Skip to content

Security triage review: 2026-09-03 (part 4/6) #367

Description

@github-actions

Automated Flatcar security-triage review batch 33722816193, part 4 of 6.

Run metadata

Summary

This part contains 23 decision group(s).

Recommendation Count
discovery_create_issue 2
discovery_ignore 18
discovery_update_issue 3
Confidence Count
high 16
low 1
medium 6
Severity Count
CRITICAL 1
HIGH 2
n/a 20

Whole batch: 145 decision group(s) across 6 part(s).

Recommendation Count
discovery_create_issue 16
discovery_ignore 116
discovery_update_issue 13
Confidence Count
high 86
low 11
medium 48
Severity Count
CRITICAL 3
HIGH 11
MEDIUM 14
n/a 117

How to use this review

  • Check exactly one box per group to approve that action; leave a group fully unchecked to take no action for it.
  • Checking more than one box in the same group cancels that group: it is skipped and reported as a conflict.
  • Close this issue with reason Completed to apply every checked, conflict-free action.
  • Close this issue as Not planned (or leave it open) to take no automated action at all.
  • Do not edit the hidden HTML comments below the decision groups; they carry the machine-readable manifest this automation depends on.

Decision groups

Group 64: expat (discovery, source: oss_security)

The production SBOM contains dev-libs/expat 2.8.2, which is older than the 2.8.4 release fixing the four newly reported CVEs. Open issue #234 already tracks the same package but not these CVEs, so it should be updated rather than duplicated.

Proposed additive update for action disc-091946acb3bbd08e3009 (issue #234)
  • Add CVEs: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
  • Add CVSSs: 7.5, 5.9
  • Action Needed (only applied if currently TBD): update target
  • Summary (only applied if currently TBD): Expat 2.8.4 fixes four denial-of-service vulnerabilities: quadratic runtime from attribute isCdata lookups, parser re-entry through custom encoding callbacks, and hash flooding caused by inverted getentropy() handling.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957
- Add upstream context: Expat 2.8.4 fixes four denial-of-service vulnerabilities: quadratic runtime from attribute isCdata lookups, parser re-entry through custom encoding callbacks, and hash flooding caused by inverted getentropy() handling.
- Review upstream references: CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957, CVE-2026-45186
- Review Bugzilla description: Hello oss-security,


just a quick note that libexpat 2.8.4 (or "Expat 2.8.4") released today
is fixing four vulnerabilities:

- CVE-2026-66046
- CVE-2026-76641
- CVE-2026-76956
- CVE-2026-76957

The related part of the change log is this:

   #1321 #1331  CVE-2026-66046, CVE-2026-76641 -- Fix qu...

Source: https://www.openwall.com/lists/oss-security/2026/08/31/13

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 65: URI (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/08/31/14
  • CVEs / upstream IDs: CVE-2026-19953
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

CVE-2026-19953 affects the CPAN/Perl URI distribution, but the evidence contains no indication that Flatcar ships or uses it, and there are no production SBOM matches or existing issues.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 66: freerdp (discovery, source: oss_security)

FreeRDP has no production SBOM match or other evidence of shipment/use in Flatcar, and the reported vulnerabilities affect only its server role; the cited affected deployments are desktop remote-desktop components outside Flatcar's scope.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 67: nltk (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/09/01/3
  • CVEs / upstream IDs: CVE-2026-80205
  • CVSS: 8.7, 7.5
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

NLTK is an application-level Python NLP library, and the bundle provides no evidence that Flatcar ships or uses it; no production SBOM match or existing issue is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 68: Apache Spark (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/09/01/4
  • CVEs / upstream IDs: CVE-2026-32773, SPARK-53747
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Apache Spark is not evidenced as shipped or used by Flatcar, and no production SBOM package matches exist.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 69: Net-DNS (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/09/02/1
  • CVEs / upstream IDs: CVE-2026-81928
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: github.com/miekg/dns v1.1.66 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.33.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.34.0 (ambiguous_substring); golang.org/x/net v0.38.0 (ambiguous_substring); golang.org/x/net v0.43.0 (ambiguous_substring); golang.org/x/net v0.46.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.47.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring); golang.org/x/net v0.55.0 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 70: curl (discovery, source: oss_security)

Flatcar production SBOM contains net-misc/curl 8.21.0, and the upstream curl 8.22.0 announcement reports ten curl/libcurl security CVEs with 8.22.0 as the fixed release. No existing matching issue is present.

Exact proposed issue for action disc-4fc93d5fbd387026168c

Title: update: curl

Name: curl
CVEs: CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209, CVE-2026-80256
CVSSs: n/a
Action Needed: TBD
Summary: The curl 8.22.0 announcement reports ten separate security vulnerabilities affecting curl/libcurl and wcurl, including authentication bypasses, use-after-free issues, connection reuse flaws, certificate-validation bypasses, cookie handling bypasses, and a wcurl backslash bypass. The source does not provide affected version ranges or CVSS scores.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: curl

Group 71: jenkins and listed Jenkins plugins (discovery, source: oss_security)

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 72: golang.org/x/crypto (discovery, source: oss_security)

  • Source URL: https://www.openwall.com/lists/oss-security/2026/09/02/5
  • CVEs / upstream IDs: CVE-2026-56855, CVE-2026-78662, GO ISSUE 81317, GO ISSUE 81316
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: golang.org/x/crypto v0.31.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.43.0 (exact_name); golang.org/x/crypto v0.45.0 (exact_name); golang.org/x/crypto v0.53.0 (exact_name)
  • Existing issue matches: update: golang.org/x/crypto #236 (open): update: golang.org/x/crypto

The production SBOM contains affected golang.org/x/crypto versions below v0.56.0, and open issue #236 already tracks the same package but lacks CVE-2026-56855 and CVE-2026-78662.

Proposed additive update for action disc-a0f8f13e6bd3fdbde47b (issue #236)
  • Add CVEs: CVE-2026-56855, CVE-2026-78662, GO ISSUE 81317, GO ISSUE 81316
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): golang.org/x/crypto v0.56.0 fixes two SSH denial-of-service vulnerabilities: crafted messages could deadlock established connections or flood undecided channels and deadlock the connection.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-56855, CVE-2026-78662, GO ISSUE 81317, GO ISSUE 81316
- Add upstream context: golang.org/x/crypto v0.56.0 fixes two SSH denial-of-service vulnerabilities: crafted messages could deadlock established connections or flood undecided channels and deadlock the connection.
- Review upstream references: CVE-2026-56855, CVE-2026-78662
- Review Bugzilla description: -------- Forwarded Message --------
Subject: 	[security] Vulnerabilities in golang.org/x/crypto
Date: 	Wed, 2 Sep 2026 11:46:32 -0700 (PDT)
From: 	Neal Patel <neal@...ang.org>
To: 	golang-announce <golang-announce@...glegroups.com>

Howdy gophers,

We have tagged version v0.56.0 of golang.org/x/c...

Source: https://www.openwall.com/lists/oss-security/2026/09/02/5

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 73: github.com/kyverno/kyverno (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6296
  • CVEs / upstream IDs: CVE-2026-54523, GHSA-79gf-7frw-68m9, GO-2026-6296
  • CVSS: n/a
  • Flatcar relevance: needs_manual_review (scope: unknown)
  • Recommendation: needs_manual_review (confidence: low)
  • SBOM matches: none
  • Existing issue matches: none

LLM relevance decision requested manual review.

  • Safety/ambiguity notes: LLM relevance decision requested manual review.
Exact proposed issue for action disc-312db4ab942c64f333c9

Title: update: github.com/kyverno/kyverno

Name: github.com/kyverno/kyverno
CVEs: CVE-2026-54523, GHSA-79GF-7FRW-68M9, GO-2026-6296
CVSSs: n/a
Action Needed: TBD
Summary: Kyverno's NamespacedGeneratingPolicy generator failed to validate its namespace argument, allowing the background controller to create RoleBindings in arbitrary namespaces, including kube-system. Versions 1.18.0 through before 1.18.2 are affected; fixed in 1.18.2.

refmap.gentoo: TBD

Labels: advisory, security

Choose at most one (leave all unchecked to take no action for this group):

  • Create new advisory issue: update: github.com/kyverno/kyverno
  • No advisory action (ignore/defer)
  • Manual handling outside the pipeline

Group 74: github.com/andreimarcu/linx-server (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6297
  • CVEs / upstream IDs: CVE-2026-50879, GO-2026-6297, GHSA-g743-m6x3-v6wm
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: ../server (devel) (ambiguous_substring); ../server (devel) (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 75: github.com/cloudreve/Cloudreve (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6298
  • CVEs / upstream IDs: CVE-2026-54563, GHSA-w5fv-7x5q-g8qp, GO-2026-6298
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Cloudreve is an application-level Go package, and the evidence contains no indication that Flatcar ships or uses it; no SBOM package matches were found.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 76: github.com/statping-ng/statping-ng (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6299
  • CVEs / upstream IDs: CVE-2026-50884, GHSA-5442-mh7f-72px, GO-2026-6299
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

The advisory affects the statping-ng Go application, and the evidence contains no indication that Flatcar ships or uses it; no production SBOM match or existing issue is present.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 77: github.com/mickael-kerjean/filestash (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6300
  • CVEs / upstream IDs: CVE-2026-50891, GHSA-rcqf-cpv9-g5jf, GO-2026-6300
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Filestash is an application-level Go package with no evidence that it is shipped or used by Flatcar, and it has no production SBOM matches or existing Flatcar issue.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 78: github.com/akuity/kargo (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6301
  • CVEs / upstream IDs: CVE-2026-42350, GHSA-g7gw-m874-7rmf, GO-2026-6301
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go v0.121.6 (ambiguous_substring); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (ambiguous_substring); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.7 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 79: golang.org/x/crypto (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6303
  • CVEs / upstream IDs: CVE-2026-56854, GO-2026-6303
  • CVSS: n/a
  • Flatcar relevance: relevant (scope: production)
  • Recommendation: update_existing_issue (confidence: high)
  • SBOM matches: golang.org/x/crypto v0.31.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.32.0 (exact_name); golang.org/x/crypto v0.43.0 (exact_name); golang.org/x/crypto v0.45.0 (exact_name); golang.org/x/crypto v0.53.0 (exact_name)
  • Existing issue matches: update: golang.org/x/crypto #236 (open): update: golang.org/x/crypto

The production SBOM contains affected golang.org/x/crypto versions below 0.55.0, and open issue #236 already tracks the same package but not CVE-2026-56854/GO-2026-6303 or this distinct SSH source-address enforcement flaw.

Proposed additive update for action disc-25dfff61ecaf8cccab7b (issue #236)
  • Add CVEs: CVE-2026-56854, GO-2026-6303
  • Action Needed (only applied if currently TBD): TBD
  • Summary (only applied if currently TBD): The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.

Comment to post:

Gentoo Bugzilla has new or changed upstream context for this advisory.

Recommended review items:
- Add CVEs: CVE-2026-56854, GO-2026-6303
- Add upstream context: The SSH source-address critical option was not enforced for permissions returned by non-public-key authentication callbacks, allowing configured source-address restrictions to be ignored; fixed in x/crypto 0.55.0.
- Review upstream references: CVE-2026-56854, https://go.dev/issue/80213, https://go.dev/cl/797040
- Review Bugzilla description: The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAu...

Source: https://pkg.go.dev/vuln/GO-2026-6303

This is a guarded automation recommendation; maintainers should review before editing the advisory body.

This update is re-applied against the issue's current body at apply time and never removes existing content.

Choose at most one (leave all unchecked to take no action for this group):

Group 80: github.com/pocket-id/pocket-id/backend (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6305
  • CVEs / upstream IDs: CVE-2026-55834, GHSA-2wvm-8mvp-22qv, GO-2026-6305
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Pocket-ID Go backend is not evidenced as shipped or used by Flatcar, and no production SBOM package matches exist.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 81: code.vikunja.io/api (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6306
  • CVEs / upstream IDs: CVE-2026-55064, CVE-2026-35595, GHSA-44v6-7fxq-vgf4, GO-2026-6306
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: ../api (devel) (exact_name); ../api (devel) (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.8.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); go.etcd.io/etcd/api/v3 v3.6.5 (exact_purl); google.golang.org/api v0.248.0 (exact_name); google.golang.org/api v0.252.0 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20241021214115-324edc3d5d38 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250218202821-56aae31c358a (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20251029180050-ab9386a59fda (exact_name); k8s.io/api v0.31.2 (exact_name); k8s.io/api v0.33.0-rc.0 (exact_name); k8s.io/api v0.34.1 (exact_name)
  • Existing issue matches: none

The advisory affects the Vikunja application module code.vikunja.io/api, which has no evidence of being shipped or used by Flatcar; all SBOM candidates are unrelated modules that merely contain an api path component.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 82: code.vikunja.io/api (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6307
  • CVEs / upstream IDs: CVE-2026-55067, GHSA-569v-q83c-3j3g, GO-2026-6307
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: ../api (devel) (exact_name); ../api (devel) (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.8.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); go.etcd.io/etcd/api/v3 v3.6.5 (exact_purl); google.golang.org/api v0.248.0 (exact_name); google.golang.org/api v0.252.0 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20241021214115-324edc3d5d38 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250218202821-56aae31c358a (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20251029180050-ab9386a59fda (exact_name); k8s.io/api v0.31.2 (exact_name); k8s.io/api v0.33.0-rc.0 (exact_name); k8s.io/api v0.34.1 (exact_name)
  • Existing issue matches: none

The advisory affects Vikunja's Go module code.vikunja.io/api, and there is no evidence that Flatcar ships or uses Vikunja. SBOM candidates matching generic “api” names are unrelated modules.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 83: code.vikunja.io/api (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6308
  • CVEs / upstream IDs: CVE-2026-55066, GHSA-5pg6-m483-7vrg, GO-2026-6308
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: ../api (devel) (exact_name); ../api (devel) (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.8.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); go.etcd.io/etcd/api/v3 v3.6.5 (exact_purl); google.golang.org/api v0.248.0 (exact_name); google.golang.org/api v0.252.0 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20241021214115-324edc3d5d38 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250218202821-56aae31c358a (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20251029180050-ab9386a59fda (exact_name); k8s.io/api v0.31.2 (exact_name); k8s.io/api v0.33.0-rc.0 (exact_name); k8s.io/api v0.34.1 (exact_name)
  • Existing issue matches: none

Vikunja's code.vikunja.io/api module is not evidenced as shipped or used by Flatcar; the SBOM candidates are unrelated Go API modules or generic local paths.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 84: github.com/hatchet-dev/hatchet (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6309
  • CVEs / upstream IDs: CVE-2026-54746, GHSA-8x7x-83cf-c3pg, GO-2026-6309
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: none
  • Existing issue matches: none

Hatchet is an application-level Go package, and the bundle provides no evidence that Flatcar ships or uses it; no production SBOM match exists.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 85: github.com/klever-io/klever-go (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6310
  • CVEs / upstream IDs: CVE-2026-54755, GHSA-cgc5-v3f2-8m2v, GO-2026-6310
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: medium)
  • SBOM matches: cloud.google.com/go v0.121.6 (ambiguous_substring); github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 (ambiguous_substring); github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.11 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.12 (ambiguous_substring); github.com/json-iterator/go v1.1.7 (ambiguous_substring)
  • Existing issue matches: none

LLM judged the only SBOM matches unrelated; treat this as strong not-shipped evidence.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

Group 86: code.vikunja.io/api (discovery, source: go_vulndb)

  • Source URL: https://pkg.go.dev/vuln/GO-2026-6311
  • CVEs / upstream IDs: CVE-2026-54766, GHSA-f27p-pw2p-9pr4
  • CVSS: n/a
  • Flatcar relevance: not_relevant (scope: not_shipped)
  • Recommendation: ignore (confidence: high)
  • SBOM matches: ../api (devel) (exact_name); ../api (devel) (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.10.0 (exact_name); github.com/containerd/containerd/api v1.8.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); github.com/moby/moby/api v1.52.0 (exact_name); go.etcd.io/etcd/api/v3 v3.6.5 (exact_purl); google.golang.org/api v0.248.0 (exact_name); google.golang.org/api v0.252.0 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20241021214115-324edc3d5d38 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250218202821-56aae31c358a (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 (exact_name); google.golang.org/genproto/googleapis/api v0.0.0-20251029180050-ab9386a59fda (exact_name); k8s.io/api v0.31.2 (exact_name); k8s.io/api v0.33.0-rc.0 (exact_name); k8s.io/api v0.34.1 (exact_name)
  • Existing issue matches: none

The advisory affects the Vikunja Go module code.vikunja.io/api, which is not present in the provided Flatcar SBOM evidence; all listed candidates are different Go modules or generic local paths.

Choose at most one (leave all unchecked to take no action for this group):

  • Acknowledge: no advisory action needed

This section is machine-readable metadata used by the apply automation. It is safe to ignore while reviewing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-triage/reviewSecurity-triage generated review issue (approval required)security-triage/review-appliedSecurity-triage review actions have been applied

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions