You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The advisory affects an upstream Go module, with no evidence that Flatcar ships or uses github.com/sonirico/mcp-shell; no production SBOM matches or existing issues are present.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 134: github.com/labstack/echo (discovery, source: go_vulndb)
This is a Go application-framework vulnerability, and the bundle provides no evidence that Flatcar ships or uses github.com/labstack/echo in its production image, SDK, or sysexts.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 135: github.com/aquasecurity/trivy (discovery, source: go_vulndb)
No production SBOM match or other evidence shows that Flatcar ships or uses github.com/aquasecurity/trivy; this Go application vulnerability is therefore not Flatcar-relevant.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 136: github.com/geiserx/genieacs-mcp (discovery, source: go_vulndb)
Exact proposed issue for action disc-312db4ab942c64f333c9
Title: update: github.com/kyverno/kyverno
Name: github.com/kyverno/kyverno
CVEs: CVE-2026-54523, GHSA-79GF-7FRW-68M9, GO-2026-6296
CVSSs: n/a
Action Needed: TBD
Summary: Kyverno's NamespacedGeneratingPolicy generator failed to validate its namespace argument, allowing the background controller to create RoleBindings in arbitrary namespaces, including kube-system. Versions 1.18.0 through before 1.18.2 are affected; fixed in 1.18.2.
refmap.gentoo: TBD
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: github.com/kyverno/kyverno
No advisory action (ignore/defer)
Manual handling outside the pipeline
Group 138: github.com/andreimarcu/linx-server (discovery, source: go_vulndb)
Cloudreve is an application-level Go package, and the evidence contains no indication that Flatcar ships or uses it; no SBOM package matches were found.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 140: github.com/statping-ng/statping-ng (discovery, source: go_vulndb)
The advisory affects the statping-ng Go application, and the evidence contains no indication that Flatcar ships or uses it; no production SBOM match or existing issue is present.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 141: github.com/mickael-kerjean/filestash (discovery, source: go_vulndb)
Filestash is an application-level Go package with no evidence that it is shipped or used by Flatcar, and it has no production SBOM matches or existing Flatcar issue.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 142: github.com/akuity/kargo (discovery, source: go_vulndb)
The production SBOM contains affected golang.org/x/crypto versions below 0.55.0, and open issue #236 already tracks the same package but not CVE-2026-56854/GO-2026-6303 or this distinct SSH source-address enforcement flaw.
Proposed additive update for action disc-25dfff61ecaf8cccab7b (issue #236)
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-56854, GO-2026-6303
- Add upstream context: The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.
- Review upstream references: CVE-2026-56854, https://go.dev/issue/80213, https://go.dev/cl/797040
- Review Bugzilla description: The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAu...
Source: https://pkg.go.dev/vuln/GO-2026-6303
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
No existing issue or production SBOM match indicates that the Rust crate libcrux-psq is shipped or used by Flatcar; this application-ecosystem advisory has no demonstrated Flatcar relevance.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 147: libcrux-psq (discovery, source: rustsec)
postgres-protocol is a Rust application-library advisory with no evidence that Flatcar ships or uses it; no existing issue or production SBOM match is present.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 150: stable-vec (discovery, source: rustsec)
Automated Flatcar security-triage review batch
33364211207, part 6 of 6.Run metadata
flatcar/security-triageflatcar/security-triageedcedfc577028c2f2c86117a50bde13afa38024fSummary
This part contains 26 decision group(s).
Whole batch: 156 decision group(s) across 6 part(s).
How to use this review
Decision groups
Group 131: github.com/sonirico/mcp-shell (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6290Choose at most one (leave all unchecked to take no action for this group):
Group 132: github.com/sonirico/mcp-shell (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6291Choose at most one (leave all unchecked to take no action for this group):
Group 133: github.com/sonirico/mcp-shell (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6292Choose at most one (leave all unchecked to take no action for this group):
Group 134: github.com/labstack/echo (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6293Choose at most one (leave all unchecked to take no action for this group):
Group 135: github.com/aquasecurity/trivy (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6294Choose at most one (leave all unchecked to take no action for this group):
Group 136: github.com/geiserx/genieacs-mcp (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6295Choose at most one (leave all unchecked to take no action for this group):
Group 137: github.com/kyverno/kyverno (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6296Exact proposed issue for action
disc-312db4ab942c64f333c9Title:
update: github.com/kyverno/kyvernoLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 138: github.com/andreimarcu/linx-server (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6297Choose at most one (leave all unchecked to take no action for this group):
Group 139: github.com/cloudreve/Cloudreve (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6298Choose at most one (leave all unchecked to take no action for this group):
Group 140: github.com/statping-ng/statping-ng (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6299Choose at most one (leave all unchecked to take no action for this group):
Group 141: github.com/mickael-kerjean/filestash (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6300Choose at most one (leave all unchecked to take no action for this group):
Group 142: github.com/akuity/kargo (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6301Choose at most one (leave all unchecked to take no action for this group):
Group 143: golang.org/x/crypto (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6303Proposed additive update for action
disc-25dfff61ecaf8cccab7b(issue #236)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 144: libcrux-ecdh (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0023.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 145: libcrux-ed25519 (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0026.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 146: libcrux-psq (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0024.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 147: libcrux-psq (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0025.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 148: postgres-protocol (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0179.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 149: postgres-protocol (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0180.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 150: stable-vec (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-0000-0000.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 151: stable-vec (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0267.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 152: telemetry (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2021-0046.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 153: tokio-postgres (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0178.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 154: triton-vm (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2021-0156.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 155: vibeio-http (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0181.htmlChoose at most one (leave all unchecked to take no action for this group):
Group 156: wasmtime-wasi (discovery, source: rustsec)
https://rustsec.org/advisories/RUSTSEC-2026-0182.htmlChoose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.