Security Status
This page shows the current results of automated container-image vulnerability scans (Trivy) across the latest versions of the msg.ZenTestAI services.
Scans run automatically every day. Each service section below lists the Critical and High severity findings for:
- latest — the latest release (main branch)
- Previous releases — the latest patch of each of the two preceding minor releases
Only Critical and High severity CVEs are tracked on this page. Medium and Low severity findings are monitored internally and addressed during regular maintenance.
Individual findings that have been reviewed and accepted as not exploitable are documented per service. Fixes are shipped with the next regular release.
The timestamp in each section shows when the respective scan last ran. If the timestamp is older than 48 hours, please contact support.
Overview
| Module | Critical | High | Scanned (UTC) |
|---|---|---|---|
| Frontend | 0 | 2 | 2026-07-12T05:09:06Z |
| Backend | 0 | 0 | 2026-07-09T11:21:51Z |
| Runner | 0 | 2 | 2026-09-20T04:04:08Z |
Frontend
Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)
Latest versions
| Target | Critical | High | Scanned (UTC) |
|---|---|---|---|
| latest | 0 | 2 | 2026-07-12T05:09:06Z |
| 1.20.1 | 0 | 5 | 2026-07-12T05:07:46Z |
| 1.19.28 | 0 | 5 | 2026-07-12T05:08:19Z |
Open findings
latest
| CVE | Severity | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CVE-2026-33630 | HIGH | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| CVE-2026-39822 | HIGH | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
1.20.1
| CVE | Severity | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CVE-2026-33630 | HIGH | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| CVE-2026-56131 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 lacks handler call depth tracking for calls to X ... |
| CVE-2026-56407 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in doProlog that is rela ... |
| CVE-2026-56408 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-39822 | HIGH | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
1.19.28
| CVE | Severity | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CVE-2026-33630 | HIGH | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling |
| CVE-2026-56131 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 lacks handler call depth tracking for calls to X ... |
| CVE-2026-56407 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in doProlog that is rela ... |
| CVE-2026-56408 | HIGH | libexpat | 2.8.1-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-39822 | HIGH | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
Backend
Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)
Latest versions
| Target | Critical | High | Scanned (UTC) |
|---|---|---|---|
| latest | 0 | 0 | 2026-07-09T11:21:51Z |
| 1.20.1 | 0 | 0 | 2026-07-09T11:22:15Z |
Open findings
No open CRITICAL or HIGH findings.
Runner
Severity filter: CRITICAL, HIGH (MEDIUM/LOW not tracked)
Latest versions
| Target | Critical | High | Scanned (UTC) |
|---|---|---|---|
| latest | 0 | 2 | 2026-09-20T04:04:08Z |
| 1.23.20 | 0 | 23 | 2026-09-20T04:06:09Z |
| 1.22.6 | 0 | 29 | 2026-09-20T04:06:06Z |
Open findings
latest
| CVE | Severity | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CVE-2026-39244 | HIGH | adm-zip | 0.5.17 | 0.6.0 | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation |
| CVE-2026-77301 | HIGH | adm-zip | 0.5.17 | 0.6.1 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
1.23.20
| CVE | Severity | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CVE-2026-53612 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-53612 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-53612 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-39244 | HIGH | adm-zip | 0.5.17 | 0.6.0 | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation |
| CVE-2026-77301 | HIGH | adm-zip | 0.5.17 | 0.6.1 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
1.22.6
| CVE | Severity | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| CVE-2026-53612 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libblkid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-14456 | HIGH | libcrypto3 | 3.5.7-r1 | 3.5.8-r0 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-66046 | HIGH | libexpat | 2.8.2-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via quadratic complexity in attribute processing |
| CVE-2026-76956 | HIGH | libexpat | 2.8.2-r0 | 2.8.4-r0 | libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML |
| CVE-2026-76957 | HIGH | libexpat | 2.8.2-r0 | 2.8.4-r0 | libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service |
| CVE-2026-53612 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libmount | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-14456 | HIGH | libssl3 | 3.5.7-r1 | 3.5.8-r0 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-53612 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| CVE-2026-53613 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| CVE-2026-53614 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| CVE-2026-76642 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks |
| CVE-2026-78408 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority |
| CVE-2026-78409 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks |
| CVE-2026-78410 | HIGH | libuuid | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection |
| CVE-2026-39244 | HIGH | adm-zip | 0.5.17 | 0.6.0 | adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation |
| CVE-2026-77301 | HIGH | adm-zip | 0.5.17 | 0.6.1 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
| GHSA-rgj7-g3m4-5g8c | HIGH | sharp | 0.35.3 | 0.35.4 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |