Skip to content

Security triage review: 2026-08-31 (part 6/6) #361

Description

@github-actions

Automated Flatcar security-triage review batch 33364211207, part 6 of 6.

Run metadata

Summary

This part contains 26 decision group(s).

Recommendation Count
discovery_create_issue 1
discovery_ignore 24
discovery_update_issue 1
Confidence Count
high 21
low 1
medium 4
Severity Count
MEDIUM 8
n/a 18

Whole batch: 156 decision group(s) across 6 part(s).

Recommendation Count
discovery_create_issue 18
discovery_ignore 128
discovery_kernel_routing 1
discovery_update_issue 9
Confidence Count
high 106
low 14
medium 36
Severity Count
CRITICAL 2
HIGH 10
MEDIUM 10
n/a 134

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 131: github.com/sonirico/mcp-shell (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6290
  • CVEs / upstream IDs: CVE-2026-55581
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows github.com/sonirico/mcp-shell is shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 132: github.com/sonirico/mcp-shell (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6291
  • CVEs / upstream IDs: CVE-2026-55582, GO-2026-6291, GHSA-74hp-mggr-hv58
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence that Flatcar ships or uses the Go application github.com/sonirico/mcp-shell, and it has no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 133: github.com/sonirico/mcp-shell (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6292
  • CVEs / upstream IDs: CVE-2026-55580, GHSA-f5pj-2738-996m, GO-2026-6292
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects an upstream Go module, with no evidence that Flatcar ships or uses github.com/sonirico/mcp-shell; no production SBOM matches or existing issues are present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 134: github.com/labstack/echo (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6293
  • CVEs / upstream IDs: CVE-2026-55677, GO-2026-6293, GHSA-vfp3-v2gw-7wfq
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

This is a Go application-framework vulnerability, and the bundle provides no evidence that Flatcar ships or uses github.com/labstack/echo in its production image, SDK, or sysexts.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 135: github.com/aquasecurity/trivy (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6294
  • CVEs / upstream IDs: CVE-2026-55092, GHSA-mcj4-mphf-j9ff, GO-2026-6294
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM match or other evidence shows that Flatcar ships or uses github.com/aquasecurity/trivy; this Go application vulnerability is therefore not Flatcar-relevant.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 136: github.com/geiserx/genieacs-mcp (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6295
  • CVEs / upstream IDs: CVE-2026-55637, GHSA-cmwv-wf9p-p8wx
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The affected Go application package is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 137: github.com/kyverno/kyverno (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6296
  • CVEs / upstream IDs: CVE-2026-54523, GHSA-79gf-7frw-68m9, GO-2026-6296
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-312db4ab942c64f333c9

Title: update: github.com/kyverno/kyverno

Name: github.com/kyverno/kyverno
CVEs: CVE-2026-54523, GHSA-79GF-7FRW-68M9, GO-2026-6296
CVSSs: n/a
Action Needed: TBD
Summary: Kyverno's NamespacedGeneratingPolicy generator failed to validate its namespace argument, allowing the background controller to create RoleBindings in arbitrary namespaces, including kube-system. Versions 1.18.0 through before 1.18.2 are affected; fixed in 1.18.2.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: github.com/kyverno/kyverno
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 138: github.com/andreimarcu/linx-server (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6297
  • CVEs / upstream IDs: CVE-2026-50879, GO-2026-6297, GHSA-g743-m6x3-v6wm
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: ../server (devel) (ambiguous_substring); ../server (devel) (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 139: github.com/cloudreve/Cloudreve (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6298
  • CVEs / upstream IDs: CVE-2026-54563, GHSA-w5fv-7x5q-g8qp, GO-2026-6298
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Cloudreve is an application-level Go package, and the evidence contains no indication that Flatcar ships or uses it; no SBOM package matches were found.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 140: github.com/statping-ng/statping-ng (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6299
  • CVEs / upstream IDs: CVE-2026-50884, GHSA-5442-mh7f-72px, GO-2026-6299
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects the statping-ng Go application, and the evidence contains no indication that Flatcar ships or uses it; no production SBOM match or existing issue is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 141: github.com/mickael-kerjean/filestash (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6300
  • CVEs / upstream IDs: CVE-2026-50891, GHSA-rcqf-cpv9-g5jf, GO-2026-6300
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Filestash is an application-level Go package with no evidence that it is shipped or used by Flatcar, and it has no production SBOM matches or existing Flatcar issue.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 142: github.com/akuity/kargo (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6301
  • CVEs / upstream IDs: CVE-2026-42350, GHSA-g7gw-m874-7rmf, GO-2026-6301
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go v0.121.6 (ambiguous_substring); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (ambiguous_substring); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.7 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 143: golang.org/x/crypto (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6303
  • CVEs / upstream IDs: CVE-2026-56854, GO-2026-6303
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: golang.org/x/crypto v0.31.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.43.0 (exact_name); golang.org/x/crypto v0.45.0 (exact_name); golang.org/x/crypto v0.53.0 (exact_name)
  • Existing issue matches: update: golang.org/x/crypto #236 (open): update: golang.org/x/crypto

The production SBOM contains affected golang.org/x/crypto versions below 0.55.0, and open issue #236 already tracks the same package but not CVE-2026-56854/GO-2026-6303 or this distinct SSH source-address enforcement flaw.

Proposed additive update for action disc-25dfff61ecaf8cccab7b (issue #236)
  • Add CVEs: CVE-2026-56854, GO-2026-6303
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-56854, GO-2026-6303
- Add upstream context: The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.
- Review upstream references: CVE-2026-56854, https://go.dev/issue/80213, https://go.dev/cl/797040
- Review Bugzilla description: The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAu...

Source: https://pkg.go.dev/vuln/GO-2026-6303

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 144: libcrux-ecdh (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0023.html
  • CVEs / upstream IDs: CVE-2026-76234, GHSA-435g-fcv3-8j26, RUSTSEC-2026-0023
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

libcrux-ecdh is not present in the provided Flatcar SBOM evidence, and no other evidence shows Flatcar ships or uses this Rust crate.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 145: libcrux-ed25519 (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0026.html
  • CVEs / upstream IDs: CVE-2026-76234, GHSA-435g-fcv3-8j26, RUSTSEC-2026-0026
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No production SBOM match or other evidence establishes that Flatcar ships or uses the libcrux-ed25519 Rust crate.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 146: libcrux-psq (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0024.html
  • CVEs / upstream IDs: CVE-2026-76234, GHSA-435g-fcv3-8j26, RUSTSEC-2026-0024
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No existing issue or production SBOM match indicates that the Rust crate libcrux-psq is shipped or used by Flatcar; this application-ecosystem advisory has no demonstrated Flatcar relevance.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 147: libcrux-psq (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0025.html
  • CVEs / upstream IDs: CVE-2026-76234, GHSA-435g-fcv3-8j26
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

libcrux-psq is a Rust crate with no evidence that it is shipped or used by Flatcar, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 148: postgres-protocol (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0179.html
  • CVEs / upstream IDs: RUSTSEC-2026-0179, GHSA-5x78-73v4-xg6w
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

No evidence shows that Flatcar ships or uses the Rust crate postgres-protocol, and there are no production SBOM matches or existing Flatcar issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 149: postgres-protocol (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0180.html
  • CVEs / upstream IDs: GHSA-rgqc-3x5p-6gwg, RUSTSEC-2026-0180
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

postgres-protocol is a Rust application-library advisory with no evidence that Flatcar ships or uses it; no existing issue or production SBOM match is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 150: stable-vec (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-0000-0000.html
  • CVEs / upstream IDs: RUSTSEC-0000-0000, GHSA-mr2v-63pc-gmr4
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects the Rust crate stable-vec, but the bundle contains no production SBOM match or other evidence that Flatcar ships or uses it.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 151: stable-vec (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0267.html
  • CVEs / upstream IDs: GHSA-mr2v-63pc-gmr4
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

stable-vec is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches or existing tracking issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 152: telemetry (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0046.html
  • CVEs / upstream IDs: CVE-2021-29937, GHSA-hpcx-3pw8-g3j2, RUSTSEC-2021-0046
  • CVSS: 3.1
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 (ambiguous_substring); github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53.0 (ambiguous_substring); github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 153: tokio-postgres (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0178.html
  • CVEs / upstream IDs: RUSTSEC-2026-0178, GHSA-3gjw-f78c-vvpw
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

tokio-postgres is not evidenced as shipped or used by Flatcar, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 154: triton-vm (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2021-0156.html
  • CVEs / upstream IDs: RUSTSEC-2021-0156, GHSA-vjf8-9fx6-mv6x
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

triton-vm is a Rust application-library/proof-system package with no evidence that Flatcar ships or uses it, and there are no production SBOM matches.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 155: vibeio-http (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0181.html
  • CVEs / upstream IDs: GHSA-fx4f-mhw4-qm7j
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

vibeio-http is not evidenced as shipped or used by Flatcar, and no production SBOM package match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 156: wasmtime-wasi (discovery, source: rustsec)

  • Source URL: https://rustsec.org/advisories/RUSTSEC-2026-0182.html
  • CVEs / upstream IDs: CVE-2026-54786, GHSA-3p27-qvp9-27qf
  • CVSS: 4.0
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: golang.org/x/time v0.0.0-20210220033141-f8bda1e9f3ba (ambiguous_substring); golang.org/x/time v0.0.0-20210220033141-f8bda1e9f3ba (ambiguous_substring); golang.org/x/time v0.13.0 (ambiguous_substring); golang.org/x/time v0.14.0 (ambiguous_substring); golang.org/x/time v0.14.0 (ambiguous_substring); golang.org/x/time v0.14.0 (ambiguous_substring); golang.org/x/time v0.6.0 (ambiguous_substring); golang.org/x/time v0.9.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)security-triage/review-appliedSecurity-triage review actions have been applied

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions