3.6.6 — Security fixes



Fixes provided in 3.6.6

70 CVE(s) fixed compared to the previous release.

Service CVE Severity Package Previously affected
admin-center CVE-2026-42588 HIGH activemq-broker 3.6.3
admin-center CVE-2026-45505 HIGH activemq-broker 3.6.3
admin-center CVE-2026-54291 HIGH postgresql 3.6.2
admin-center CVE-2026-55831 HIGH netty-codec-http 3.6.2
admin-center CVE-2026-55833 HIGH netty-codec-http 3.6.2
admin-center CVE-2026-56745 HIGH netty-codec-http 3.6.2
admin-center CVE-2026-59901 HIGH netty-codec 3.6.2
ai-service CVE-2025-15281 HIGH libc-bin 3.6.5
ai-service CVE-2026-0861 HIGH libc-bin 3.6.5
ai-service CVE-2026-0915 HIGH libc-bin 3.6.5
ai-service CVE-2026-40467 HIGH gawk 3.6.2
ai-service CVE-2026-40468 CRITICAL gawk 3.6.2
ai-service CVE-2026-40469 CRITICAL gawk 3.6.2
ai-service CVE-2026-40553 HIGH gawk 3.6.2
ai-service CVE-2026-53615 HIGH libuuid1 3.6.5
analysis-node CVE-2020-27225 HIGH 3.6.5
analysis-node CVE-2026-40467 HIGH gawk 3.6.2
analysis-node CVE-2026-40468 CRITICAL gawk 3.6.2
analysis-node CVE-2026-40469 CRITICAL gawk 3.6.2
analysis-node CVE-2026-40553 HIGH gawk 3.6.2
analysis-node CVE-2026-47302 HIGH System.Security.Cryptography.Xml 3.6.2
analysis-node CVE-2026-47304 HIGH System.Security.Cryptography.Xml 3.6.2
analysis-node CVE-2026-50524 HIGH Microsoft.NETCore.App.Runtime.linux-x64 3.6.2
analysis-node CVE-2026-50525 HIGH System.Security.Cryptography.Xml 3.6.2
analysis-node CVE-2026-50527 HIGH System.Security.Cryptography.Xml 3.6.2
analysis-node CVE-2026-50528 HIGH Microsoft.NETCore.App.Runtime.linux-x64 3.6.2
analysis-node CVE-2026-50648 HIGH System.Security.Cryptography.Xml 3.6.2
analysis-node CVE-2026-50651 HIGH Microsoft.NETCore.App.Runtime.linux-x64 3.6.2
analysis-node CVE-2026-57108 HIGH Microsoft.NETCore.App.Runtime.linux-x64 3.6.2
auth-service CVE-2026-41842 HIGH spring-webflux 3.6.2
auth-service CVE-2026-41850 HIGH spring-expression 3.6.2
auth-service CVE-2026-55831 HIGH netty-codec-http 3.6.2
auth-service CVE-2026-55833 HIGH netty-codec-http 3.6.2
auth-service CVE-2026-56745 HIGH netty-codec-http 3.6.2
auth-service CVE-2026-59901 HIGH netty-codec 3.6.2
console CVE-2026-41842 HIGH spring-webmvc 3.6.2
console CVE-2026-41845 HIGH spring-webmvc 3.6.2
console CVE-2026-41850 HIGH spring-expression 3.6.2
console CVE-2026-54291 HIGH postgresql 3.6.2
etl-service CVE-2026-33630 HIGH c-ares 3.6.2
etl-service CVE-2026-5773 HIGH curl 3.6.2
etl-service CVE-2026-6276 HIGH curl 3.6.2
gateway CVE-2026-41842 HIGH spring-webflux 3.6.2
gateway CVE-2026-41845 HIGH spring-webmvc 3.6.2
gateway CVE-2026-41850 HIGH spring-expression 3.6.2
gateway CVE-2026-55831 HIGH netty-codec-http 3.6.2
gateway CVE-2026-55833 HIGH netty-codec-http 3.6.2
gateway CVE-2026-56745 HIGH netty-codec-http 3.6.2
gateway CVE-2026-59901 HIGH netty-codec 3.6.2
imaging-apis CVE-2026-33630 HIGH c-ares 3.6.2
imaging-apis CVE-2026-45186 HIGH libexpat 3.6.3
imaging-apis CVE-2026-56131 HIGH libexpat 3.6.3
imaging-apis CVE-2026-56407 HIGH libexpat 3.6.3
imaging-apis CVE-2026-56408 HIGH libexpat 3.6.3
imaging-apis CVE-2026-5773 HIGH curl 3.6.2
imaging-apis CVE-2026-6276 HIGH curl 3.6.2
neo4j CVE-2025-15281 HIGH libc-bin 3.6.5
neo4j CVE-2026-0861 HIGH libc-bin 3.6.5
neo4j CVE-2026-0915 HIGH libc-bin 3.6.5
neo4j CVE-2026-40467 HIGH gawk 3.6.2
neo4j CVE-2026-40468 CRITICAL gawk 3.6.2
neo4j CVE-2026-40469 CRITICAL gawk 3.6.2
neo4j CVE-2026-40553 HIGH gawk 3.6.2
sso-service CVE-2025-15281 HIGH 3.6.5
sso-service CVE-2026-0861 HIGH 3.6.5
sso-service CVE-2026-0915 HIGH 3.6.5
sso-service CVE-2026-40467 HIGH gawk 3.6.2
sso-service CVE-2026-40468 CRITICAL gawk 3.6.2
sso-service CVE-2026-40469 CRITICAL gawk 3.6.2
sso-service CVE-2026-40553 HIGH gawk 3.6.2

Pre-existing — assessed

The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.

Service CVE Severity Package Status Justification
ai-service CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2023-2953 HIGH libldap-2.5-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2023-31484 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2023-45853 CRITICAL zlib1g OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-15467 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-6020 HIGH libpam-modules OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-68973 HIGH gpgv OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-69421 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-6965 CRITICAL libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-69720 HIGH libncursesw6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-7458 CRITICAL libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-11822 HIGH libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-11824 HIGH libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-22184 HIGH zlib OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-26269 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-27135 HIGH libnghttp2-14 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28387 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28388 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28389 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28390 HIGH libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28417 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-28421 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-31789 CRITICAL libssl3 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-33412 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-33845 CRITICAL libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-33846 HIGH libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-34982 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-35177 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-3833 HIGH libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-39881 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-40200 HIGH musl OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42009 HIGH libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42010 CRITICAL libgnutls30 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42496 CRITICAL perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-42497 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-45447 HIGH libssl3 OS Vendor OpenSSL vulnerability in DHI (Docker Hardened Image) base image. Waiting for fix from Docker/Debian.
imaging-mcp-server CVE-2026-46483 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-47162 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-4878 HIGH libcap2 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-48962 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-52858 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-52860 HIGH vim OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-5773 HIGH curl OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-6276 HIGH curl OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-7598 HIGH libssh2-1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-8376 CRITICAL perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-9538 HIGH perl-base OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
init-util CVE-2025-69720 HIGH libtinfo6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.