[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/agent:0.28.1
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Overview
Daily container scan findings for `ghcr.io/github/gh-aw-firewall/agent:0.28.1` (pinned `sha256:5e3f6ee27eeae07195838b97ac4aa2f8aea42a7c55f1c0d3e17d8e88e294ad0d`), an Ubuntu 22.04-based image.
### Key metrics
| Severity | Count |
|---|---|
| Critical | 0 |
| High | 9 |
| Medium | 293 (141 distinct CVE/GHSA IDs) |
| Low | 62 |
| Negligible | 19 |
| Unknown | 0 |
| License violations | 0 |
### Vulnerabilities
High (9)
| CVE/GHSA | Package | Fixed version |
|---|---|---|
| GO-2026-5026 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GHSA-rgw5-rvv9-x895 | brace-expansion@5.0.7 | 5.0.9 |
| GO-2026-5942 | stdlib@go1.26.5 | 1.26.6, 1.27.0-rc.3 |
| GHSA-mh99-v99m-4gvg | brace-expansion@5.0.7 | 5.0.8 |
| GHSA-mwp4-54f8-5fhr | ip-address@10.2.0 | 10.3.1 |
| GO-2026-6089 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6088 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6090 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-5972 | stdlib@go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
Medium (293 lines, 141 distinct CVE/GHSA IDs, grouped by affected package)
| Package | Version | CVE/GHSA count | CVE/GHSA IDs |
|---|---|---|---|
| bind9-libs (+ bind9-host, bind9-dnsutils, dnsutils) | 1:9.18.39-0ubuntu0.22.04.4 | 29 | CVE-2022-2795, CVE-2023-2828, CVE-2023-4408, CVE-2023-50387, CVE-2023-50868, CVE-2024-0760, CVE-2024-11187, CVE-2024-12705, CVE-2024-1737, CVE-2024-1975, CVE-2025-40778, CVE-2025-40780, CVE-2025-8677, CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, CVE-2026-1519, CVE-2026-3039, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591, CVE-2026-3592, CVE-2026-5946, CVE-2026-5950 |
| libexpat1 | 2.4.7-1ubuntu0.7 | 22 | CVE-2025-59375, CVE-2025-66382, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-41080, CVE-2026-45186, CVE-2026-4739, CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412, CVE-2026-72522 |
| python3.10 / libpython3.10-stdlib / libpython3.10-minimal / python3.10-minimal | 3.10.12-1~22.04.16 | 13 | CVE-2025-12781, CVE-2025-15366, CVE-2025-15367, CVE-2026-0864, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-18503, CVE-2026-3446, CVE-2026-4360, CVE-2026-67422, CVE-2026-6879, CVE-2026-7210 |
| perl / libperl5.34 / perl-base / perl-modules-5.34 | 5.34.0-3ubuntu1.7 | 13 | CVE-2023-31486, CVE-2025-15649, CVE-2026-12087, CVE-2026-13221, CVE-2026-15534, CVE-2026-42497, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432, CVE-2026-57433, CVE-2026-7017, CVE-2026-9538 |
| libssh-4 | 0.9.6-2ubuntu0.22.04.7 | 10 | CVE-2026-15370, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849, CVE-2026-59850, CVE-2026-59851 |
| libglib2.0-0 | 2.72.4-0ubuntu2.9 | 9 | CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016 |
| gh | 2.97.0 | 6 | CVE-2026-45803, CVE-2026-59831, CVE-2026-64652, CVE-2026-64653, CVE-2026-64654, CVE-2026-64655 |
| bsdutils / util-linux / mount / libblkid1 / libmount1 / libsmartcols1 / libuuid1 | 2.37.2-4ubuntu3.5 | 6 | CVE-2026-13595, CVE-2026-27456, CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-53615 |
| php8.1-common / php8.1-gd / php8.1-intl | 8.1.2-1ubuntu2.25 | 2 | CVE-2026-17543, CVE-2026-7260 |
| libtiff5 | 4.3.0-6ubuntu0.13 | 3 | CVE-2026-12912, CVE-2026-36849, CVE-2026-4775 |
| curl / libcurl3-gnutls / libcurl4 | 7.81.0-1ubuntu1.25 | 1 | CVE-2026-11856 |
| libpam-modules(-bin) / libpam-runtime / libpam0g | 1.4.0-11ubuntu2.7 | 1 | CVE-2024-10041 |
| git / git-man | 1:2.34.1-1ubuntu1.17 | 1 | CVE-2024-52005 |
| tar | 1.34+dfsg-1ubuntu0.1.22.04.6 | 2 | CVE-2026-18477, CVE-2026-18508 |
| libp11-kit0 | 0.24.0-6build1 | 2 | CVE-2026-13757, CVE-2026-18938 |
| liblmdb0 | 0.9.24-1build2 | 1 | CVE-2026-22185 |
| libacl1 | 2.3.1-1 | 2 | CVE-2026-54369, CVE-2026-54370 |
| libattr1 | 1:2.5.1-1build1 | 1 | CVE-2026-54371 |
| libssl-dev / libssl3 / openssl | 3.0.2-0ubuntu1.26 | 1 | CVE-2026-54876 |
| coreutils | 8.32-4.1ubuntu1.3 | 2 | CVE-2026-56391, CVE-2026-56392 |
| diffutils | 1:3.8-0ubuntu2 | 1 | CVE-2026-53910 |
| libc6 / libc-bin | 2.35-0ubuntu3.14 | 2 | CVE-2026-6368, CVE-2026-6791 |
| libgd3 | 2.3.0-2ubuntu2.3 | 1 | CVE-2026-9672 |
| ip-address (JS) | 10.2.0 | 2 | GHSA-22jq-vg5j-6vgg (fix 10.2.1), GHSA-4xrf-jv44-h6hh (fix 10.2.2) |
| undici (JS) | 6.27.0 | 3 | GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5, GHSA-v3r7-h72x-cjcm (fix 6.28.0) |
| tar (JS) | 7.5.19 | 1 | GHSA-r292-9mhp-454m (fix 7.5.21) |
| stdlib (Go) | go1.26.5 | 2 | GO-2026-6091, GO-2026-6218 (fix 1.25.13, 1.26.6, 1.27.0-rc.3) |
Low (62)
| CVE | Package | Version |
|---|---|---|
| CVE-2016-2781 | coreutils | 8.32-4.1ubuntu1.3 |
| CVE-2017-7189 | php8.1-common, php8.1-gd, php8.1-intl | 8.1.2-1ubuntu2.25 |
| CVE-2017-7475 | libcairo2 | 1.16.0-5ubuntu2.1 |
| CVE-2018-1000021 | git-man, git | 1:2.34.1-1ubuntu1.17 |
| CVE-2018-10126 | libjpeg-turbo8 | 2.1.2-0ubuntu1 |
| CVE-2018-18064 | libcairo2 | 1.16.0-5ubuntu2.1 |
| CVE-2020-25697 | libx11-6, libx11-data | 2:1.7.5-1ubuntu0.3 |
| CVE-2022-27943 | gcc-12-base, libgcc-s1, libstdc++6 | 12.3.0-1ubuntu1~22.04.3 |
| CVE-2022-3219 | dirmngr, gnupg-l10n, gnupg-utils, gnupg, gpg-agent, gpg-wks-client, gpg-wks-server, gpg, gpgconf, gpgsm, gpgv | 2.2.27-3ubuntu2.5 |
| CVE-2022-41409 | libpcre2-8-0 | 10.39-3ubuntu0.1 |
| CVE-2022-4899 | libzstd1 | 1.4.8+dfsg-3build1 |
| CVE-2023-29383 | login, passwd | 1:4.8.1-2ubuntu2.2 |
| CVE-2023-50495 | libncurses6, libncursesw6, libtinfo6, ncurses-base, ncurses-bin | 6.3-2ubuntu0.2 |
| CVE-2024-2236 | libgcrypt20 | 1.9.4-3ubuntu3.2 |
| CVE-2024-56433 | login, passwd | 1:4.8.1-2ubuntu2.2 |
| CVE-2025-50422 | libcairo2 | 1.16.0-5ubuntu2.1 |
| CVE-2025-5222 | libicu70 | 70.1-2 |
| CVE-2025-5278 | coreutils | 8.32-4.1ubuntu1.3 |
| CVE-2025-6141 | libncurses6, libncursesw6, libtinfo6, ncurses-base, ncurses-bin | 6.3-2ubuntu0.2 |
| CVE-2026-40228 | libsystemd0, libudev1 | 249.11-0ubuntu3.22 |
| CVE-2026-42250 | libbz2-1.0 | 1.0.8-5build1 |
| CVE-2026-57062 | dirmngr, gnupg-l10n, gnupg-utils, gnupg, gpg-agent, gpg-wks-client, gpg-wks-server, gpg, gpgconf, gpgsm, gpgv | 2.2.27-3ubuntu2.5 |
| CVE-2026-8932 | curl, libcurl3-gnutls, libcurl4 | 7.81.0-1ubuntu1.25 |
Negligible (19)
| CVE | Package | Version |
|---|---|---|
| CVE-2016-20013 | libc-bin, libc6 | 2.35-0ubuntu3.14 |
| CVE-2017-11164 | libpcre3 | 2:8.39-13ubuntu0.22.04.1 |
| CVE-2018-5709 | libgssapi-krb5-2, libk5crypto3, libkrb5-3, libkrb5support0 | 1.19.2-2ubuntu0.8 |
| CVE-2020-10735 | libpython3.10-minimal, libpython3.10-stdlib, python3.10-minimal, python3.10 | 3.10.12-1~22.04.16 |
| CVE-2022-24975 | git-man, git | 1:2.34.1-1ubuntu1.17 |
| CVE-2023-47039 | libperl5.34, perl-base, perl-modules-5.34, perl | 5.34.0-3ubuntu1.7 |
| CVE-2023-52355 | libtiff5 | 4.3.0-6ubuntu0.13 |
| CVE-2026-11979 | libxml2 | 2.9.13+dfsg-1ubuntu0.12 |
### License violations
None found for this image.
### Next actions
- Update the embedded Go toolchain to 1.26.6+ (or 1.27.0-rc.3) to close 6 of 9 High findings and both remaining Medium `GO-2026-*` findings.
- Bump `brace-expansion` to 5.0.9 and `ip-address` (JS) to 10.3.1 to close the remaining High findings.
- The `bind9-libs`/`bind9-host`/`bind9-dnsutils`/`dnsutils` family (29 Medium CVEs) and `libexpat1` (22 Medium CVEs) are the largest single remediation opportunities — a base-image rebuild pulling the latest Ubuntu 22.04 security updates for `bind9` and `expat` will resolve the bulk of the Medium backlog in one step.
- Upgrade `gh` CLI from 2.97.0 to the latest release to close 6 Medium CVEs.
- Bump `libssh-4`, `libglib2.0-0`, `util-linux` family, and `tar` to their latest Ubuntu security-patched versions.
- This image is rebuilt weekly via the daily `gh aw compile --force-refresh-container-pins` job, which will pick up all upstream Ubuntu security patches automatically.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31929401072) · auto · 438.5 AIC · ⌖ 15.1 AIC · ⊞ 7.2K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.