You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The production SBOM contains dev-libs/expat 2.8.2, which is older than the 2.8.4 release fixing the four newly reported CVEs. Open issue #234 already tracks the same package but not these CVEs, so it should be updated rather than duplicated.
Proposed additive update for action disc-091946acb3bbd08e3009 (issue #234)
Action Needed (only applied if currently TBD): update target
Summary (only applied if currently TBD): Expat 2.8.4 fixes four denial-of-service vulnerabilities: quadratic runtime from attribute isCdata lookups, parser re-entry through custom encoding callbacks, and hash flooding caused by inverted getentropy() handling.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
- Add upstream context: Expat 2.8.4 fixes four denial-of-service vulnerabilities: quadratic runtime from attribute isCdata lookups, parser re-entry through custom encoding callbacks, and hash flooding caused by inverted getentropy() handling.
- Review upstream references: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957, CVE-2026-45186
- Review Bugzilla description: Hello oss-security,
just a quick note that libexpat 2.8.4 (or "Expat 2.8.4") released today
is fixing four vulnerabilities:
- CVE-2026-66046
- CVE-2026-76641
- CVE-2026-76956
- CVE-2026-76957
The related part of the change log is this:
#1321 #1331 CVE-2026-66046, CVE-2026-76641 -- Fix qu...
Source: https://www.openwall.com/lists/oss-security/2026/08/31/13
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
CVE-2026-19953 affects the CPAN/Perl URI distribution, but the evidence contains no indication that Flatcar ships or uses it, and there are no production SBOM matches or existing issues.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 66: freerdp (discovery, source: oss_security)
FreeRDP has no production SBOM match or other evidence of shipment/use in Flatcar, and the reported vulnerabilities affect only its server role; the cited affected deployments are desktop remote-desktop components outside Flatcar's scope.
Choose at most one (leave all unchecked to take no action for this group):
NLTK is an application-level Python NLP library, and the bundle provides no evidence that Flatcar ships or uses it; no production SBOM match or existing issue is present.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 68: Apache Spark (discovery, source: oss_security)
Flatcar production SBOM contains net-misc/curl 8.21.0, and the upstream curl 8.22.0 announcement reports ten curl/libcurl security CVEs with 8.22.0 as the fixed release. No existing matching issue is present.
Exact proposed issue for action disc-4fc93d5fbd387026168c
Title: update: curl
Name: curl
CVEs: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209, CVE-2026-80256
CVSSs: n/a
Action Needed: TBD
Summary: The curl 8.22.0 announcement reports ten separate security vulnerabilities affecting curl/libcurl and wcurl, including authentication bypasses, use-after-free issues, connection reuse flaws, certificate-validation bypasses, cookie handling bypasses, and a wcurl backslash bypass. The source does not provide affected version ranges or CVSS scores.
refmap.gentoo: TBD
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: curl
Group 71: jenkins and listed Jenkins plugins (discovery, source: oss_security)
The production SBOM contains affected golang.org/x/crypto versions below v0.56.0, and open issue #236 already tracks the same package but lacks CVE-2026-56855 and CVE-2026-78662.
Proposed additive update for action disc-a0f8f13e6bd3fdbde47b (issue #236)
Add CVEs: CVE-2026-56855, CVE-2026-78662, GO ISSUE 81317, GO ISSUE 81316
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): golang.org/x/crypto v0.56.0 fixes two SSH denial-of-service vulnerabilities: crafted messages could deadlock established connections or flood undecided channels and deadlock the connection.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-56855, CVE-2026-78662, GO ISSUE 81317, GO ISSUE 81316
- Add upstream context: golang.org/x/crypto v0.56.0 fixes two SSH denial-of-service vulnerabilities: crafted messages could deadlock established connections or flood undecided channels and deadlock the connection.
- Review upstream references: CVE-2026-56855, CVE-2026-78662
- Review Bugzilla description: -------- Forwarded Message --------
Subject: [security] Vulnerabilities in golang.org/x/crypto
Date: Wed, 2 Sep 2026 11:46:32 -0700 (PDT)
From: Neal Patel <neal@...ang.org>
To: golang-announce <golang-announce@...glegroups.com>
Howdy gophers,
We have tagged version v0.56.0 of golang.org/x/c...
Source: https://www.openwall.com/lists/oss-security/2026/09/02/5
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Exact proposed issue for action disc-312db4ab942c64f333c9
Title: update: github.com/kyverno/kyverno
Name: github.com/kyverno/kyverno
CVEs: CVE-2026-54523, GHSA-79GF-7FRW-68M9, GO-2026-6296
CVSSs: n/a
Action Needed: TBD
Summary: Kyverno's NamespacedGeneratingPolicy generator failed to validate its namespace argument, allowing the background controller to create RoleBindings in arbitrary namespaces, including kube-system. Versions 1.18.0 through before 1.18.2 are affected; fixed in 1.18.2.
refmap.gentoo: TBD
Labels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Create new advisory issue: update: github.com/kyverno/kyverno
No advisory action (ignore/defer)
Manual handling outside the pipeline
Group 74: github.com/andreimarcu/linx-server (discovery, source: go_vulndb)
Cloudreve is an application-level Go package, and the evidence contains no indication that Flatcar ships or uses it; no SBOM package matches were found.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 76: github.com/statping-ng/statping-ng (discovery, source: go_vulndb)
The advisory affects the statping-ng Go application, and the evidence contains no indication that Flatcar ships or uses it; no production SBOM match or existing issue is present.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 77: github.com/mickael-kerjean/filestash (discovery, source: go_vulndb)
Filestash is an application-level Go package with no evidence that it is shipped or used by Flatcar, and it has no production SBOM matches or existing Flatcar issue.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 78: github.com/akuity/kargo (discovery, source: go_vulndb)
The production SBOM contains affected golang.org/x/crypto versions below 0.55.0, and open issue #236 already tracks the same package but not CVE-2026-56854/GO-2026-6303 or this distinct SSH source-address enforcement flaw.
Proposed additive update for action disc-25dfff61ecaf8cccab7b (issue #236)
Action Needed (only applied if currently TBD): TBD
Summary (only applied if currently TBD): The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.
Comment to post:
Gentoo Bugzilla has new or changed upstream context for this advisory.
Recommended review items:
- Add CVEs: CVE-2026-56854, GO-2026-6303
- Add upstream context: The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.
- Review upstream references: CVE-2026-56854, https://go.dev/issue/80213, https://go.dev/cl/797040
- Review Bugzilla description: The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAu...
Source: https://pkg.go.dev/vuln/GO-2026-6303
This is a guarded automation recommendation; maintainers should review before editing the advisory body.
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
The advisory affects the Vikunja application module code.vikunja.io/api, which has no evidence of being shipped or used by Flatcar; all SBOM candidates are unrelated modules that merely contain an api path component.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 82: code.vikunja.io/api (discovery, source: go_vulndb)
The advisory affects Vikunja's Go module code.vikunja.io/api, and there is no evidence that Flatcar ships or uses Vikunja. SBOM candidates matching generic “api” names are unrelated modules.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 83: code.vikunja.io/api (discovery, source: go_vulndb)
Vikunja's code.vikunja.io/api module is not evidenced as shipped or used by Flatcar; the SBOM candidates are unrelated Go API modules or generic local paths.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
Group 84: github.com/hatchet-dev/hatchet (discovery, source: go_vulndb)
The advisory affects the Vikunja Go module code.vikunja.io/api, which is not present in the provided Flatcar SBOM evidence; all listed candidates are different Go modules or generic local paths.
Choose at most one (leave all unchecked to take no action for this group):
Acknowledge: no advisory action needed
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.
Automated Flatcar security-triage review batch
33722816193, part 4 of 6.Run metadata
flatcar/security-triageflatcar/security-triageedcedfc577028c2f2c86117a50bde13afa38024fSummary
This part contains 23 decision group(s).
Whole batch: 145 decision group(s) across 6 part(s).
How to use this review
Decision groups
Group 64: expat (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/08/31/13Proposed additive update for action
disc-091946acb3bbd08e3009(issue #234)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 65: URI (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/08/31/14Choose at most one (leave all unchecked to take no action for this group):
Group 66: freerdp (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/01/2Choose at most one (leave all unchecked to take no action for this group):
Group 67: nltk (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/01/3Choose at most one (leave all unchecked to take no action for this group):
Group 68: Apache Spark (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/01/4Choose at most one (leave all unchecked to take no action for this group):
Group 69: Net-DNS (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/02/1Choose at most one (leave all unchecked to take no action for this group):
Group 70: curl (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/02/2Exact proposed issue for action
disc-4fc93d5fbd387026168cTitle:
update: curlLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 71: jenkins and listed Jenkins plugins (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/02/4Choose at most one (leave all unchecked to take no action for this group):
Group 72: golang.org/x/crypto (discovery, source: oss_security)
https://www.openwall.com/lists/oss-security/2026/09/02/5Proposed additive update for action
disc-a0f8f13e6bd3fdbde47b(issue #236)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 73: github.com/kyverno/kyverno (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6296Exact proposed issue for action
disc-312db4ab942c64f333c9Title:
update: github.com/kyverno/kyvernoLabels: advisory, security
Choose at most one (leave all unchecked to take no action for this group):
Group 74: github.com/andreimarcu/linx-server (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6297Choose at most one (leave all unchecked to take no action for this group):
Group 75: github.com/cloudreve/Cloudreve (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6298Choose at most one (leave all unchecked to take no action for this group):
Group 76: github.com/statping-ng/statping-ng (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6299Choose at most one (leave all unchecked to take no action for this group):
Group 77: github.com/mickael-kerjean/filestash (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6300Choose at most one (leave all unchecked to take no action for this group):
Group 78: github.com/akuity/kargo (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6301Choose at most one (leave all unchecked to take no action for this group):
Group 79: golang.org/x/crypto (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6303Proposed additive update for action
disc-25dfff61ecaf8cccab7b(issue #236)Comment to post:
This update is re-applied against the issue's current body at apply time and never removes existing content.
Choose at most one (leave all unchecked to take no action for this group):
Group 80: github.com/pocket-id/pocket-id/backend (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6305Choose at most one (leave all unchecked to take no action for this group):
Group 81: code.vikunja.io/api (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6306Choose at most one (leave all unchecked to take no action for this group):
Group 82: code.vikunja.io/api (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6307Choose at most one (leave all unchecked to take no action for this group):
Group 83: code.vikunja.io/api (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6308Choose at most one (leave all unchecked to take no action for this group):
Group 84: github.com/hatchet-dev/hatchet (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6309Choose at most one (leave all unchecked to take no action for this group):
Group 85: github.com/klever-io/klever-go (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6310Choose at most one (leave all unchecked to take no action for this group):
Group 86: code.vikunja.io/api (discovery, source: go_vulndb)
https://pkg.go.dev/vuln/GO-2026-6311Choose at most one (leave all unchecked to take no action for this group):
This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.