3.6.8 — Security fixes



Fixes provided in 3.6.8

200 CVE(s) fixed compared to the previous release.

Service CVE Severity Package Previously affected
admin-center CVE-2026-13506 HIGH bcprov-jdk18on 3.6.6
admin-center CVE-2026-41855 HIGH spring-jms 3.6.5
admin-center CVE-2026-47884 CRITICAL spring-webmvc 3.6.6
admin-center CVE-2026-47890 CRITICAL spring-webflux 3.6.2
admin-center CVE-2026-47892 CRITICAL spring-webflux 3.6.2
admin-center CVE-2026-54399 HIGH httpcore5 3.6.2
admin-center CVE-2026-54428 HIGH httpcore5-h2 3.6.2
admin-center CVE-2026-54512 HIGH 3.6.7
admin-center CVE-2026-54513 HIGH 3.6.7
admin-center CVE-2026-65182 CRITICAL tomcat-embed-core 3.6.2
admin-center CVE-2026-65905 CRITICAL tomcat-embed-core 3.6.2
admin-center CVE-2026-68494 HIGH jackson-core 3.6.4
admin-center CVE-2026-68497 HIGH jackson-databind 3.6.2
admin-center CVE-2026-68525 CRITICAL tomcat-embed-core 3.6.2
admin-center CVE-2026-75595 CRITICAL netty-handler 3.6.6
admin-center CVE-2026-84939 CRITICAL freemarker 3.6.6
admin-center CVE-2026-8763 CRITICAL bcprov-jdk18on 3.6.6
admin-center CVE-2026-89407 HIGH jackson-core 3.6.2
admin-center CVE-2026-89425 HIGH jackson-core 3.6.2
admin-center CVE-2026-91776 HIGH jackson-databind 3.6.7
admin-center CVE-2026-91777 HIGH jackson-databind 3.6.7
ai-service CVE-2025-15281 HIGH 3.6.7
ai-service CVE-2025-47273 HIGH 3.6.7
ai-service CVE-2026-0861 HIGH 3.6.7
ai-service CVE-2026-0915 HIGH 3.6.7
ai-service CVE-2026-102266 HIGH PyJWT 3.6.7
ai-service CVE-2026-102267 HIGH PyJWT 3.6.7
ai-service CVE-2026-102268 CRITICAL PyJWT 3.6.7
ai-service CVE-2026-102271 HIGH PyJWT 3.6.7
ai-service CVE-2026-102272 HIGH PyJWT 3.6.7
ai-service CVE-2026-102273 HIGH PyJWT 3.6.7
ai-service CVE-2026-102993 HIGH pypdf 3.6.6
ai-service CVE-2026-102994 HIGH pypdf 3.6.6
ai-service CVE-2026-102995 HIGH pypdf 3.6.6
ai-service CVE-2026-102996 HIGH pypdf 3.6.6
ai-service CVE-2026-102997 HIGH pypdf 3.6.6
ai-service CVE-2026-102998 HIGH pypdf 3.6.6
ai-service CVE-2026-102999 HIGH pypdf 3.6.6
ai-service CVE-2026-103000 HIGH pypdf 3.6.6
ai-service CVE-2026-11822 HIGH libsqlite3-0 3.6.3
ai-service CVE-2026-11824 HIGH libsqlite3-0 3.6.3
ai-service CVE-2026-14456 HIGH libssl3t64 3.6.2
ai-service CVE-2026-57585 HIGH 3.6.7
ai-service CVE-2026-59950 HIGH mcp 3.6.7
ai-service CVE-2026-80047 HIGH transformers 3.6.5
ai-service CVE-2026-97687 HIGH urllib3 3.6.3
ai-service CVE-2026-97689 HIGH urllib3 3.6.3
ai-service CVE-2026-9856 HIGH transformers 3.6.4
ai-service GHSA-6v7p-g79w-8964 HIGH 3.6.7
analysis-node CVE-2020-27225 HIGH 3.6.7
analysis-node CVE-2025-55247 HIGH 3.6.7
analysis-node CVE-2026-103111 HIGH libpcre2-8-0 3.6.3
analysis-node CVE-2026-14456 HIGH libssl3t64 3.6.2
analysis-node CVE-2026-23949 HIGH jaraco.context 3.6.3
analysis-node CVE-2026-24049 HIGH wheel 3.6.3
analysis-node CVE-2026-26171 HIGH 3.6.7
analysis-node CVE-2026-33116 HIGH 3.6.7
analysis-node CVE-2026-41992 HIGH gzip 3.6.5
analysis-node CVE-2026-44432 HIGH 3.6.7
analysis-node CVE-2026-68497 HIGH jackson-databind 3.6.3
analysis-node CVE-2026-77422 HIGH jline-builtins 3.6.7
analysis-node CVE-2026-89407 HIGH jackson-core 3.6.3
analysis-node CVE-2026-89425 HIGH jackson-core 3.6.3
analysis-node CVE-2026-91776 HIGH jackson-databind 3.6.3
analysis-node CVE-2026-91777 HIGH jackson-databind 3.6.3
auth-service CVE-2026-13506 HIGH bcprov-jdk18on 3.6.2
auth-service CVE-2026-14456 HIGH libcrypto3 3.6.7
auth-service CVE-2026-47890 CRITICAL spring-webflux 3.6.2
auth-service CVE-2026-47892 CRITICAL spring-webflux 3.6.2
auth-service CVE-2026-68497 HIGH jackson-databind 3.6.2
auth-service CVE-2026-75595 CRITICAL netty-handler 3.6.2
auth-service CVE-2026-8763 CRITICAL bcprov-jdk18on 3.6.2
auth-service CVE-2026-89407 HIGH jackson-core 3.6.2
auth-service CVE-2026-89425 HIGH jackson-core 3.6.2
auth-service CVE-2026-91776 HIGH jackson-databind 3.6.3
auth-service CVE-2026-91777 HIGH jackson-databind 3.6.3
console CVE-2017-0247 HIGH 3.6.7
console CVE-2017-0249 HIGH 3.6.7
console CVE-2017-11770 HIGH 3.6.7
console CVE-2024-0056 HIGH 3.6.7
console CVE-2025-60876 HIGH 3.6.7
console CVE-2026-13506 HIGH bcprov-jdk18on 3.6.2
console CVE-2026-41855 HIGH spring-jms 3.6.4
console CVE-2026-47884 CRITICAL spring-webmvc 3.6.2
console CVE-2026-47890 CRITICAL spring-webmvc 3.6.2
console CVE-2026-54399 HIGH httpcore5 3.6.2
console CVE-2026-54428 HIGH httpcore5-h2 3.6.2
console CVE-2026-65182 CRITICAL tomcat-embed-core 3.6.2
console CVE-2026-65905 CRITICAL tomcat-embed-core 3.6.2
console CVE-2026-68497 HIGH jackson-databind 3.6.2
console CVE-2026-68525 CRITICAL tomcat-embed-core 3.6.2
console CVE-2026-84939 CRITICAL freemarker 3.6.2
console CVE-2026-8763 CRITICAL bcprov-jdk18on 3.6.2
console CVE-2026-89407 HIGH jackson-core 3.6.2
console CVE-2026-89425 HIGH jackson-core 3.6.2
console CVE-2026-91776 HIGH jackson-databind 3.6.3
console CVE-2026-91777 HIGH jackson-databind 3.6.3
dashboards-v3 CVE-2025-15281 HIGH libc-bin 3.6.5
dashboards-v3 CVE-2025-69720 HIGH ncurses 3.6.5
dashboards-v3 CVE-2025-9086 HIGH 3.6.5
dashboards-v3 CVE-2026-0861 HIGH libc-bin 3.6.5
dashboards-v3 CVE-2026-0915 HIGH libc-bin 3.6.5
dashboards-v3 CVE-2026-13506 HIGH bcprov-jdk18on 3.6.2
dashboards-v3 CVE-2026-14456 HIGH libcrypto3 3.6.6
dashboards-v3 CVE-2026-2100 HIGH p11-kit 3.6.3
dashboards-v3 CVE-2026-45186 HIGH libexpat 3.6.3
dashboards-v3 CVE-2026-45447 HIGH libssl3t64 3.6.2
dashboards-v3 CVE-2026-47884 CRITICAL spring-webmvc 3.6.2
dashboards-v3 CVE-2026-47890 CRITICAL spring-webmvc 3.6.2
dashboards-v3 CVE-2026-56408 HIGH libexpat 3.6.6
dashboards-v3 CVE-2026-65182 CRITICAL tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-65905 CRITICAL tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-66046 HIGH libexpat 3.6.7
dashboards-v3 CVE-2026-68497 HIGH jackson-databind 3.6.2
dashboards-v3 CVE-2026-68525 CRITICAL tomcat-embed-core 3.6.2
dashboards-v3 CVE-2026-75140 HIGH jsoup 3.6.2
dashboards-v3 CVE-2026-76641 HIGH libexpat 3.6.7
dashboards-v3 CVE-2026-84782 HIGH libssl3t64 3.6.2
dashboards-v3 CVE-2026-8763 CRITICAL bcprov-jdk18on 3.6.2
dashboards-v3 CVE-2026-89407 HIGH jackson-core 3.6.2
dashboards-v3 CVE-2026-89425 HIGH jackson-core 3.6.2
dashboards-v3 CVE-2026-91776 HIGH jackson-databind 3.6.7
dashboards-v3 CVE-2026-91777 HIGH jackson-databind 3.6.7
etl-service CVE-2026-11352 HIGH curl 3.6.2
etl-service CVE-2026-11586 HIGH curl 3.6.2
etl-service CVE-2026-12064 HIGH curl 3.6.2
etl-service CVE-2026-14456 HIGH libcrypto3 3.6.2
etl-service CVE-2026-32316 HIGH jq 3.6.2
etl-service CVE-2026-40164 HIGH jq 3.6.2
etl-service CVE-2026-56854 CRITICAL golang.org/x/crypto 3.6.2
etl-service CVE-2026-8286 HIGH curl 3.6.2
etl-service CVE-2026-8458 HIGH curl 3.6.2
etl-service CVE-2026-8925 HIGH curl 3.6.2
etl-service CVE-2026-8927 HIGH curl 3.6.2
etl-service CVE-2026-9547 HIGH curl 3.6.2
gateway CVE-2026-13506 HIGH bcprov-jdk18on 3.6.2
gateway CVE-2026-14456 HIGH libcrypto3 3.6.7
gateway CVE-2026-47884 CRITICAL spring-webmvc 3.6.2
gateway CVE-2026-47890 CRITICAL spring-webflux 3.6.2
gateway CVE-2026-47892 CRITICAL spring-webflux 3.6.2
gateway CVE-2026-54399 HIGH httpcore5 3.6.2
gateway CVE-2026-54428 HIGH httpcore5-h2 3.6.2
gateway CVE-2026-68497 HIGH jackson-databind 3.6.2
gateway CVE-2026-75595 CRITICAL netty-handler 3.6.2
gateway CVE-2026-8763 CRITICAL bcprov-jdk18on 3.6.2
gateway CVE-2026-89407 HIGH jackson-core 3.6.2
gateway CVE-2026-89425 HIGH jackson-core 3.6.2
gateway CVE-2026-91776 HIGH jackson-databind 3.6.3
gateway CVE-2026-91777 HIGH jackson-databind 3.6.3
imaging-apis CVE-2026-11352 HIGH curl 3.6.2
imaging-apis CVE-2026-11586 HIGH curl 3.6.2
imaging-apis CVE-2026-12064 HIGH curl 3.6.2
imaging-apis CVE-2026-14456 HIGH libcrypto3 3.6.2
imaging-apis CVE-2026-32316 HIGH jq 3.6.2
imaging-apis CVE-2026-40164 HIGH jq 3.6.2
imaging-apis CVE-2026-66046 HIGH libexpat 3.6.2
imaging-apis CVE-2026-76641 HIGH libexpat 3.6.2
imaging-apis CVE-2026-8286 HIGH curl 3.6.2
imaging-apis CVE-2026-8458 HIGH curl 3.6.2
imaging-apis CVE-2026-8925 HIGH curl 3.6.2
imaging-apis CVE-2026-8927 HIGH curl 3.6.2
imaging-apis CVE-2026-93990 HIGH libexpat 3.6.2
imaging-apis CVE-2026-9547 HIGH curl 3.6.2
neo4j CVE-2025-15281 HIGH 3.6.7
neo4j CVE-2026-0861 HIGH 3.6.7
neo4j CVE-2026-0915 HIGH 3.6.7
neo4j CVE-2026-10050 HIGH jetty-ee8-security 3.6.2
neo4j CVE-2026-103111 HIGH libpcre2-8-0 3.6.2
neo4j CVE-2026-14456 HIGH libssl3t64 3.6.2
neo4j CVE-2026-41992 HIGH gzip 3.6.5
neo4j CVE-2026-54399 HIGH httpcore5 3.6.5
neo4j CVE-2026-54428 HIGH httpcore5-h2 3.6.5
neo4j CVE-2026-54512 HIGH jackson-databind 3.6.2
neo4j CVE-2026-54513 HIGH jackson-databind 3.6.2
neo4j CVE-2026-55831 HIGH netty-codec-http 3.6.2
neo4j CVE-2026-55833 HIGH netty-codec-http 3.6.2
neo4j CVE-2026-55851 HIGH netty-codec-haproxy 3.6.5
neo4j CVE-2026-56745 HIGH netty-codec-http 3.6.2
neo4j CVE-2026-56816 HIGH netty-codec-http3 3.6.2
neo4j CVE-2026-56819 HIGH netty-codec-http2 3.6.2
neo4j CVE-2026-56854 CRITICAL golang.org/x/crypto 3.6.6
neo4j CVE-2026-59901 HIGH netty-codec-compression 3.6.2
neo4j CVE-2026-68494 HIGH jackson-core 3.6.2
neo4j CVE-2026-68497 HIGH jackson-databind 3.6.2
neo4j CVE-2026-75595 CRITICAL netty-handler 3.6.2
neo4j GHSA-r7wm-3cxj-wff9 HIGH jackson-core 3.6.2
sso-service CVE-2025-15281 HIGH 3.6.7
sso-service CVE-2026-0861 HIGH 3.6.7
sso-service CVE-2026-0915 HIGH 3.6.7
sso-service CVE-2026-103111 HIGH libpcre2-8-0 3.6.2
sso-service CVE-2026-13506 HIGH bcprov-jdk18on 3.6.2
sso-service CVE-2026-14456 HIGH libssl3t64 3.6.2
sso-service CVE-2026-68497 HIGH jackson-databind 3.6.2
sso-service CVE-2026-8763 CRITICAL bcprov-jdk18on 3.6.2
viewer CVE-2026-103111 HIGH pcre2 3.6.2
viewer CVE-2026-14456 HIGH libcrypto3 3.6.2
viewer CVE-2026-56854 CRITICAL golang.org/x/crypto 3.6.2
viewer CVE-2026-86145 HIGH pcre2 3.6.2
viewer CVE-2026-89157 HIGH pcre2 3.6.2
viewer CVE-2026-89161 HIGH pcre2 3.6.2

Pre-existing — assessed

The following CVEs were present in this release and assessed as not requiring an immediate fix. See Security Advisories for up-to-date status.

Service CVE Severity Package Status Justification
ai-service CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2026-16742 HIGH libsystemd0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2026-54284 HIGH sqlparse Not Affected sqlparse is used by cast_application_api (sql_tool / _execute_raw_query) only to split and format SQL text that comes from the extension’s own bundled SQL scripts. No analyzer extension builds these query strings dynamically from external or source-code-derived input, so no adversary can supply the crafted SQL needed to trigger this parser CPU-exhaustion bug. Tracked for upgrade to sqlparse 0.6.0 once impact of the bump on analyzer extensions is validated (EXTSDK-9).
analysis-node CVE-2026-54369 HIGH libacl1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
analysis-node CVE-2026-59893 HIGH sqlparse Not Affected sqlparse is used by cast_application_api (sql_tool / _execute_raw_query) only to split and format SQL text that comes from the extension’s own bundled SQL scripts. No analyzer extension builds these query strings dynamically from external or source-code-derived input, so no adversary can supply the crafted dollar-quoted SQL needed to trigger this parser ReDoS bug. Tracked for upgrade to sqlparse 0.6.0 once impact of the bump on analyzer extensions is validated (EXTSDK-9).
analysis-node CVE-2026-71491 HIGH sqlparse Not Affected sqlparse is used by cast_application_api (sql_tool / _execute_raw_query) only to split and format SQL text that comes from the extension’s own bundled SQL scripts. No analyzer extension builds these query strings dynamically from external or source-code-derived input, so no adversary can supply the crafted comment-only SQL needed to trigger this parser CPU-exhaustion bug. Tracked for upgrade to sqlparse 0.6.0 once impact of the bump on analyzer extensions is validated (EXTSDK-9).
extend-proxy CVE-2024-10491 HIGH express Not Affected Version-range false positive. The authoritative advisory (GitHub Advisory Database GHSA-cm5g-3pgc-8rg4, and Snyk SNYK-JS-EXPRESS-8310337) scopes this vulnerability to express 3.0.0-alpha1 through 3.21.4 inclusive, with the fix released in express 4.0.0-rc1. The image ships express 5.2.1, which is two major versions beyond the patched release, so the vulnerable revision of the response.links implementation is not present in the product. Independently corroborated by this image’s own scan results: Trivy indexed every npm package in /opt/cast_extend_proxy/app and raised no finding against express, as did Grype.
extend-proxy sonatype-2016-0121 HIGH multer Not Affected RESOLVED BY RISK ACCEPTANCE - not suppressed; residual gaps are disclosed below. multer 2.2.0 is present and on the execute path of both upload endpoints, and the underlying behaviour the advisory describes (multer consuming the full stream before enforcing a fileSize limit) is unchanged in this version - no upgrade exists or would change it, 2.2.0 is the latest published release. CAST product ownership judges the vulnerability class adequately mitigated in this product by the combination of: (1) both the primary upload endpoint (package-controller.js, POST /upload) and the bundle upload endpoint (bundle-controller.js) require a valid proxy API key, so neither is anonymously reachable; (2) the primary endpoint sets limits.fileSize to 1 GB, comfortably above the largest legitimate extension package published to date (192 MB), bounding the heap-exhaustion vector on that path; (3) custom-extension upload is a low-usage feature exercised by a small minority of customers, materially reducing real-world exposure versus a default, high-traffic endpoint. Two gaps remain open and are disclosed rather than hidden: the bundle upload endpoint (bundle-controller.js) still sets no fileSize limit of its own - it is disk-backed rather than memory-backed, so its exposure is disk consumption, not heap exhaustion; and multer’s abortWithError does not unpipe or destroy the request stream on the LIMIT_FILE_SIZE path, so bytes up to the configured cap are still read and discarded rather than the connection being torn down early. If either gap is later judged material - for example if bundle upload usage increases - this statement should be revisited. Tracked in EXTPROXY-198.
extend-proxy sonatype-2019-0159 HIGH lunr Not Affected RESOLVED - same attribution conflict as sonatype-2021-1683, resolved the same way. CAST confirmed directly with Sonatype that this identifier also matches ‘mocha’, not ’lunr’. Sonatype’s own published advisory page already described this as a ReDoS in mocha (issue 3416 / PR 3686) with a matching CVSS score and vector. mocha is a devDependency removed from the runtime artifact by ’npm prune –production’; there is no node_modules/mocha in the shipped image. See the sonatype-2021-1683 statement for the full reasoning. Tracked in EXTPROXY-198.
extend-proxy sonatype-2021-0078 HIGH express Not Affected Per Sonatype’s own published advisory text (guide.sonatype.com/vulnerability/sonatype-2021-0078), this is a component-combination vulnerability that requires the ‘hbs’ Handlebars templating engine to be used alongside express. Neither ‘hbs’ nor ‘handlebars’ appears in the extend-proxy dependency manifest, in package-lock.json, or anywhere in the shipped image: a path scan of the exported filesystem for node_modules/hbs and node_modules/handlebars returns no match. The proxy renders no server-side templates. The required co-component is absent, so the vulnerable combination cannot exist in this product.
extend-proxy sonatype-2021-1683 HIGH lunr Not Affected RESOLVED - CAST queried Sonatype directly on the component-coordinate conflict described in the prior revision of this statement and confirmed the identifier matches ‘mocha’, not ’lunr’. Sonatype’s own published advisory page already described this as a ReDoS in mocha (issue 4766 / PR 4770) with a CVSS score and vector matching this finding exactly; the customer-supplied Nexus IQ report’s attribution to ’lunr : 2.3.9’ is a component mis-attribution in the IQ match result. mocha is declared solely in devDependencies and is removed from the runtime artifact by ’npm prune –production’: a path scan of the exported filesystem of castimaging/extend-proxy confirms there is no node_modules/mocha in the shipped image. The component the advisory defines is therefore not present in this product. Tracked in EXTPROXY-198.
imaging-mcp-server CVE-2013-7445 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2019-19449 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2019-19814 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2021-3847 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2021-3864 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2024-21803 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2024-58015 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-22104 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-38137 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-38187 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-38204 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-38206 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-38421 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-38636 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-39859 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-39862 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-39958 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2025-69720 HIGH libncursesw6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-11822 HIGH libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-11824 HIGH libsqlite3-0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-23102 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-23208 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-23327 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-31493 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-31536 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-31568 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-43185 CRITICAL linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-43198 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-43263 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-46130 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-46181 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-46279 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-52991 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-53000 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-53010 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-53089 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-53091 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-53109 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
imaging-mcp-server CVE-2026-53118 HIGH linux-libc-dev OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
init-util CVE-2025-69720 HIGH libtinfo6 OS Vendor Debian NODSA. Debian Security Team does not require an immediate fix.
neo4j CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
neo4j CVE-2026-106451 HIGH lz4-java Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-16742 HIGH libsystemd0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
neo4j CVE-2026-54369 HIGH libacl1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
neo4j CVE-2026-89407 HIGH jackson-core Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-89425 HIGH jackson-core Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-91776 HIGH jackson-databind Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
neo4j CVE-2026-91777 HIGH jackson-databind Vendor Dependent Neo4j is a third-party database component bundled as-is. Java CVEs in neo4j require an upstream Neo4j release to fix; CAST cannot patch these dependencies directly.
sso-service CVE-2025-59250 HIGH mssql-jdbc False Positive Installed library is 13.2.1; scanner expects 13.2.1.jre. Same library, different PURL classifier.
sso-service CVE-2025-69720 HIGH libtinfo6 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
sso-service CVE-2026-16742 HIGH libsystemd0 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).
sso-service CVE-2026-54369 HIGH libacl1 OS Vendor OS package from DHI base image. Fix depends on OS vendor (Debian security team).