Skip to content

Security triage review: 2026-08-19 (part 7/22) #296

Description

@github-actions

Automated Flatcar security-triage review batch 32222485591, part 7 of 22.

Run metadata

Summary

This part contains 27 decision group(s).

Recommendation Count
discovery_create_issue 4
discovery_ignore 20
discovery_update_issue 3
Confidence Count
high 21
low 3
medium 3
Severity Count
HIGH 1
n/a 26

Whole batch: 531 decision group(s) across 22 part(s).

Recommendation Count
cleanup_keep_open 34
discovery_create_issue 76
discovery_ignore 370
discovery_kernel_routing 1
discovery_update_issue 50
Confidence Count
high 328
low 88
medium 115
Severity Count
CRITICAL 2
HIGH 10
MEDIUM 5
n/a 514

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 128: util-linux (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/967612
  • CVEs / upstream IDs: CVE-2025-14104
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: sys-apps/util-linux 2.41.4-r1 (exact_name)
  • Existing issue matches: update: util-linux #70 (open): update: util-linux

The production SBOM confirms util-linux is shipped, and the open matching issue 70 does not include CVE-2025-14104 or Gentoo bug 967612. The shipped 2.41.4-r1 version is newer than the stated 2.41.3 fix, but the existing util-linux tracking issue should be updated with this CVE and reference.

Proposed additive update for action disc-10e48fe0ef686e837aa3 (issue #70)
  • Add CVEs: CVE-2025-14104
  • Add refmap.gentoo: https://bugs.gentoo.org/967612
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): Heap buffer overread in util-linux setpwnam() when processing 256-byte usernames, affecting SUID login-utils utilities that write to the password database.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2025-14104
- Add Gentoo aliases/CVEs: CVE-2025-14104
- Add upstream context: Heap buffer overread in util-linux setpwnam() when processing 256-byte usernames, affecting SUID login-utils utilities that write to the password database.
- Review Gentoo severity: minor
- Review Bugzilla description: """
A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.
"""

https://github.com/util-linux/util-linu...
- Review Bugzilla comment #2 by bacs at 2026-08-16T12:32:40Z: glsa^ with 971935

New Bugzilla comments in the processing window:
- Review Bugzilla comment #2 by bacs at 2026-08-16T12:32:40Z: glsa^ with 971935

Source: https://bugs.gentoo.org/967612

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 129: dropbear (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/967696
  • CVEs / upstream IDs: CVE-2025-14282
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-32990b2b63369914eceb

Title: update: dropbear

Name: dropbear
CVEs: CVE-2025-14282
CVSSs: n/a
Action Needed: update target
Summary: Dropbear server versions 2024.84 through 2025.88 contain a privilege-escalation vulnerability allowing authenticated users to run arbitrary programs as root, depending on other system programs; fixed in 2025.89.

refmap.gentoo: https://bugs.gentoo.org/967696

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dropbear
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 130: nginx (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/967910
  • CVEs / upstream IDs: CVE-2025-53859
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing Flatcar issue or production SBOM evidence shows that nginx is shipped or used by Flatcar; this is not a kernel issue.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 131: gnupg (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/968171
  • CVEs / upstream IDs: T7901
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: app-crypt/gnupg 2.5.20-r1 (exact_name)
  • Existing issue matches: none

The production SBOM contains the exact GnuPG package, but at 2.5.20-r1, which is newer than the stated fixed version 2.5.16 and outside the affected range (<2.5.16).

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 132: app-crypt/age (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/968204
  • CVEs / upstream IDs: 968204
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

app-crypt/age has no production SBOM match or other evidence of shipment or use by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 133: libpcap (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/968315
  • CVEs / upstream IDs: CVE-2025-11961, CVE-2025-11964
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: net-libs/libpcap 1.10.6 (exact_name)
  • Existing issue matches: none

The production SBOM contains net-libs/libpcap 1.10.6, while the reported affected range is below 1.10.6 and no existing Flatcar issue matches these CVEs.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 134: libtasn1 (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/968531
  • CVEs / upstream IDs: CVE-2025-13151
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: dev-libs/libtasn1 4.21.0 (exact_name)
  • Existing issue matches: none

Production SBOM contains dev-libs/libtasn1 4.21.0, while CVE-2025-13151 affects 4.20.0 and is fixed in 4.21.0.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 135: www-client/chromium (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969084
  • CVEs / upstream IDs: CVE-2026-1220
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CVE-2026-1220 affects Chromium-based desktop web browsers, which are outside Flatcar's relevant server-package scope, and no production SBOM evidence shows that any affected browser is shipped.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 136: glibc (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969087
  • CVEs / upstream IDs: CVE-2025-15281
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: sys-libs/glibc 2.43-r2 (exact_name)
  • Existing issue matches: update: glibc #154 (open): update: glibc

The production SBOM confirms glibc is shipped, and open issue #154 already tracks glibc. CVE-2025-15281 is not listed there and the Gentoo/sourceware references and affected-version context should be added; the shipped 2.43-r2 version is outside the reported affected range through 2.42.

Proposed additive update for action disc-7c296d4191b34fd2eca8 (issue #154)
  • Add CVEs: CVE-2025-15281
  • Add refmap.gentoo: https://bugs.gentoo.org/969087
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): glibc wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized pointers in we_wordv, potentially causing invalid-pointer dereference or process abort.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2025-15281
- Add Gentoo aliases/CVEs: CVE-2025-15281
- Add upstream context: glibc wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized pointers in we_wordv, potentially causing invalid-pointer dereference or process abort.
- Review Gentoo severity: normal
- Review upstream references: https://sourceware.org/bugzilla/show_bug.cgi?id=33814
- Review Bugzilla description: Low impact again.

"""
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

The implementation o...
- Review Bugzilla comment #1 by bacs at 2026-08-16T12:17:57Z: glsa^ with 968862

New Bugzilla comments in the processing window:
- Review Bugzilla comment #1 by bacs at 2026-08-16T12:17:57Z: glsa^ with 968862

Source: https://bugs.gentoo.org/969087

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 137: net-dns/bind (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969156
  • CVEs / upstream IDs: CVE-2025-13878
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: net-dns/bind 9.20.23 (exact_name)
  • Existing issue matches: update: net-dns/bind #61 (open): update: net-dns/bind

The open net-dns/bind issue is an exact package match but does not list CVE-2025-13878. Add the CVE, Gentoo/ISC references, affected and fixed version context, noting that the production SBOM version 9.20.23 is newer than the 9.20.18 fix.

Proposed additive update for action disc-18f16cfad6f582501ec2 (issue #61)
  • Add CVEs: CVE-2025-13878
  • Add refmap.gentoo: https://bugs.gentoo.org/969156
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): Malformed BRID/HHIT records can cause named to terminate unexpectedly; fixed in BIND 9.18.44, 9.20.18, and 9.21.17.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2025-13878
- Add Gentoo aliases/CVEs: CVE-2025-13878
- Add upstream context: Malformed BRID/HHIT records can cause named to terminate unexpectedly; fixed in BIND 9.18.44, 9.20.18, and 9.21.17.
- Review Gentoo severity: minor (source: https://kb.isc.org/docs/cve-2025-13878)
- Review upstream references: https://kb.isc.org/docs/cve-2025-13878
- Review Bugzilla description: CVE-2025-13878: Malformed BRID/HHIT records can cause named to terminate unexpectedly 

Affected:
9.18.40 -> 9.18.43
9.20.13 -> 9.20.17
9.21.12 -> 9.21.16

Fixed in:
9.18.44
9.20.18
9.21.17

Reproducible: Always

Source: https://bugs.gentoo.org/969156

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 138: media-gfx/gimp (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969286
  • CVEs / upstream IDs: CVE-2025-10920, CVE-2025-10922, CVE-2025-10923, CVE-2025-10924
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

GIMP is a desktop graphics application, has no Flatcar SBOM match, and Gentoo states it is not in @system or dependencies.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 139: gimp (discovery, source: gentoo)

GIMP is a desktop graphics application, has no production SBOM match, and Gentoo explicitly states media-gfx/gimp is not in @system or its dependencies.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 140: www-client/chromium (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969398
  • CVEs / upstream IDs: CVE-2026-1504
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CVE-2026-1504 affects Chromium-based desktop browser packages, which are outside Flatcar's server-focused package scope, and no production SBOM evidence shows that Flatcar ships them.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 141: tor (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969415
  • CVEs / upstream IDs: TROVE-2025-016, TOR BUG 41180
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Tor is not evidenced as shipped or used by Flatcar; there are no production SBOM matches, and the source explicitly states net-vpn/tor is not in Gentoo @system or dependencies.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 142: curl (discovery, source: gentoo)

curl is confirmed in the production SBOM at 8.21.0, which is newer than the 8.18.0 fixed version; no existing Flatcar issue match is present.

Exact proposed issue for action disc-be0167379b21b15eea84

Title: update: curl

Name: curl
CVEs: CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224
CVSSs: n/a
Action Needed: update target 8.18.0
Summary: Multiple curl vulnerabilities involving libssh authentication and known_hosts handling, OpenSSL chain policy, credential leakage on redirects, threaded LDAPS TLS options, and GnuTLS QUIC certificate pinning.

refmap.gentoo: https://bugs.gentoo.org/969430

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: curl

Group 143: nginx (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969626
  • CVEs / upstream IDs: CVE-2026-1642
  • CVSS: 5.9, 8.2
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-4f5fd2cd4c7ed1250475

Title: update: nginx

Name: nginx
CVEs: CVE-2026-1642
CVSSs: 5.9, 8.2
Action Needed: update target
Summary: NGINX configured to proxy to upstream TLS servers may allow an upstream-side MITM attacker to inject plaintext data into proxied responses sent to clients.

refmap.gentoo: https://bugs.gentoo.org/969626

Labels: advisory, security, cvss/HIGH

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: nginx
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 144: net-misc/freerdp (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/969847
  • CVEs / upstream IDs: CVE-2026-23948, CVE-2026-24491, CVE-2026-24675, CVE-2026-24676, CVE-2026-24677, CVE-2026-24678, CVE-2026-24679, CVE-2026-24680, CVE-2026-24681, CVE-2026-24682, CVE-2026-24683, CVE-2026-24684
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

FreeRDP has no production SBOM match or other evidence of being shipped or used by Flatcar; the Gentoo advisory alone does not establish Flatcar relevance.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 145: yt-dlp (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970421
  • CVEs / upstream IDs: CVE-2026-26331
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: acct-group/lp 0-r3 (unique_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 146: net-p2p/freenet (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970477
  • CVEs / upstream IDs: 970477
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 147: cups-filters (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970481
  • CVEs / upstream IDs: CVE-2025-64524
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CVE-2025-64524 affects the desktop/printing component cups-filters, and there is no evidence that it is shipped or used by Flatcar.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 148: net-print/cups (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970482
  • CVEs / upstream IDs: CVE-2025-58436, CVE-2025-61915
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CUPS is a printing-service package and no production SBOM or other evidence shows Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 149: www-client/firefox (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970560
  • CVEs / upstream IDs: TBD
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Firefox is a desktop web browser and no production SBOM or other Flatcar evidence shows that Flatcar ships or uses www-client/firefox.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 150: mail-client/thunderbird (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970561
  • CVEs / upstream IDs: TBD
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Thunderbird is a desktop mail client, and the bundle provides no evidence that it is shipped or used by Flatcar in any supported scope.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 151: wireshark (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970622
  • CVEs / upstream IDs: CVE-2026-3201, CVE-2026-3202, CVE-2026-3203
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Wireshark is not evidenced in the Flatcar production SBOM or otherwise shown to be shipped or used by Flatcar; it is a network-analysis application outside the limited production package set.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 152: dev-python/django (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970871
  • CVEs / upstream IDs: CVE-2026-25674
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go v0.121.6 (ambiguous_substring); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (ambiguous_substring); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.7 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 153: libxml2 (discovery, source: gentoo)

The production SBOM confirms libxml2 is shipped, but at 2.15.3, which is newer than the affected range (<2.15.2) and includes the 2.15.2 fixes. No evidence shows an affected Flatcar version requiring an advisory.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 154: dev-lang/go (discovery, source: gentoo)

  • Source URL: https://bugs.gentoo.org/970944
  • CVEs / upstream IDs: CVE-2026-25679, CVE-2026-27139, CVE-2026-27142
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: cloud.google.com/go v0.121.6 (exact_name); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (exact_name); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.11 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.12 (exact_name); github.com/json-iterator/go v1.1.7 (exact_name)
  • Existing issue matches: update: dev-lang/go #64 (open): update: dev-lang/go

LLM relevance decision requested manual review.; Issue mutation recommendation requires a relevant Flatcar status.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.; Issue mutation recommendation requires a relevant Flatcar status.
Exact proposed issue for action disc-d7c9edc64ca70ee46d85

Title: update: dev-lang/go

Name: dev-lang/go
CVEs: CVE-2026-25679, CVE-2026-27139, CVE-2026-27142
CVSSs: n/a
Action Needed: update target
Summary: Go fixes URL parsing validation, html/template meta-refresh URL escaping, and FileInfo metadata escapes from Root; fixed in Go 1.25.8.

refmap.gentoo: https://bugs.gentoo.org/970944

Labels: advisory, security

Proposed additive update for action disc-2666dbea89a4c1d9ce25 (issue #64)

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: dev-lang/go
  • Update existing issue update: dev-lang/go #64 with new upstream context
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions