3.6.3 — Security fixes
For the live, searchable view of all CVE advisories with remediation status, see the Security Advisories.
Fixes provided in 3.6.3
75 CVE(s) fixed compared to the previous release.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| admin-center | CVE-2026-41284 | HIGH | tomcat-embed-core | 3.6.2 |
| admin-center | CVE-2026-41293 | CRITICAL | tomcat-embed-core | 3.6.2 |
| admin-center | CVE-2026-42498 | HIGH | tomcat-embed-core | 3.6.2 |
| admin-center | CVE-2026-43512 | CRITICAL | tomcat-embed-core | 3.6.2 |
| admin-center | CVE-2026-43513 | HIGH | tomcat-embed-core | 3.6.2 |
| admin-center | CVE-2026-43515 | CRITICAL | tomcat-embed-core | 3.6.2 |
| console | CVE-2026-41284 | HIGH | tomcat-embed-core | 3.6.2 |
| console | CVE-2026-41293 | CRITICAL | tomcat-embed-core | 3.6.2 |
| console | CVE-2026-42498 | HIGH | tomcat-embed-core | 3.6.2 |
| console | CVE-2026-43512 | CRITICAL | tomcat-embed-core | 3.6.2 |
| console | CVE-2026-43513 | HIGH | tomcat-embed-core | 3.6.2 |
| console | CVE-2026-43515 | CRITICAL | tomcat-embed-core | 3.6.2 |
| dashboards-v3 | CVE-2025-14813 | CRITICAL | bcprov-jdk18on | 3.6.2 |
| dashboards-v3 | CVE-2026-25680 | HIGH | golang.org/x/net | 3.6.2 |
| dashboards-v3 | CVE-2026-25681 | HIGH | golang.org/x/net | 3.6.2 |
| dashboards-v3 | CVE-2026-27136 | HIGH | golang.org/x/net | 3.6.2 |
| dashboards-v3 | CVE-2026-33811 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-33814 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-39820 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-39821 | HIGH | golang.org/x/net | 3.6.2 |
| dashboards-v3 | CVE-2026-39823 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-39825 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-39836 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-40973 | HIGH | spring-boot | 3.6.2 |
| dashboards-v3 | CVE-2026-41284 | HIGH | tomcat-embed-core | 3.6.2 |
| dashboards-v3 | CVE-2026-41293 | CRITICAL | tomcat-embed-core | 3.6.2 |
| dashboards-v3 | CVE-2026-42198 | HIGH | postgresql | 3.6.2 |
| dashboards-v3 | CVE-2026-42498 | HIGH | tomcat-embed-core | 3.6.2 |
| dashboards-v3 | CVE-2026-42499 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-42502 | HIGH | golang.org/x/net | 3.6.2 |
| dashboards-v3 | CVE-2026-42504 | HIGH | stdlib | 3.6.2 |
| dashboards-v3 | CVE-2026-42506 | HIGH | golang.org/x/net | 3.6.2 |
| dashboards-v3 | CVE-2026-43512 | CRITICAL | tomcat-embed-core | 3.6.2 |
| dashboards-v3 | CVE-2026-43513 | HIGH | tomcat-embed-core | 3.6.2 |
| dashboards-v3 | CVE-2026-43515 | CRITICAL | tomcat-embed-core | 3.6.2 |
| etl-service | CVE-2026-33811 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-33814 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-39820 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-39823 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-39825 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-39836 | HIGH | stdlib | 3.6.2 |
| etl-service | CVE-2026-42499 | HIGH | stdlib | 3.6.2 |
| gateway | CVE-2026-41284 | HIGH | tomcat-embed-core | 3.6.2 |
| gateway | CVE-2026-41293 | CRITICAL | tomcat-embed-core | 3.6.2 |
| gateway | CVE-2026-42498 | HIGH | tomcat-embed-core | 3.6.2 |
| gateway | CVE-2026-43512 | CRITICAL | tomcat-embed-core | 3.6.2 |
| gateway | CVE-2026-43513 | HIGH | tomcat-embed-core | 3.6.2 |
| gateway | CVE-2026-43515 | CRITICAL | tomcat-embed-core | 3.6.2 |
| imaging-mcp-server | CVE-2026-48526 | HIGH | PyJWT | 3.0.1 |
| imaging-mcp-server | CVE-2026-48818 | HIGH | starlette | 3.0.1 |
| imaging-mcp-server | CVE-2026-49852 | HIGH | joserfc | 3.0.1 |
| imaging-mcp-server | CVE-2026-52869 | HIGH | mcp | 3.0.1 |
| imaging-mcp-server | CVE-2026-52870 | HIGH | mcp | 3.0.1 |
| imaging-mcp-server | CVE-2026-53539 | HIGH | python-multipart | 3.0.1 |
| imaging-mcp-server | GHSA-4w2j-m93h-cj5j | HIGH | quinn-proto | 3.0.1 |
| neo4j | CVE-2026-33811 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-33814 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-39820 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-39823 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-39825 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-39826 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-39836 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-42499 | HIGH | stdlib | 3.6.2 |
| neo4j | CVE-2026-55851 | HIGH | netty-codec-haproxy | 3.6.2 |
| sso-service | CVE-2026-29111 | HIGH | libsystemd0 | 3.6.2 |
| sso-service | CVE-2026-42578 | HIGH | netty-handler-proxy | 3.6.2 |
| sso-service | CVE-2026-42579 | CRITICAL | netty-codec-dns | 3.6.2 |
| sso-service | CVE-2026-4878 | HIGH | libcap2 | 3.6.2 |
| viewer | CVE-2026-33811 | HIGH | stdlib | 3.6.2 |
| viewer | CVE-2026-33814 | HIGH | stdlib | 3.6.2 |
| viewer | CVE-2026-39820 | HIGH | stdlib | 3.6.2 |
| viewer | CVE-2026-39823 | HIGH | stdlib | 3.6.2 |
| viewer | CVE-2026-39825 | HIGH | stdlib | 3.6.2 |
| viewer | CVE-2026-39836 | HIGH | stdlib | 3.6.2 |
| viewer | CVE-2026-42499 | HIGH | stdlib | 3.6.2 |
Security patch 3.6.3.1
93 CVE(s) fixed in the 3.6.3.1 security patch.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| ai-service | CVE-2026-25087 | HIGH | pyarrow | 3.6.3 |
| ai-service | CVE-2026-4372 | HIGH | transformers | 3.6.2 |
| ai-service | CVE-2026-44843 | HIGH | langchain-core | 3.6.3 |
| ai-service | CVE-2026-45134 | HIGH | langchain-classic | 3.6.3 |
| ai-service | CVE-2026-5241 | HIGH | transformers | 3.6.2 |
| ai-service | GHSA-xf7x-x43h-rpqh | HIGH | json_repair | 3.6.3 |
| etl-service | CVE-2026-39827 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-39828 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-39829 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-39830 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-39835 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-42508 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-46595 | HIGH | golang.org/x/crypto | 3.6.2 |
| etl-service | CVE-2026-46597 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2025-22868 | HIGH | golang.org/x/oauth2 | 3.6.3 |
| imaging-apis | CVE-2026-25680 | HIGH | golang.org/x/net | 3.6.2 |
| imaging-apis | CVE-2026-25681 | HIGH | golang.org/x/net | 3.6.2 |
| imaging-apis | CVE-2026-27136 | HIGH | golang.org/x/net | 3.6.2 |
| imaging-apis | CVE-2026-39821 | HIGH | golang.org/x/net | 3.6.2 |
| imaging-apis | CVE-2026-39827 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-39828 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-39829 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-39830 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-39835 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-42502 | HIGH | golang.org/x/net | 3.6.2 |
| imaging-apis | CVE-2026-42506 | HIGH | golang.org/x/net | 3.6.2 |
| imaging-apis | CVE-2026-42508 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-46595 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-apis | CVE-2026-46597 | HIGH | golang.org/x/crypto | 3.6.2 |
| imaging-mcp-server | CVE-2025-15281 | HIGH | 3.0.2 | |
| imaging-mcp-server | CVE-2025-62727 | HIGH | starlette | 3.0.2 |
| imaging-mcp-server | CVE-2025-64439 | HIGH | langgraph-checkpoint | 3.0.2 |
| imaging-mcp-server | CVE-2025-65106 | HIGH | langchain-core | 3.0.2 |
| imaging-mcp-server | CVE-2025-66416 | HIGH | mcp | 3.0.2 |
| imaging-mcp-server | CVE-2025-67221 | HIGH | orjson | 3.0.2 |
| imaging-mcp-server | CVE-2025-68664 | CRITICAL | langchain-core | 3.0.2 |
| imaging-mcp-server | CVE-2025-69196 | HIGH | fastmcp | 3.0.2 |
| imaging-mcp-server | CVE-2026-0861 | HIGH | 3.0.2 | |
| imaging-mcp-server | CVE-2026-0915 | HIGH | 3.0.2 | |
| imaging-mcp-server | CVE-2026-23949 | HIGH | jaraco.context | 3.0.2 |
| imaging-mcp-server | CVE-2026-24049 | HIGH | wheel | 3.0.2 |
| imaging-mcp-server | CVE-2026-26007 | HIGH | cryptography | 3.0.2 |
| imaging-mcp-server | CVE-2026-27124 | HIGH | fastmcp | 3.0.2 |
| imaging-mcp-server | CVE-2026-27135 | HIGH | nghttp2-libs | 3.0.1 |
| imaging-mcp-server | CVE-2026-32871 | CRITICAL | fastmcp | 3.0.2 |
| imaging-mcp-server | CVE-2026-34070 | HIGH | langchain-core | 3.0.2 |
| imaging-mcp-server | CVE-2026-34444 | HIGH | lupa | 3.0.2 |
| imaging-mcp-server | CVE-2026-44431 | HIGH | urllib3 | 3.0.2 |
| imaging-mcp-server | CVE-2026-44432 | HIGH | urllib3 | 3.0.1 |
| imaging-mcp-server | CVE-2026-44843 | HIGH | langchain-core | 3.0.1 |
| imaging-mcp-server | CVE-2026-45134 | HIGH | langsmith | 3.0.1 |
| imaging-mcp-server | CVE-2026-45447 | HIGH | libssl3t64 | 3.0.2 |
| imaging-mcp-server | CVE-2026-48818 | HIGH | starlette | 3.0.2 |
| imaging-mcp-server | CVE-2026-54283 | HIGH | starlette | 3.0.1 |
| imaging-mcp-server | CVE-2026-69249 | HIGH | cryptography | 3.0.1 |
| imaging-mcp-server | CVE-2026-9669 | HIGH | 3.0.2 | |
| imaging-mcp-server | GHSA-537c-gmf6-5ccf | HIGH | cryptography | 3.0.1 |
| imaging-mcp-server | GHSA-82j2-j2ch-gfr8 | HIGH | rustls-webpki | 3.0.1 |
| imaging-mcp-server | GHSA-c2jp-c369-7pvx | HIGH | fastmcp | 3.0.2 |
| imaging-mcp-server | GHSA-f4xh-w4cj-qxq8 | HIGH | langsmith | 3.0.1 |
| imaging-mcp-server | GHSA-rcfx-77hg-w2wv | HIGH | fastmcp | 3.0.2 |
| init-util | CVE-2025-59375 | HIGH | libexpat1 | 1.2.11 |
| init-util | CVE-2026-11822 | HIGH | libsqlite3-0 | 1.2.10 |
| init-util | CVE-2026-11824 | HIGH | libsqlite3-0 | 1.2.10 |
| init-util | CVE-2026-24882 | HIGH | gpgv | 1.2.11 |
| init-util | CVE-2026-25210 | HIGH | libexpat1 | 1.2.11 |
| init-util | CVE-2026-42496 | CRITICAL | libperl5.40 | 1.2.11 |
| init-util | CVE-2026-42497 | HIGH | libperl5.40 | 1.2.11 |
| init-util | CVE-2026-45186 | HIGH | libexpat1 | 1.2.11 |
| init-util | CVE-2026-45447 | HIGH | libssl3t64 | 1.2.11 |
| init-util | CVE-2026-48959 | HIGH | libperl5.40 | 1.2.11 |
| init-util | CVE-2026-48962 | HIGH | libperl5.40 | 1.2.11 |
| init-util | CVE-2026-5773 | HIGH | curl | 1.2.11 |
| init-util | CVE-2026-6276 | HIGH | curl | 1.2.11 |
| init-util | CVE-2026-7210 | CRITICAL | libpython3.13-minimal | 1.2.11 |
| init-util | CVE-2026-7598 | HIGH | libssh2-1t64 | 1.2.11 |
| init-util | CVE-2026-8376 | CRITICAL | libperl5.40 | 1.2.11 |
| init-util | CVE-2026-9538 | HIGH | libperl5.40 | 1.2.11 |
| init-util | CVE-2026-9669 | HIGH | libpython3.13-minimal | 1.2.11 |
| viewer | CVE-2026-25680 | HIGH | golang.org/x/net | 3.6.2 |
| viewer | CVE-2026-25681 | HIGH | golang.org/x/net | 3.6.2 |
| viewer | CVE-2026-27136 | HIGH | golang.org/x/net | 3.6.2 |
| viewer | CVE-2026-39821 | HIGH | golang.org/x/net | 3.6.2 |
| viewer | CVE-2026-39827 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-39828 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-39829 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-39830 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-39835 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-42502 | HIGH | golang.org/x/net | 3.6.2 |
| viewer | CVE-2026-42506 | HIGH | golang.org/x/net | 3.6.2 |
| viewer | CVE-2026-42508 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-46595 | HIGH | golang.org/x/crypto | 3.6.2 |
| viewer | CVE-2026-46597 | HIGH | golang.org/x/crypto | 3.6.2 |
Security patch 3.6.3.2
1 CVE(s) fixed in the 3.6.3.2 security patch.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| ai-service | CVE-2026-69249 | HIGH | cryptography | 3.6.2 |
Pre-existing — assessed
The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.
| Service | CVE | Severity | Package | Status | Justification |
|---|---|---|---|---|---|
| ai-service | CVE-2025-69720 | HIGH | ncurses | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| analysis-node | CVE-2025-26646 | HIGH | Microsoft.Build.Tasks.Core | Not Affected | –no-restore skips the NuGet restore pipeline where this CVE lives. |
| analysis-node | CVE-2025-55247 | HIGH | Microsoft.Build.Tasks.Core | Not Affected | MSBuild input comes exclusively from CAST’s own tooling — no external input. |
| analysis-node | CVE-2025-67030 | HIGH | plexus-utils | Not Affected | The vulnerable code path is never invoked at runtime. |
| analysis-node | CVE-2025-69720 | HIGH | ncurses | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| analysis-node | CVE-2026-23949 | HIGH | jaraco.context | Not Affected | jaraco.context is a transitive dependency of pip/setuptools used only during the container build phase. It is not installed or reachable at runtime in the analysis-node service. |
| analysis-node | CVE-2026-24049 | HIGH | wheel | Not Affected | wheel is a build-time tool only — not used at runtime. |
| analysis-node | CVE-2026-26171 | HIGH | System.Security.Cryptography.Xml | Not Affected | Not loaded during any runtime code path. |
| analysis-node | CVE-2026-44432 | HIGH | urllib3 | Not Affected | Not used in any production code path. |
| dashboards-v3 | CVE-2026-2100 | HIGH | p11-kit | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| dashboards-v3 | CVE-2026-45186 | HIGH | libexpat | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2023-2953 | HIGH | libldap-2.5-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2023-31484 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2023-45853 | CRITICAL | zlib1g | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-15467 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-6020 | HIGH | libpam-modules | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-68973 | HIGH | gpgv | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-69421 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-6965 | CRITICAL | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-69720 | HIGH | libncursesw6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| imaging-mcp-server | CVE-2025-7458 | CRITICAL | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-11822 | HIGH | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-11824 | HIGH | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-22184 | HIGH | zlib | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-26269 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28387 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28388 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28389 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28390 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28417 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28421 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-31789 | CRITICAL | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-33412 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-33845 | CRITICAL | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-33846 | HIGH | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-34982 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-35177 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-3833 | HIGH | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-39881 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-40200 | HIGH | musl | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42009 | HIGH | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42010 | CRITICAL | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42496 | CRITICAL | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42497 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-46483 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-47162 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-4878 | HIGH | libcap2 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-48962 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-52858 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-52860 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-5773 | HIGH | curl | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-6276 | HIGH | curl | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-7598 | HIGH | libssh2-1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-8376 | CRITICAL | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-9538 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| init-util | CVE-2025-69720 | HIGH | libncursesw6 | OS Vendor | OS package upgrade required from Debian/DHI base image. |
| neo4j | CVE-2025-69720 | HIGH | ncurses | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |
| neo4j | CVE-2026-10050 | HIGH | jetty-ee8-security | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| neo4j | CVE-2026-59901 | HIGH | netty-codec-compression | Vendor Dependent | Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly. |
| sso-service | CVE-2025-59250 | HIGH | mssql-jdbc | False Positive | Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier. |
| sso-service | CVE-2025-69720 | HIGH | ncurses | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |