replicatedhq / replicatedhq/replicated-sdk

[Security] containerd 1.7.32 CVEs (fixed in 1.7.33) + glibc CVE-2026-5450 in replicated-sdk:1.19.6

Open Beginner friendly
#437 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
5
Forks
10
Avg merge
12h 23m
Merged PRs (30d)
5

Description

Grype scan of replicated/replicated-sdk:1.19.6 flags 3 vulnerabilities.

CVE / GHSA Package Severity Fixed in
GHSA-xhf5-7wjv-pqxp github.com/containerd/containerd v1.7.32 High 1.7.33
GHSA-jpcc-p29g-p8mq github.com/containerd/containerd v1.7.32 Medium 1.7.33
CVE-2026-5450 glibc 2.42-r5 (base image) Critical no upstream fix yet

containerd was recently bumped to 1.7.32 (#432); bumping to 1.7.33 clears both containerd advisories. The glibc CVE has no fix available upstream yet — tracking only.

Scanner: grype v0.111.0.
1.19.6 is latest. Latest release, published 2026-06-08. No newer version

Image

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the build or dependency entry point that produced replicated/replicated-sdk:1.19.6 and references containerd 1.7.32; review the recent bump in #432 and run the reported Grype v0.111.0 scan. Done means containerd is 1.7.33 and both listed containerd advisories are cleared, while CVE-2026-5450 remains tracked until an upstream glibc fix exists.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
devops, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.