Skip to content

Security triage review: 2026-08-18 (part 17/20) #286

Description

@github-actions

Automated Flatcar security-triage review batch 32105957657, part 17 of 20.

Run metadata

Summary

This part contains 25 decision group(s).

Recommendation Count
discovery_create_issue 5
discovery_ignore 17
discovery_update_issue 3
Confidence Count
high 21
low 1
medium 3
Severity Count
HIGH 2
n/a 23

Whole batch: 420 decision group(s) across 20 part(s).

Recommendation Count
cleanup_keep_open 34
discovery_create_issue 70
discovery_ignore 259
discovery_kernel_routing 1
discovery_update_issue 56
Confidence Count
high 251
low 84
medium 85
Severity Count
CRITICAL 4
HIGH 11
MEDIUM 8
n/a 397

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 335: Net-OAuth (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/08/16/3
  • CVEs / upstream IDs: CVE-2026-72887
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go/auth v0.16.5 (ambiguous_substring); cloud.google.com/go/auth v0.17.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 336: Net-OAuth (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/08/16/4
  • CVEs / upstream IDs: CVE-2026-72888
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go/auth v0.16.5 (ambiguous_substring); cloud.google.com/go/auth v0.17.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 337: OpenZFS (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/08/16/5
  • CVEs / upstream IDs: OPENZFS UPSTREAM ISSUE Security triage review: 2026-07-17 (part 5/5) #26, OPENZFS PR #18620 (CONTESTED, RELATED TO OZ-7)
  • CVSS: 8.7, 8.4, 7.8, 7.3, 6.4, 5.1, 4.4, 3.4, 1.9, 8.3, 8.8, 6.9
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: none
  • Existing issue matches: none

OpenZFS has no production SBOM match or other evidence of shipment/use by Flatcar; the report has no assigned CVEs, no established affected range or fixes, and its accuracy is explicitly questioned in the thread.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 338: lyx (and associated TeX Live tools biber, xindy/texindy, and xindex) (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/08/17/1
  • CVEs / upstream IDs: 00A, 00B, 00C, 00D, 00E, 00G, 00H, 00I, 00K, 00DE, 00DE-2, BIBER-47CCD83187, BIBER-30C2A10FD1, BIBER-584A1E3729, BIBER-74252E608E, XINDY-R79990
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

LyX and the associated TeX Live document-processing tools are desktop/document-authoring ecosystem components, and no Flatcar production SBOM evidence shows that any affected package is shipped or used.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 339: shim / grub2 (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/08/18/1
  • CVEs / upstream IDs: F-1, F-9, S-SBAT-UINT16, GRUB-F01
  • CVSS: 7.4, 6.4
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-9401f214bd2180973c3d

Title: update: shim / grub2

Name: shim / grub2
CVEs: F-1, F-9, S-SBAT-UINT16, GRUB-F01
CVSSs: 7.4, 6.4
Action Needed: TBD
Summary: A disputed, AI-assisted report alleges a combined shim fallback.efi BOOT.CSV path traversal and missing verification, SBAT UINT16 truncation, and GRUB2 memdisk/procfs verifier bypass. Upstream shim maintainers and Red Hat Product Security question the security impact and note that the prerequisites already provide equivalent control; no CVE or confirmed fix is reported.

refmap.gentoo: TBD

Labels: advisory, security, cvss/HIGH

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: shim / grub2
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 340: golang.org/x/crypto (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5005
  • CVEs / upstream IDs: CVE-2026-39833, GO-2026-5005
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: golang.org/x/crypto v0.31.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.43.0 (exact_name); golang.org/x/crypto v0.45.0 (exact_name); golang.org/x/crypto v0.53.0 (exact_name)
  • Existing issue matches: update: golang.org/x/crypto #236 (open): update: golang.org/x/crypto

Open issue #236 already covers CVE-2026-39833 and GO-2026-5005 for golang.org/x/crypto; production SBOM contains affected versions, and the newly supplied GHSA/reference metadata can be reflected in the existing issue.

Proposed additive update for action disc-72905e3794357ab2fc2a (issue #236)
  • Add CVEs: CVE-2026-39833, GO-2026-5005
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): Before version 0.52.0, the in-memory SSH agent keyring accepted ConfirmBeforeUse constraints without enforcing them, allowing signing without confirmation; unsupported constraints now return an error.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: GO-2026-5005
- Review upstream references: GHSA-jppx-rxg9-jmrx, https://go.dev/issue/79436, https://go.dev/cl/778642, https://groups.google.com/g/golang-announce/c/a082jnz-LvI
- Review Bugzilla description: The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsu...

Source: https://pkg.go.dev/vuln/GO-2026-5005

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 341: golang.org/x/crypto (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5006
  • CVEs / upstream IDs: CVE-2026-39832, GO-2026-5006
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: golang.org/x/crypto v0.31.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.43.0 (exact_name); golang.org/x/crypto v0.45.0 (exact_name); golang.org/x/crypto v0.53.0 (exact_name)
  • Existing issue matches: update: golang.org/x/crypto #236 (open): update: golang.org/x/crypto

The production SBOM contains affected golang.org/x/crypto versions, and open issue #236 already tracks the same package but not CVE-2026-39832/GO-2026-5006; update it rather than creating a duplicate.

Proposed additive update for action disc-6f994e81b6765c220298 (issue #236)
  • Add CVEs: CVE-2026-39832, GO-2026-5006
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): SSH agent key constraint extensions were omitted when forwarding keys, silently removing destination restrictions and permitting unrestricted remote use; fixed by serializing constraints and rejecting unsupported extensions in NewKeyring().

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-39832, GO-2026-5006
- Add upstream context: SSH agent key constraint extensions were omitted when forwarding keys, silently removing destination restrictions and permitting unrestricted remote use; fixed by serializing constraints and rejecting unsupported extensions in NewKeyring().
- Review upstream references: CVE-2026-39832, GHSA-f5wc-c3c7-36mc, https://go.dev/issue/79435, https://go.dev/cl/778640, https://go.dev/cl/778641
- Review Bugzilla description: When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all c...

Source: https://pkg.go.dev/vuln/GO-2026-5006

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 342: golang.org/x/crypto (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5021
  • CVEs / upstream IDs: CVE-2026-42508, GHSA-5cgq-3rg8-m6cv, GO-2026-5021
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: golang.org/x/crypto v0.31.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.43.0 (exact_name); golang.org/x/crypto v0.45.0 (exact_name); golang.org/x/crypto v0.53.0 (exact_name)
  • Existing issue matches: update: golang.org/x/crypto #236 (open): update: golang.org/x/crypto

The production SBOM contains exact golang.org/x/crypto modules at affected versions, and existing open issue #236 already tracks this package but not CVE-2026-42508/GO-2026-5021. Update it with the distinct vulnerability, affected import path, and fixed-version context.

Proposed additive update for action disc-c0d35ad71ace718c0f2e (issue #236)
  • Add CVEs: CVE-2026-42508, GHSA-5cgq-3rg8-m6cv, GO-2026-5021
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): A revoked CA SignatureKey was not correctly checked in ssh/knownhosts, allowing authentication bypass; revocation checks now cover both key and SignatureKey.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-42508, GHSA-5CGQ-3RG8-M6CV, GO-2026-5021
- Review Action Needed: update target
- Add upstream context: A revoked CA SignatureKey was not correctly checked in ssh/knownhosts, allowing authentication bypass; revocation checks now cover both key and SignatureKey.
- Review upstream references: CVE-2026-42508, GHSA-5cgq-3rg8-m6cv, https://go.dev/issue/79568, https://go.dev/cl/781220, https://groups.google.com/g/golang-announce/c/a082jnz-LvI
- Review Bugzilla description: Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for `@revoked`.

Source: https://pkg.go.dev/vuln/GO-2026-5021

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 343: Go stdlib and golang.org/x/net (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5026
  • CVEs / upstream IDs: CVE-2026-39821, GO-2026-5026
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: golang.org/x/net v0.33.0 (exact_name); golang.org/x/net v0.33.0 (exact_name); golang.org/x/net v0.34.0 (exact_name); golang.org/x/net v0.34.0 (exact_name); golang.org/x/net v0.38.0 (exact_name); golang.org/x/net v0.43.0 (exact_name); golang.org/x/net v0.46.0 (exact_name); golang.org/x/net v0.47.0 (exact_name); golang.org/x/net v0.47.0 (exact_name); golang.org/x/net v0.47.0 (exact_name); golang.org/x/net v0.55.0 (exact_name); golang.org/x/net v0.55.0 (exact_name); golang.org/x/net v0.55.0 (exact_name)
  • Existing issue matches: none

Production SBOM contains exact golang.org/x/net module matches at affected versions below 0.55.0; the advisory directly affects golang.org/x/net/idna.

Exact proposed issue for action disc-c55e9193d16b7edf6cee

Title: update: Go stdlib and golang.org/x/net

Name: Go stdlib and golang.org/x/net
CVEs: CVE-2026-39821, GO-2026-5026
CVSSs: n/a
Action Needed: TBD
Summary: Go's IDNA handling incorrectly accepts Punycode labels that decode to ASCII-only labels, potentially enabling privilege escalation when hostname authorization checks and Unicode conversion are combined.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: Go stdlib and golang.org/x/net

Group 344: github.com/dadrus/heimdall (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5075
  • CVEs / upstream IDs: CVE-2026-57210, GHSA-38x9-25wx-7fg2
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or SBOM evidence indicates that Flatcar ships or uses github.com/dadrus/heimdall; this is an unrelated Go application dependency absent from the production image evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 345: github.com/nezhahq/nezha (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5119
  • CVEs / upstream IDs: CVE-2026-48119, GHSA-4g6j-g789-rghm, GO-2026-5119
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Nezha is an application-level Go monitoring project with no evidence it is shipped or used by Flatcar; no production SBOM matches or existing issues are present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 346: Traefik (github.com/traefik/traefik) (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5152
  • CVEs / upstream IDs: CVE-2026-48491, GHSA-5r4w-85f3-pw66, GO-2026-5152
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Traefik is an application-level Go reverse proxy, and the bundle provides no evidence that Flatcar ships or uses it; there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 347: github.com/dgraph-io/dgraph (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5274
  • CVEs / upstream IDs: CVE-2026-40173, GHSA-95mq-xwj4-r47p, GO-2026-5274
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This is a Dgraph application/Go-module vulnerability, and the evidence contains no Flatcar production, SDK, sysext, or build usage; no SBOM match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 348: github.com/traefik/traefik (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5287
  • CVEs / upstream IDs: CVE-2026-53622, GHSA-9cr8-q42q-g8m7
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM match or other evidence shows that Flatcar ships or uses Traefik; this Go application/module is therefore not relevant to the tracked Flatcar package set.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 349: github.com/canonical/lxd (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5306
  • CVEs / upstream IDs: CVE-2026-34179, GHSA-c3h3-89qf-jqm5, GO-2026-5306
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM or other Flatcar package evidence shows that Canonical LXD is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 350: github.com/canonical/lxd (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5368
  • CVEs / upstream IDs: CVE-2026-34177, GHSA-fm2x-c5qw-4h6f, GO-2026-5368
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects the upstream Go LXD module, but the evidence provides no indication that Flatcar ships or uses LXD, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 351: rclone (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5466
  • CVEs / upstream IDs: CVE-2026-41179, GHSA-jfwf-28xr-xw6q, GO-2026-5466
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows that rclone is shipped or used by Flatcar, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 352: github.com/dgraph-io/dgraph (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5516
  • CVEs / upstream IDs: CVE-2026-41327, GHSA-mrxx-39g5-ph77
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Dgraph is an application/database server and no SBOM or other evidence shows it is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 353: github.com/dgraph-io/dgraph (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5529
  • CVEs / upstream IDs: CVE-2026-34976, GHSA-p5rh-vmhp-gvcw, GO-2026-5529
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Dgraph is an application-level Go database package, and the evidence provides no indication that Flatcar ships or uses it; there are no production SBOM matches or existing Flatcar issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 354: github.com/traefik/traefik (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5532
  • CVEs / upstream IDs: CVE-2026-41181, GHSA-p6hg-qh38-555r, GO-2026-5532
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No Flatcar SBOM package match or other evidence shows that Traefik is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 355: github.com/canonical/lxd (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5576
  • CVEs / upstream IDs: CVE-2026-34178, GO-2026-5576, GHSA-q96j-3fmm-7fv4
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The affected Go module is LXD, and the evidence provides no indication that Flatcar ships or uses LXD; there are no production SBOM matches or existing Flatcar issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 356: github.com/rclone/rclone (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5596
  • CVEs / upstream IDs: CVE-2026-49980, GHSA-qw24-gh76-8rvv, GO-2026-5596
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or production SBOM/package evidence shows that Flatcar ships or uses rclone; this Go application vulnerability is therefore not Flatcar-relevant.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 357: github.com/docker/docker (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5668
  • CVEs / upstream IDs: CVE-2026-41568, GHSA-vp62-88p7-qqf5
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: acct-group/docker 0-r3 (exact_name); app-containers/docker 29.1.3-r1 (exact_name); github.com/docker/docker v28.0.0-rc.2+incompatible (exact_name); github.com/docker/docker v28.1.1+incompatible (exact_name); github.com/dotcloud/docker v0.11.2-0.20140522020950-55d41c3e21e1 (exact_name)
  • Existing issue matches: none

Production SBOM evidence confirms Flatcar ships Docker and the affected github.com/docker/docker daemon module; the vulnerability affects Docker daemon docker cp handling and no existing issue match is present.

Exact proposed issue for action disc-7b979ef7998c3bc29567

Title: update: github.com/docker/docker

Name: github.com/docker/docker
CVEs: CVE-2026-41568, GHSA-VP62-88P7-QQF5
CVSSs: n/a
Action Needed: TBD
Summary: A race condition in the Docker daemon's docker cp operation can allow an attacker to create arbitrary empty host files by replacing a destination path with a symbolic link.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: github.com/docker/docker

Group 358: stdlib; golang.org/x/net (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5942
  • CVEs / upstream IDs: CVE-2026-46600, GO-2026-5942
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: golang.org/x/net v0.33.0 (exact_name); golang.org/x/net v0.33.0 (exact_name); golang.org/x/net v0.34.0 (exact_name); golang.org/x/net v0.34.0 (exact_name); golang.org/x/net v0.38.0 (exact_name); golang.org/x/net v0.43.0 (exact_name); golang.org/x/net v0.46.0 (exact_name); golang.org/x/net v0.47.0 (exact_name); golang.org/x/net v0.47.0 (exact_name); golang.org/x/net v0.47.0 (exact_name); golang.org/x/net v0.55.0 (exact_name); golang.org/x/net v0.55.0 (exact_name); golang.org/x/net v0.55.0 (exact_name)
  • Existing issue matches: none

The production SBOM contains exact golang.org/x/net module matches at versions v0.33.0 through v0.55.0, all below the fixed v0.56.0 and therefore within the affected range for CVE-2026-46600/GO-2026-5942.

Exact proposed issue for action disc-0463ce6352e4b94fb376

Title: update: stdlib; golang.org/x/net

Name: stdlib; golang.org/x/net
CVEs: CVE-2026-46600, GO-2026-5942
CVSSs: n/a
Action Needed: TBD
Summary: Parsing an invalid SVCB or HTTPS DNS record can cause a panic when a parameter value size overflows the message buffer, affecting Go stdlib net and golang.org/x/net/dns/dnsmessage.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: stdlib; golang.org/x/net

Group 359: Go stdlib (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-5972
  • CVEs / upstream IDs: CVE-2026-33818, GO-2026-5972
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: cloud.google.com/go v0.121.6 (ambiguous_substring); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (ambiguous_substring); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.7 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring); stdlib go1.26.3-X:nodwarf5 (ambiguous_substring)
  • Existing issue matches: none

The production SBOM contains the Go standard library at 1.26.3, which is within the affected >= 1.26.0-0, < 1.26.6 range; no existing matching issue is present.

Exact proposed issue for action disc-ebb7ae7cdf766c16ef96

Title: update: Go stdlib

Name: Go stdlib
CVEs: CVE-2026-33818, GO-2026-5972
CVSSs: n/a
Action Needed: TBD
Summary: Go encoding/asn1 Unmarshal lacked a recursion limit, allowing deeply nested recursive structures to exhaust the stack; fixed in Go 1.25.13, 1.26.6, and 1.27.0-rc.3.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: Go stdlib

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions