53612HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
CVE-2026-53613HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
CVE-2026-53614HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
CVE-2026-76642HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-78408HIGHlibmount2.42.1-r02.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78409HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78410HIGHlibmount2.42.1-r02.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-14456HIGHlibssl33.5.7-r13.5.8-r0openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server
CVE-2026-53612HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
CVE-2026-53613HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
CVE-2026-53614HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
CVE-2026-76642HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks
CVE-2026-78408HIGHlibuuid2.42.1-r02.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-78409HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks
CVE-2026-78410HIGHlibuuid2.42.1-r02.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
CVE-2026-39244HIGHadm-zip0.5.170.6.0adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation
CVE-2026-77301HIGHadm-zip0.5.170.6.1adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
GHSA-rgj7-g3m4-5g8cHIGHsharp0.35.30.35.4sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545