Skip to content

Security triage review: 2026-08-19 (part 4/22) #293

Description

@github-actions

Automated Flatcar security-triage review batch 32222485591, part 4 of 22.

Run metadata

Summary

This part contains 21 decision group(s).

Recommendation Count
discovery_create_issue 7
discovery_ignore 12
discovery_update_issue 2
Confidence Count
high 13
low 5
medium 3
Severity Count
MEDIUM 1
n/a 20

Whole batch: 531 decision group(s) across 22 part(s).

Recommendation Count
cleanup_keep_open 34
discovery_create_issue 76
discovery_ignore 370
discovery_kernel_routing 1
discovery_update_issue 50
Confidence Count
high 328
low 88
medium 115
Severity Count
CRITICAL 2
HIGH 10
MEDIUM 5
n/a 514

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 70: libpcap (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/939952
  • CVEs / upstream IDs: CVE-2023-7256, CVE-2024-8006
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: net-libs/libpcap 1.10.6 (exact_name)
  • Existing issue matches: none

The production SBOM contains net-libs/libpcap 1.10.6, which is newer than the affected range (< 1.10.5) and includes the stated fixes.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 71: cups (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/940316
  • CVEs / upstream IDs: 940316
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The report concerns CUPS printer/PPD validation, with no CVE identifier, no established affected/fixed upstream version range, and no evidence that CUPS is shipped or used by Flatcar production images.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 72: net-analyzer/wireshark (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/941560
  • CVEs / upstream IDs: CVE-2024-8250, CVE-2024-9781
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Wireshark is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 73: unbound (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/941857
  • CVEs / upstream IDs: CVE-2024-8508
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-6925b78930a8ea754a64

Title: update: unbound

Name: unbound
CVEs: CVE-2024-8508
CVSSs: n/a
Action Needed: TBD
Summary: Unbounded name compression in Unbound can lead to denial of service; a patch is reported to apply cleanly to versions 1.19.3 and 1.20.0.

refmap.gentoo: https://bugs.gentoo.org/941857

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: unbound
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 74: python (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/942077
  • CVEs / upstream IDs: CVE-2024-9287
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-c4b3f0b6120def67f0c9

Title: update: python

Name: python
CVEs: CVE-2024-9287
CVSSs: n/a
Action Needed: TBD
Summary: CPython venv creation failed to quote paths in activation scripts, allowing an attacker-controlled virtual environment to execute commands when activated.

refmap.gentoo: https://bugs.gentoo.org/942077

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: python
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 75: podman (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/942556
  • CVEs / upstream IDs: GHSA-wq2p-5pc6-wpgf
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: acct-group/man 0-r3 (ambiguous_substring); acct-user/man 1-r3 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 76: 7zip (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/945395
  • CVEs / upstream IDs: ZDI-24-1532
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: app-arch/zip 3.0-r7 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 77: curl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/946291
  • CVEs / upstream IDs: CVE-2024-11053
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: net-misc/curl 8.21.0 (exact_name)
  • Existing issue matches: none

Production SBOM confirms net-misc/curl 8.21.0, the same package affected by CVE-2024-11053; no existing matching issue is present.

Exact proposed issue for action disc-3db38879d376bf88dafe

Title: update: curl

Name: curl
CVEs: CVE-2024-11053
CVSSs: n/a
Action Needed: update target
Summary: curl may leak .netrc credentials to an HTTP redirect target when the target entry omits a password or both login and password.

refmap.gentoo: https://bugs.gentoo.org/946291

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: curl

Group 78: asterisk (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/947790
  • CVEs / upstream IDs: CVE-2024-53566, GHSA-33x6-fj46-6rfh
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Asterisk is not present in the provided production SBOM matches, and there is no evidence that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 79: vim (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/947924
  • CVEs / upstream IDs: CVE-2025-22134
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: app-editors/vim 9.1.1652-r2 (exact_name)
  • Existing issue matches: update: vim #153 (open): update: vim

The production SBOM confirms app-editors/vim is shipped, and open issue #153 already tracks the same package but not CVE-2025-22134. Update it with this distinct CVE, advisory details, affected/fixed versions, and references; the shipped 9.1.1652-r2 version is newer than the 9.1.1003 fix.

Proposed additive update for action disc-95c4c8024737c971070b (issue #153)

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2025-22134
- Add Gentoo aliases/CVEs: CVE-2025-22134
- Add upstream context: Vim heap-buffer-overflow when switching buffers with visual mode active while executing :all; fixed in patch 9.1.1003.
- Review Gentoo severity: normal (source: https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8)
- Review upstream references: https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8, https://bugs.gentoo.org/show_bug.cgi?id=961498, https://codeberg.org/gentoo/gentoo/pulls/284
- Review Bugzilla description: From $URL:

###
Summary

A heap-buffer-overflow with visual mode was found in Vim < 9.1.1003
Impact

When switching to other buffers using the :all command and visual mode
still being active, this may cause a heap-buffer overflow, because Vim
does not properly end visual mode and therefore may tr...
- Review Bugzilla comment #2 by bacs at 2026-08-16T11:05:23Z: glsa^ with 937126

New Bugzilla comments in the processing window:
- Review Bugzilla comment #2 by bacs at 2026-08-16T11:05:23Z: glsa^ with 937126

Source: https://bugs.gentoo.org/947924

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 80: dev-lang/go (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/948232
  • CVEs / upstream IDs: CVE-2024-45336, CVE-2024-45341
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
  • Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go

LLM relevance decision requested manual review.; Issue mutation recommendation requires a relevant Flatcar status.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.; Issue mutation recommendation requires a relevant Flatcar status.
Exact proposed issue for action disc-6149e8906119d25ccf66

Title: update: dev-lang/go

Name: dev-lang/go
CVEs: CVE-2024-45336, CVE-2024-45341
CVSSs: n/a
Action Needed: update target
Summary: Go vulnerabilities involving sensitive headers being restored after cross-domain redirects and IPv6 zone IDs bypassing URI name constraints.

refmap.gentoo: https://bugs.gentoo.org/948232

Labels: advisory, security

Proposed additive update for action disc-4206141b65623d471353 (issue #64)
  • Add CVEs: CVE-2024-45336, CVE-2024-45341
  • Add refmap.gentoo: https://bugs.gentoo.org/948232
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): Go vulnerabilities involving sensitive headers being restored after cross-domain redirects and IPv6 zone IDs bypassing URI name constraints.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-lang/go
  • Update existing issue update: dev-lang/go #64 with new upstream context
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 81: openssl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/948515
  • CVEs / upstream IDs: CVE-2024-13176
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: dev-libs/openssl 3.5.7 (exact_name)
  • Existing issue matches: none

Flatcar production SBOM contains OpenSSL 3.5.7, which is newer than the listed fixed releases (3.3.3, 3.2.4, 3.1.8, and 3.0.16); no affected Flatcar version is evidenced.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 82: dev-java/openjdk, dev-java/openjdk-bin, dev-java/openjdk-jre-bin (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/948666
  • CVEs / upstream IDs: CVE-2025-21502
  • CVSS: 4.8
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CVE-2025-21502 affects OpenJDK/GraalVM packages, but the bundle provides no evidence that any affected Java package is shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 83: net-dns/bind (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949125
  • CVEs / upstream IDs: CVE-2024-11187, CVE-2024-12705, CVE-2025-40775
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: net-dns/bind 9.20.23 (exact_name)
  • Existing issue matches: update: net-dns/bind #61 (open): update: net-dns/bind

The production SBOM confirms net-dns/bind is shipped, and open issue #61 already tracks this package but does not list CVE-2024-11187, CVE-2024-12705, or CVE-2025-40775. Update that existing issue rather than creating a duplicate; the shipped 9.20.23 is newer than the reported fixes.

Proposed additive update for action disc-915e12c0bd1a6f59d732 (issue #61)
  • Add CVEs: CVE-2024-11187, CVE-2024-12705, CVE-2025-40775
  • Add refmap.gentoo: https://bugs.gentoo.org/949125
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): Bind vulnerabilities causing resource exhaustion via DoH or large additional sections and denial of service through invalid TSIG messages; fixes are reported in 9.18.33, 9.20.5, and 9.21.4.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2024-11187, CVE-2024-12705, CVE-2025-40775
- Add Gentoo aliases/CVEs: CVE-2024-11187, CVE-2024-12705, CVE-2025-40775
- Add upstream context: Bind vulnerabilities causing resource exhaustion via DoH or large additional sections and denial of service through invalid TSIG messages; fixes are reported in 9.18.33, 9.20.5, and 9.21.4.
- Review Gentoo severity: normal (source: https://kb.isc.org/docs/aa-00913)
- Review upstream references: https://kb.isc.org/docs/aa-00913
- Review Bugzilla description: Two vulnerabilities (CVE-2024-11187,CVE-2024-12705) have been fixed in the latest updates of bind.

Fixed in 9.18.33,9.20.5,9.21.4.
- Review Bugzilla comment #7 by bacs at 2026-08-16T10:20:32Z: glsa^ with 936568

New Bugzilla comments in the processing window:
- Review Bugzilla comment #7 by bacs at 2026-08-16T10:20:32Z: glsa^ with 936568

Source: https://bugs.gentoo.org/949125

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 84: net-misc/curl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949330
  • CVEs / upstream IDs: CVE-2025-0167, CVE-2025-0665, CVE-2025-0725
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: create_issue (confidence: high)
  • SBOM matches: net-misc/curl 8.21.0 (exact_name)
  • Existing issue matches: none

Production SBOM confirms net-misc/curl 8.21.0; the Gentoo advisory identifies three curl CVEs fixed in 8.12.0, and no existing Flatcar issue match is present.

Exact proposed issue for action disc-c49d92d7003186c333c8

Title: update: net-misc/curl

Name: net-misc/curl
CVEs: CVE-2025-0167, CVE-2025-0665, CVE-2025-0725
CVSSs: n/a
Action Needed: update target
Summary: Curl vulnerabilities involving netrc/default credential leakage, eventfd double close, and a gzip integer overflow; the source states that curl 8.12.0 contains fixes.

refmap.gentoo: https://bugs.gentoo.org/949330

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: net-misc/curl

Group 85: curl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949342
  • CVEs / upstream IDs: CURL ISSUE 16197
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: net-misc/curl 8.21.0 (exact_name)
  • Existing issue matches: none

Flatcar ships production curl 8.21.0, which is newer than the reported 8.13.0 fix; no existing Flatcar issue requires updating.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 86: dev-lang/go (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949405
  • CVEs / upstream IDs: CVE-2025-22866, GO ISSUE 71383
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
  • Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-776a79d63c4851103e98

Title: update: dev-lang/go

Name: dev-lang/go
CVEs: CVE-2025-22866, GO ISSUE 71383
CVSSs: n/a
Action Needed: update target
Summary: A variable-time instruction in Go's ppc64le P-256 elliptic-curve assembly leaks a small number of secret-scalar bits through a timing side channel; upstream states this is not believed sufficient to recover private keys in well-known protocols.

refmap.gentoo: https://bugs.gentoo.org/949405

Labels: advisory, security

Proposed additive update for action disc-a10b67cebf4b5d27cb38 (issue #64)
  • Add CVEs: CVE-2025-22866, GO ISSUE 71383
  • Add refmap.gentoo: https://bugs.gentoo.org/949405
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): A variable-time instruction in Go's ppc64le P-256 elliptic-curve assembly leaks a small number of secret-scalar bits through a timing side channel; upstream states this is not believed sufficient to recover private keys in well-known protocols.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-lang/go
  • Update existing issue update: dev-lang/go #64 with new upstream context
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 87: dev-ruby/net-imap (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949413
  • CVEs / upstream IDs: CVE-2025-25186
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 88: dev-libs/libtasn1 (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949497
  • CVEs / upstream IDs: CVE-2024-12133
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: dev-libs/libtasn1 4.21.0 (exact_name)
  • Existing issue matches: none

libtasn1 is present in the production SBOM, but the shipped version is 4.21.0, which is newer than the stated fixed version 4.20.0; no evidence shows an affected Flatcar version.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 89: openssl (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/949620
  • CVEs / upstream IDs: CVE-2024-12797
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: dev-libs/openssl 3.5.7 (exact_name)
  • Existing issue matches: none

OpenSSL is shipped in the production SBOM, but the recorded production version is 3.5.7, which is newer than the listed fixed releases (3.1.8, 3.2.4, and 3.3.3) for CVE-2024-12797. The affected range is limited to OpenSSL >=3.1 before those fixes; no affected Flatcar production version is evidenced.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 90: dev-lang/go (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/951230
  • CVEs / upstream IDs: CVE-2025-22870, GO ISSUE 71984
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
  • Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go

LLM relevance decision requested manual review.; Issue mutation recommendation requires a relevant Flatcar status.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.; Issue mutation recommendation requires a relevant Flatcar status.
Exact proposed issue for action disc-169d4e3496ca398a4f54

Title: update: dev-lang/go

Name: dev-lang/go
CVEs: CVE-2025-22870, GO ISSUE 71984
CVSSs: n/a
Action Needed: update target
Summary: Go proxy matching could improperly treat an IPv6 zone ID as a hostname component, allowing a NO_PROXY pattern to bypass the proxy.

refmap.gentoo: https://bugs.gentoo.org/951230

Labels: advisory, security

Proposed additive update for action disc-9bcab5916407ae05ea57 (issue #64)
  • Add CVEs: CVE-2025-22870, GO ISSUE 71984
  • Add refmap.gentoo: https://bugs.gentoo.org/951230
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): Go proxy matching could improperly treat an IPv6 zone ID as a hostname component, allowing a NO_PROXY pattern to bypass the proxy.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-lang/go
  • Update existing issue update: dev-lang/go #64 with new upstream context
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions