3.6.6 — Security fixes
For the live, searchable view of all CVE advisories with remediation status, see the Security Advisories.
Fixes provided in 3.6.6
70 CVE(s) fixed compared to the previous release.
| Service | CVE | Severity | Package | Previously affected |
|---|---|---|---|---|
| admin-center | CVE-2026-42588 | HIGH | activemq-broker | 3.6.3 |
| admin-center | CVE-2026-45505 | HIGH | activemq-broker | 3.6.3 |
| admin-center | CVE-2026-54291 | HIGH | postgresql | 3.6.2 |
| admin-center | CVE-2026-55831 | HIGH | netty-codec-http | 3.6.2 |
| admin-center | CVE-2026-55833 | HIGH | netty-codec-http | 3.6.2 |
| admin-center | CVE-2026-56745 | HIGH | netty-codec-http | 3.6.2 |
| admin-center | CVE-2026-59901 | HIGH | netty-codec | 3.6.2 |
| ai-service | CVE-2025-15281 | HIGH | libc-bin | 3.6.5 |
| ai-service | CVE-2026-0861 | HIGH | libc-bin | 3.6.5 |
| ai-service | CVE-2026-0915 | HIGH | libc-bin | 3.6.5 |
| ai-service | CVE-2026-40467 | HIGH | gawk | 3.6.2 |
| ai-service | CVE-2026-40468 | CRITICAL | gawk | 3.6.2 |
| ai-service | CVE-2026-40469 | CRITICAL | gawk | 3.6.2 |
| ai-service | CVE-2026-40553 | HIGH | gawk | 3.6.2 |
| ai-service | CVE-2026-53615 | HIGH | libuuid1 | 3.6.5 |
| analysis-node | CVE-2020-27225 | HIGH | 3.6.5 | |
| analysis-node | CVE-2026-40467 | HIGH | gawk | 3.6.2 |
| analysis-node | CVE-2026-40468 | CRITICAL | gawk | 3.6.2 |
| analysis-node | CVE-2026-40469 | CRITICAL | gawk | 3.6.2 |
| analysis-node | CVE-2026-40553 | HIGH | gawk | 3.6.2 |
| analysis-node | CVE-2026-47302 | HIGH | System.Security.Cryptography.Xml | 3.6.2 |
| analysis-node | CVE-2026-47304 | HIGH | System.Security.Cryptography.Xml | 3.6.2 |
| analysis-node | CVE-2026-50524 | HIGH | Microsoft.NETCore.App.Runtime.linux-x64 | 3.6.2 |
| analysis-node | CVE-2026-50525 | HIGH | System.Security.Cryptography.Xml | 3.6.2 |
| analysis-node | CVE-2026-50527 | HIGH | System.Security.Cryptography.Xml | 3.6.2 |
| analysis-node | CVE-2026-50528 | HIGH | Microsoft.NETCore.App.Runtime.linux-x64 | 3.6.2 |
| analysis-node | CVE-2026-50648 | HIGH | System.Security.Cryptography.Xml | 3.6.2 |
| analysis-node | CVE-2026-50651 | HIGH | Microsoft.NETCore.App.Runtime.linux-x64 | 3.6.2 |
| analysis-node | CVE-2026-57108 | HIGH | Microsoft.NETCore.App.Runtime.linux-x64 | 3.6.2 |
| auth-service | CVE-2026-41842 | HIGH | spring-webflux | 3.6.2 |
| auth-service | CVE-2026-41850 | HIGH | spring-expression | 3.6.2 |
| auth-service | CVE-2026-55831 | HIGH | netty-codec-http | 3.6.2 |
| auth-service | CVE-2026-55833 | HIGH | netty-codec-http | 3.6.2 |
| auth-service | CVE-2026-56745 | HIGH | netty-codec-http | 3.6.2 |
| auth-service | CVE-2026-59901 | HIGH | netty-codec | 3.6.2 |
| console | CVE-2026-41842 | HIGH | spring-webmvc | 3.6.2 |
| console | CVE-2026-41845 | HIGH | spring-webmvc | 3.6.2 |
| console | CVE-2026-41850 | HIGH | spring-expression | 3.6.2 |
| console | CVE-2026-54291 | HIGH | postgresql | 3.6.2 |
| etl-service | CVE-2026-33630 | HIGH | c-ares | 3.6.2 |
| etl-service | CVE-2026-5773 | HIGH | curl | 3.6.2 |
| etl-service | CVE-2026-6276 | HIGH | curl | 3.6.2 |
| gateway | CVE-2026-41842 | HIGH | spring-webflux | 3.6.2 |
| gateway | CVE-2026-41845 | HIGH | spring-webmvc | 3.6.2 |
| gateway | CVE-2026-41850 | HIGH | spring-expression | 3.6.2 |
| gateway | CVE-2026-55831 | HIGH | netty-codec-http | 3.6.2 |
| gateway | CVE-2026-55833 | HIGH | netty-codec-http | 3.6.2 |
| gateway | CVE-2026-56745 | HIGH | netty-codec-http | 3.6.2 |
| gateway | CVE-2026-59901 | HIGH | netty-codec | 3.6.2 |
| imaging-apis | CVE-2026-33630 | HIGH | c-ares | 3.6.2 |
| imaging-apis | CVE-2026-45186 | HIGH | libexpat | 3.6.3 |
| imaging-apis | CVE-2026-56131 | HIGH | libexpat | 3.6.3 |
| imaging-apis | CVE-2026-56407 | HIGH | libexpat | 3.6.3 |
| imaging-apis | CVE-2026-56408 | HIGH | libexpat | 3.6.3 |
| imaging-apis | CVE-2026-5773 | HIGH | curl | 3.6.2 |
| imaging-apis | CVE-2026-6276 | HIGH | curl | 3.6.2 |
| neo4j | CVE-2025-15281 | HIGH | libc-bin | 3.6.5 |
| neo4j | CVE-2026-0861 | HIGH | libc-bin | 3.6.5 |
| neo4j | CVE-2026-0915 | HIGH | libc-bin | 3.6.5 |
| neo4j | CVE-2026-40467 | HIGH | gawk | 3.6.2 |
| neo4j | CVE-2026-40468 | CRITICAL | gawk | 3.6.2 |
| neo4j | CVE-2026-40469 | CRITICAL | gawk | 3.6.2 |
| neo4j | CVE-2026-40553 | HIGH | gawk | 3.6.2 |
| sso-service | CVE-2025-15281 | HIGH | 3.6.5 | |
| sso-service | CVE-2026-0861 | HIGH | 3.6.5 | |
| sso-service | CVE-2026-0915 | HIGH | 3.6.5 | |
| sso-service | CVE-2026-40467 | HIGH | gawk | 3.6.2 |
| sso-service | CVE-2026-40468 | CRITICAL | gawk | 3.6.2 |
| sso-service | CVE-2026-40469 | CRITICAL | gawk | 3.6.2 |
| sso-service | CVE-2026-40553 | HIGH | gawk | 3.6.2 |
Pre-existing — assessed
The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.
| Service | CVE | Severity | Package | Status | Justification |
|---|---|---|---|---|---|
| ai-service | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2023-2953 | HIGH | libldap-2.5-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2023-31484 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2023-45853 | CRITICAL | zlib1g | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-15467 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-6020 | HIGH | libpam-modules | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-68973 | HIGH | gpgv | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-69421 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-6965 | CRITICAL | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-69720 | HIGH | libncursesw6 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2025-7458 | CRITICAL | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-11822 | HIGH | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-11824 | HIGH | libsqlite3-0 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-22184 | HIGH | zlib | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-26269 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-27135 | HIGH | libnghttp2-14 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28387 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28388 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28389 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28390 | HIGH | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28417 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-28421 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-31789 | CRITICAL | libssl3 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-33412 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-33845 | CRITICAL | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-33846 | HIGH | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-34982 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-35177 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-3833 | HIGH | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-39881 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-40200 | HIGH | musl | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42009 | HIGH | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42010 | CRITICAL | libgnutls30 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42496 | CRITICAL | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-42497 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-45447 | HIGH | libssl3 | OS Vendor | OpenSSL vulnerability in DHI (Docker Hardened Image) base image. Waiting for fix from Docker/Debian. |
| imaging-mcp-server | CVE-2026-46483 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-47162 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-4878 | HIGH | libcap2 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-48962 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-52858 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-52860 | HIGH | vim | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-5773 | HIGH | curl | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-6276 | HIGH | curl | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-7598 | HIGH | libssh2-1 | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-8376 | CRITICAL | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| imaging-mcp-server | CVE-2026-9538 | HIGH | perl-base | OS Vendor | OS package from DHI base image. Fix depends on OS vendor (Debian security team). |
| init-util | CVE-2025-69720 | HIGH | libtinfo6 | OS Vendor | Debian NODSA. Debian Security Team does not require an immediate fix. |