3.6.3 — Security fixes



Fixes provided in 3.6.3

75 CVE(s) fixed compared to the previous release.

Service CVE Severity Package Previously affected
admin-center CVE-2026-41284 HIGH tomcat-embed-core 3.6.2
admin-center CVE-2026-41293 CRITICAL tomcat-embed-core 3.6.2
admin-center CVE-2026-42498 HIGH tomcat-embed-core 3.6.2
admin-center CVE-2026-43512 CRITICAL tomcat-embed-core 3.6.2
admin-center CVE-2026-43513 HIGH tomcat-embed-core 3.6.2
admin-center CVE-2026-43515 CRITICAL tomcat-embed-core 3.6.2
console CVE-2026-41284 HIGH tomcat-embed-core 3.6.2
console CVE-2026-41293 CRITICAL tomcat-embed-core 3.6.2
console CVE-2026-42498 HIGH tomcat-embed-core 3.6.2
console CVE-2026-43512 CRITICAL tomcat-embed-core 3.6.2
console CVE-2026-43513 HIGH tomcat-embed-core 3.6.2
console CVE-2026-43515 CRITICAL tomcat-embed-core 3.6.2
dashboards-v3 CVE-2025-14813 CRITICAL bcprov-jdk18on 3.6.2
dashboards-v3 CVE-2026-25680 HIGH golang.org/x/net 3.6.2
dashboards-v3 CVE-2026-25681 HIGH golang.org/x/net 3.6.2
dashboards-v3 CVE-2026-27136 HIGH golang.org/x/net 3.6.2
dashboards-v3 CVE-2026-33811 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-33814 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-39820 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-39821 HIGH golang.org/x/net 3.6.2
dashboards-v3 CVE-2026-39823 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-39825 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-39836 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-40973 HIGH spring-boot 3.6.2
dashboards-v3 CVE-2026-41284 HIGH tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-41293 CRITICAL tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-42198 HIGH postgresql 3.6.2
dashboards-v3 CVE-2026-42498 HIGH tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-42499 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-42502 HIGH golang.org/x/net 3.6.2
dashboards-v3 CVE-2026-42504 HIGH stdlib 3.6.2
dashboards-v3 CVE-2026-42506 HIGH golang.org/x/net 3.6.2
dashboards-v3 CVE-2026-43512 CRITICAL tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-43513 HIGH tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-43515 CRITICAL tomcat-embed-core 3.6.2
etl-service CVE-2026-33811 HIGH stdlib 3.6.2
etl-service CVE-2026-33814 HIGH stdlib 3.6.2
etl-service CVE-2026-39820 HIGH stdlib 3.6.2
etl-service CVE-2026-39823 HIGH stdlib 3.6.2
etl-service CVE-2026-39825 HIGH stdlib 3.6.2
etl-service CVE-2026-39836 HIGH stdlib 3.6.2
etl-service CVE-2026-42499 HIGH stdlib 3.6.2
gateway CVE-2026-41284 HIGH tomcat-embed-core 3.6.2
gateway CVE-2026-41293 CRITICAL tomcat-embed-core 3.6.2
gateway CVE-2026-42498 HIGH tomcat-embed-core 3.6.2
gateway CVE-2026-43512 CRITICAL tomcat-embed-core 3.6.2
gateway CVE-2026-43513 HIGH tomcat-embed-core 3.6.2
gateway CVE-2026-43515 CRITICAL tomcat-embed-core 3.6.2
imaging-mcp-server CVE-2026-48526 HIGH PyJWT 3.0.1
imaging-mcp-server CVE-2026-48818 HIGH starlette 3.0.1
imaging-mcp-server CVE-2026-49852 HIGH joserfc 3.0.1
imaging-mcp-server CVE-2026-52869 HIGH mcp 3.0.1
imaging-mcp-server CVE-2026-52870 HIGH mcp 3.0.1
imaging-mcp-server CVE-2026-53539 HIGH python-multipart 3.0.1
imaging-mcp-server GHSA-4w2j-m93h-cj5j HIGH quinn-proto 3.0.1
neo4j CVE-2026-33811 HIGH stdlib 3.6.2
neo4j CVE-2026-33814 HIGH stdlib 3.6.2
neo4j CVE-2026-39820 HIGH stdlib 3.6.2
neo4j CVE-2026-39823 HIGH stdlib 3.6.2
neo4j CVE-2026-39825 HIGH stdlib 3.6.2
neo4j CVE-2026-39826 HIGH stdlib 3.6.2
neo4j CVE-2026-39836 HIGH stdlib 3.6.2
neo4j CVE-2026-42499 HIGH stdlib 3.6.2
neo4j CVE-2026-55851 HIGH netty-codec-haproxy 3.6.2
sso-service CVE-2026-29111 HIGH libsystemd0 3.6.2
sso-service CVE-2026-42578 HIGH netty-handler-proxy 3.6.2
sso-service CVE-2026-42579 CRITICAL netty-codec-dns 3.6.2
sso-service CVE-2026-4878 HIGH libcap2 3.6.2
viewer CVE-2026-33811 HIGH stdlib 3.6.2
viewer CVE-2026-33814 HIGH stdlib 3.6.2
viewer CVE-2026-39820 HIGH stdlib 3.6.2
viewer CVE-2026-39823 HIGH stdlib 3.6.2
viewer CVE-2026-39825 HIGH stdlib 3.6.2
viewer CVE-2026-39836 HIGH stdlib 3.6.2
viewer CVE-2026-42499 HIGH stdlib 3.6.2

Security patch 3.6.3.1

93 CVE(s) fixed in the 3.6.3.1 security patch.

Service CVE Severity Package Previously affected
ai-service CVE-2026-25087 HIGH pyarrow 3.6.3
ai-service CVE-2026-4372 HIGH transformers 3.6.2
ai-service CVE-2026-44843 HIGH langchain-core 3.6.3
ai-service CVE-2026-45134 HIGH langchain-classic 3.6.3
ai-service CVE-2026-5241 HIGH transformers 3.6.2
ai-service GHSA-xf7x-x43h-rpqh HIGH json_repair 3.6.3
etl-service CVE-2026-39827 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-39828 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-39829 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-39830 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-39835 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-42508 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-46595 HIGH golang.org/x/crypto 3.6.2
etl-service CVE-2026-46597 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2025-22868 HIGH golang.org/x/oauth2 3.6.3
imaging-apis CVE-2026-25680 HIGH golang.org/x/net 3.6.2
imaging-apis CVE-2026-25681 HIGH golang.org/x/net 3.6.2
imaging-apis CVE-2026-27136 HIGH golang.org/x/net 3.6.2
imaging-apis CVE-2026-39821 HIGH golang.org/x/net 3.6.2
imaging-apis CVE-2026-39827 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-39828 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-39829 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-39830 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-39835 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-42502 HIGH golang.org/x/net 3.6.2
imaging-apis CVE-2026-42506 HIGH golang.org/x/net 3.6.2
imaging-apis CVE-2026-42508 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-46595 HIGH golang.org/x/crypto 3.6.2
imaging-apis CVE-2026-46597 HIGH golang.org/x/crypto 3.6.2
imaging-mcp-server CVE-2025-15281 HIGH 3.0.2
imaging-mcp-server CVE-2025-62727 HIGH starlette 3.0.2
imaging-mcp-server CVE-2025-64439 HIGH langgraph-checkpoint 3.0.2
imaging-mcp-server CVE-2025-65106 HIGH langchain-core 3.0.2
imaging-mcp-server CVE-2025-66416 HIGH mcp 3.0.2
imaging-mcp-server CVE-2025-67221 HIGH orjson 3.0.2
imaging-mcp-server CVE-2025-68664 CRITICAL langchain-core 3.0.2
imaging-mcp-server CVE-2025-69196 HIGH fastmcp 3.0.2
imaging-mcp-server CVE-2026-0861 HIGH 3.0.2
imaging-mcp-server CVE-2026-0915 HIGH 3.0.2
imaging-mcp-server CVE-2026-23949 HIGH jaraco.context 3.0.2
imaging-mcp-server CVE-2026-24049 HIGH wheel 3.0.2
imaging-mcp-server CVE-2026-26007 HIGH cryptography 3.0.2
imaging-mcp-server CVE-2026-27124 HIGH fastmcp 3.0.2
imaging-mcp-server CVE-2026-27135 HIGH nghttp2-libs 3.0.1
imaging-mcp-server CVE-2026-32871 CRITICAL fastmcp 3.0.2
imaging-mcp-server CVE-2026-34070 HIGH langchain-core 3.0.2
imaging-mcp-server CVE-2026-34444 HIGH lupa 3.0.2
imaging-mcp-server CVE-2026-44431 HIGH urllib3 3.0.2
imaging-mcp-server CVE-2026-44432 HIGH urllib3 3.0.1
imaging-mcp-server CVE-2026-44843 HIGH langchain-core 3.0.1
imaging-mcp-server CVE-2026-45134 HIGH langsmith 3.0.1
imaging-mcp-server CVE-2026-45447 HIGH libssl3t64 3.0.2
imaging-mcp-server CVE-2026-48818 HIGH starlette 3.0.2
imaging-mcp-server CVE-2026-54283 HIGH starlette 3.0.1
imaging-mcp-server CVE-2026-69249 HIGH cryptography 3.0.1
imaging-mcp-server CVE-2026-9669 HIGH 3.0.2
imaging-mcp-server GHSA-537c-gmf6-5ccf HIGH cryptography 3.0.1
imaging-mcp-server GHSA-82j2-j2ch-gfr8 HIGH rustls-webpki 3.0.1
imaging-mcp-server GHSA-c2jp-c369-7pvx HIGH fastmcp 3.0.2
imaging-mcp-server GHSA-f4xh-w4cj-qxq8 HIGH langsmith 3.0.1
imaging-mcp-server GHSA-rcfx-77hg-w2wv HIGH fastmcp 3.0.2
init-util CVE-2025-59375 HIGH libexpat1 1.2.11
init-util CVE-2026-11822 HIGH libsqlite3-0 1.2.10
init-util CVE-2026-11824 HIGH libsqlite3-0 1.2.10
init-util CVE-2026-24882 HIGH gpgv 1.2.11
init-util CVE-2026-25210 HIGH libexpat1 1.2.11
init-util CVE-2026-42496 CRITICAL libperl5.40 1.2.11
init-util CVE-2026-42497 HIGH libperl5.40 1.2.11
init-util CVE-2026-45186 HIGH libexpat1 1.2.11
init-util CVE-2026-45447 HIGH libssl3t64 1.2.11
init-util CVE-2026-48959 HIGH libperl5.40 1.2.11
init-util CVE-2026-48962 HIGH libperl5.40 1.2.11
init-util CVE-2026-5773 HIGH curl 1.2.11
init-util CVE-2026-6276 HIGH curl 1.2.11
init-util CVE-2026-7210 CRITICAL libpython3.13-minimal 1.2.11
init-util CVE-2026-7598 HIGH libssh2-1t64 1.2.11
init-util CVE-2026-8376 CRITICAL libperl5.40 1.2.11
init-util CVE-2026-9538 HIGH libperl5.40 1.2.11
init-util CVE-2026-9669 HIGH libpython3.13-minimal 1.2.11
viewer CVE-2026-25680 HIGH golang.org/x/net 3.6.2
viewer CVE-2026-25681 HIGH golang.org/x/net 3.6.2
viewer CVE-2026-27136 HIGH golang.org/x/net 3.6.2
viewer CVE-2026-39821 HIGH golang.org/x/net 3.6.2
viewer CVE-2026-39827 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-39828 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-39829 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-39830 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-39835 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-42502 HIGH golang.org/x/net 3.6.2
viewer CVE-2026-42506 HIGH golang.org/x/net 3.6.2
viewer CVE-2026-42508 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-46595 HIGH golang.org/x/crypto 3.6.2
viewer CVE-2026-46597 HIGH golang.org/x/crypto 3.6.2

Security patch 3.6.3.2

1 CVE(s) fixed in the 3.6.3.2 security patch.

Service CVE Severity Package Previously affected
ai-service CVE-2026-69249 HIGH cryptography 3.6.2

Pre-existing — assessed

The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.

Service CVE Severity Package Status Justification
ai-service CVE-2025-69720 HIGH ncurses OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
analysis-node CVE-2025-26646 HIGH Microsoft.Build.Tasks.Core Not Affected –no-restore skips the NuGet restore pipeline where this CVE lives.
analysis-node CVE-2025-55247 HIGH Microsoft.Build.Tasks.Core Not Affected MSBuild input comes exclusively from CAST’s own tooling — no external input.
analysis-node CVE-2025-67030 HIGH plexus-utils Not Affected The vulnerable code path is never invoked at runtime.
analysis-node CVE-2025-69720 HIGH ncurses OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
analysis-node CVE-2026-23949 HIGH jaraco.context Not Affected jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service.
analysis-node CVE-2026-24049 HIGH wheel Not Affected wheel is a build-time tool only — not used at runtime.
analysis-node CVE-2026-26171 HIGH System.Security.Cryptography.Xml Not Affected Not loaded during any runtime code path.
analysis-node CVE-2026-44432 HIGH urllib3 Not Affected Not used in any production code path.
dashboards-v3 CVE-2026-2100 HIGH p11-kit OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
dashboards-v3 CVE-2026-45186 HIGH libexpat OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2023-2953 HIGH libldap-2.5-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2023-31484 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2023-45853 CRITICAL zlib1g OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-15467 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-6020 HIGH libpam-modules OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-68973 HIGH gpgv OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-69421 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-6965 CRITICAL libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-69720 HIGH libncursesw6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
imaging-mcp-server CVE-2025-7458 CRITICAL libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-11822 HIGH libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-11824 HIGH libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-22184 HIGH zlib OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-26269 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28387 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28388 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28389 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28390 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28417 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28421 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-31789 CRITICAL libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-33412 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-33845 CRITICAL libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-33846 HIGH libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-34982 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-35177 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-3833 HIGH libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-39881 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-40200 HIGH musl OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42009 HIGH libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42010 CRITICAL libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42496 CRITICAL perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42497 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-46483 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-47162 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-4878 HIGH libcap2 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-48962 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-52858 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-52860 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-5773 HIGH curl OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-6276 HIGH curl OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-7598 HIGH libssh2-1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-8376 CRITICAL perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-9538 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
init-util CVE-2025-69720 HIGH libncursesw6 OS Vendor OS package upgrade required from Debian/DHI base image.
neo4j CVE-2025-69720 HIGH ncurses OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
neo4j CVE-2026-10050 HIGH jetty-ee8-security Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-59901 HIGH netty-codec-compression Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
sso-service CVE-2025-59250 HIGH mssql-jdbc False Positive Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier.
sso-service CVE-2025-69720 HIGH ncurses OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.