Overview
Daily container scan findings for ghcr.io/oraios/serena:1.7.0 (pinned sha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730), a Debian 13 (trixie)-based image bundling Node, Python, and Perl toolchains. This is the only scanned image with Critical findings.
Key metrics
| Severity |
Count |
| Critical |
50 |
| High |
128 |
| Medium |
148 (unique CVE+package pairs, 72 distinct IDs) |
| Low |
35 |
| Negligible |
610 (unique CVE+package pairs) |
| Unknown |
36 |
| License violations |
661 (112 genuine rejected/unrecognized licenses + 549 packages reporting no detectable license metadata) |
Critical (50, grouped by package)
Critical findings by package
| Package |
Version |
CVE/GHSA IDs |
| curl, libcurl3t64-gnutls, libcurl4t64 |
8.14.1-2+deb13u4 |
CVE-2026-8924, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079, CVE-2026-10536, CVE-2026-11856 |
| libc6, libc-bin, libc-dev-bin, libc6-dev |
2.41-12+deb13u3 |
CVE-2026-5450, CVE-2026-8924, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079, CVE-2026-10536, CVE-2026-11856 |
| perl, libperl5.40, perl-base, perl-modules-5.40 |
5.40.1-6 |
CVE-2026-8376, CVE-2026-12087, CVE-2026-13221, CVE-2026-42496, CVE-2026-57433 |
| openssh-client, openssh-server, openssh-sftp-server, ssh |
1:10.0p1-7+deb13u4 |
CVE-2026-60002 |
| node |
22.18.0 |
CVE-2025-55130 |
| tar |
6.2.1, 7.4.3 |
GHSA-23hp-3jrh-7fpw (fix 7.5.19) |
Remediation: Debian 13 security updates for curl/glibc/perl/openssh are the highest-priority fix — a single apt-get upgrade on rebuild resolves the bulk of Critical findings. node and tar need explicit version bumps (node ≥20.20.0/22.22.0/24.13.0/25.3.0; tar ≥7.5.19).
High (128, grouped by package)
High findings by package
| Package |
Version |
CVE/GHSA IDs |
| node |
22.18.0 |
CVE-2025-55131, CVE-2025-59465, CVE-2025-59466, CVE-2026-21637, CVE-2026-21710, CVE-2026-56846, CVE-2026-56848, CVE-2026-58043 (fix: 20.20.2, 22.23.2, 24.18.1, 26.5.1) |
| python |
3.11.15 |
CVE-2026-7210, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-6100, CVE-2026-4224, CVE-2026-3644, CVE-2026-9669, CVE-2026-3298, CVE-2026-4786 (fix: 3.13.x/3.14.x/3.15.0 latest) |
| openssh-client, openssh-server, openssh-sftp-server, ssh |
1:10.0p1-7+deb13u4 |
CVE-2026-58050, CVE-2026-58051, CVE-2026-59999, CVE-2026-60000, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 (via libssh2-1t64/libc dependents) |
| curl, libcurl3t64-gnutls, libcurl4t64 |
8.14.1-2+deb13u4 |
CVE-2026-12064, CVE-2026-8286, CVE-2026-8932, CVE-2026-9080, CVE-2026-9545 |
| libc6, libc-bin, libc-dev-bin, libc6-dev |
2.41-12+deb13u3 |
CVE-2026-12064, CVE-2026-5435, CVE-2026-5928, CVE-2026-8286, CVE-2026-8932, CVE-2026-9080, CVE-2026-9545 |
| perl, libperl5.40, perl-base, perl-modules-5.40 |
5.40.1-6 |
CVE-2026-42497, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432, CVE-2026-7017, CVE-2026-9538 |
| tar |
6.2.1, 7.4.3 |
GHSA-34x7-hfp2-rc4v, GHSA-83g3-92jg-28cx, GHSA-8qq5-rm4j-mr97, GHSA-8x88-c5mf-7j5w, GHSA-9ppj-qmqm-q256, GHSA-qffp-2rhf-9h96, GHSA-r6q2-hw4h-h46w (fix ≥7.5.7) |
| minimatch (JS) |
9.0.5 |
GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74 (fix 9.0.7) |
| brace-expansion (JS) |
2.0.2 |
GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, GHSA-3jxr-9vmj-r5cp (fix 2.1.4) |
| wget |
1.25.0-2 |
CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 |
| libncursesw6, libtinfo6, ncurses-base, ncurses-bin |
6.5+20250216-2 |
CVE-2025-69720 |
| libsqlite3-0 |
3.46.1-7+deb13u1 |
CVE-2026-11822, CVE-2026-11824 |
| libacl1 |
2.3.2-2+b1 |
CVE-2026-54369, CVE-2026-54370 |
| glob (JS) |
10.4.5 |
GHSA-5j98-mcp5-4vw2 (fix 10.5.0) |
| jaraco-context (py) |
5.3.0 |
GHSA-58pv-8j8x-9vj2 (fix 6.1.0) |
| picomatch (JS) |
4.0.2 |
GHSA-c2c7-rcm5-vvqj (fix 4.0.4) |
| gzip |
1.13-1 |
CVE-2026-41992 |
| wheel (py) |
0.45.1 |
GHSA-8rrh-rw8j-w5fx (fix 0.46.2) |
| ip-address (JS) |
9.0.5 |
GHSA-mwp4-54f8-5fhr (fix 10.3.1) |
| sigstore (py) |
3.1.0 |
GHSA-52v5-jr5w-gjxr (fix 4.1.1) |
Remediation: same Debian 13 base-image rebuild resolves openssh/curl/glibc/wget/ncurses/sqlite/gzip/acl High findings. Upgrade node to a patched LTS, python to 3.13/3.14 latest, and bump JS deps minimatch→9.0.7, brace-expansion→2.1.4, glob→10.5.0, picomatch→4.0.4, ip-address→10.3.1; Python deps jaraco-context→6.1.0, wheel→0.46.2, sigstore→4.1.1.
Medium (148 unique pairs, 72 distinct CVE/GHSA IDs, grouped by package)
Medium findings by package
| Package |
Version |
CVE/GHSA IDs |
| python |
3.11.15 |
CVE-2025-12781, CVE-2025-13837, CVE-2025-15366, CVE-2025-15367, CVE-2026-0864, CVE-2026-12003, CVE-2026-1502, CVE-2026-2297, CVE-2026-3276, CVE-2026-3446, CVE-2026-4360, CVE-2026-6019, CVE-2026-7774, CVE-2026-8328 |
| tar |
6.2.1/7.4.3 |
CVE-2026-18477, CVE-2026-18508, CVE-2026-5704, GHSA-gvwx-54wh-qm9j, GHSA-r292-9mhp-454m, GHSA-vmf3-w455-68vh, GHSA-w8wr-v893-vjvp |
| node |
22.18.0 |
CVE-2025-55132, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-48937, CVE-2026-56850, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58045 |
| openssh-client/server/sftp-server, ssh |
1:10.0p1-7+deb13u4 |
CVE-2026-55655, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-60001, CVE-2026-73282 |
| pip (py) |
(bundled) |
GHSA-4xh5-x5gv-qwph, GHSA-58qw-9mgm-455v, GHSA-jp4c-xjxw-mgf9, GHSA-wf93-45jw-7689 |
| perl, libperl5.40, perl-base, perl-modules-5.40 |
5.40.1-6 |
CVE-2025-15649, CVE-2026-15534, CVE-2026-19487, CVE-2026-7010 |
| wget |
1.25.0-2 |
CVE-2021-31879, CVE-2026-15146, CVE-2026-58470 |
| bsdutils, util-linux, mount, libblkid1, libmount1, libsmartcols1, libuuid1, liblastlog2-2, login |
2.41-5 |
CVE-2026-13595, CVE-2026-27456, CVE-2026-3184 |
| libncursesw6, libtinfo6, ncurses-base, ncurses-bin |
6.5+20250216-2 |
CVE-2025-6141 |
| libexpat1 |
2.8.2-1~deb13u1 |
CVE-2025-66382, CVE-2026-72522 |
| libp11-kit0 |
0.25.5-3 |
CVE-2026-13757, CVE-2026-18938 |
| libc6, libc-bin, libc-dev-bin, libc6-dev |
2.41-12+deb13u3 |
CVE-2026-6238, CVE-2026-6791 |
| curl, libcurl3t64-gnutls, libcurl4t64 |
8.14.1-2+deb13u4 |
CVE-2026-8458 |
| libpam-modules(-bin), libpam-runtime, libpam0g |
1.7.0-5 |
CVE-2026-54411 |
| libsqlite3-0 |
3.46.1-7+deb13u1 |
CVE-2026-50812, CVE-2026-50813 |
| bzip2, libbz2-1.0 |
1.0.8-6 |
CVE-2026-42250 |
| zlib1g |
1:1.3.dfsg+really1.3.1-1+b1 |
CVE-2026-27171 |
| gzip |
1.13-1 |
CVE-2026-41991 |
| libattr1 |
1:2.5.2-3 |
CVE-2026-54371 |
| libnghttp2-14 |
1.64.0-1.1+deb13u1 |
CVE-2026-58055 |
| picomatch (JS) |
4.0.2 |
GHSA-3v7f-55p6-f55p |
| brace-expansion (JS) |
2.0.2 |
GHSA-f886-m6hf-6m8v |
| setuptools (py) |
79.0.1 |
GHSA-h35f-9h28-mq5c |
| ip-address (JS) |
9.0.5 |
GHSA-v2v4-37r5-5v8g |
Low (35), Negligible (610), Unknown (36)
Low severity (35 findings)
Affected packages: wget, python, node, openssh-*/ssh, libx11-6/libx11-data, libcairo2, libgd3, login/passwd, libncursesw6/libtinfo6/ncurses-*, git/git-man, libtiff6, dirmngr/gnupg/gpg* family, libgcrypt20, coreutils, libjpeg62-turbo, libsystemd0/libudev1. No Low-severity finding has a "no fix available" blocker beyond upstream Debian package timing.
Negligible (610 unique CVE+package pairs)
Dominated by the GNU binutils toolchain: binutils, binutils-common, libbinutils, libctf-nobfd0, libctf0, libgprofng0, libsframe1, binutils-x86-64-linux-gnu (8 packages) each carrying the same ~56 shared upstream CVE IDs (largely unresolved static-analysis findings against binutils' disassembler/linker internals with no active exploitation reported) — accounting for 448 of the 610 pairs.
The remaining 162 pairs are spread across:
openssh-client/openssh-server/openssh-sftp-server/ssh (8 CVEs × 4 packages)
libc6/libc-bin/libc-dev-bin/libc6-dev (7 CVEs × 4 packages)
krb5-family (libgssapi-krb5-2, libkrb5-3, libkrb5support0, libk5crypto3) (4 CVEs × 4 packages)
curl/libcurl3t64-gnutls/libcurl4t64 (5 CVEs × 3 packages)
systemd-family (libsystemd0, libudev1, systemd, systemd-sysv) (4 CVEs × 4 packages)
- ~15 singleton findings across
sudo, git, patch, coreutils, and other Debian base utilities.
None of these Negligible findings currently have exploit evidence; they represent low-priority defense-in-depth backlog rather than actionable urgent risk.
Unknown severity (36 findings)
Findings where Grype could not determine a CVSS-based severity rating, spread across the same Debian base-package set as the Negligible tier (binutils, krb5, systemd, and related toolchain packages awaiting upstream severity scoring).
License violations (661 total)
Genuine rejected/unrecognized licenses (112 packages)
Covers GPL/LGPL/Artistic/MPL/BSD-variant licenses flagged by policy across the Debian toolchain (gcc, binutils, perl, openssh, systemd family packages) plus Python/JS libraries: pathspec, certifi, tqdm, pystray, python-xlib, autocommand, distro, and related dependencies. These are legitimate open-source licenses (largely GPL-2/3, LGPL-2.1, MPL-2.0) that are flagged because they are copyleft/restrictive under the current Grant policy rather than unknown or malformed licenses.
No detectable license metadata (549 packages)
549 additional packages (primarily Rust crates, Python wheels, and Debian packages) report "no licenses found" — i.e. Grant could not extract SPDX/license-file metadata from the package, not necessarily an actual policy violation. Recommend running grant list locally against the image to enumerate the full package list before deciding on suppression vs. investigation.
Next actions
- Rebuild
serena on a refreshed Debian 13 base — this alone resolves the majority of Critical/High findings in curl, glibc, perl, openssh, wget, ncurses, and sqlite3 via standard apt security updates.
- Upgrade the bundled Node.js to a patched LTS (≥20.20.2/22.23.2/24.18.1/26.5.1) to close all node-specific Critical/High/Medium CVEs.
- Upgrade the bundled Python to the latest 3.13.x/3.14.x/3.15.0 patch to close all python-specific High/Medium CVEs.
- Bump
tar to ≥7.5.19 to close the Critical GHSA-23hp-3jrh-7fpw and all other tar CVEs in one step.
- Bump JS deps:
minimatch→9.0.7, brace-expansion→2.1.4, glob→10.5.0, picomatch→4.0.4, ip-address→10.3.1.
- Bump Python deps:
jaraco-context→6.1.0, wheel→0.46.2, sigstore→4.1.1, setuptools→latest.
- This image is rebuilt weekly via the daily
gh aw compile --force-refresh-container-pins job — given the Critical findings here, prioritize an out-of-band pin refresh rather than waiting for the next scheduled run.
- Given the large binutils-family negligible backlog, consider whether the image needs
binutils at all in the runtime layer, or whether it can be moved to a build-only stage to shrink the attack surface.
Generated by 🛡️ Daily Container Image Security Scan · auto · 438.5 AIC · ⌖ 15.1 AIC · ⊞ 7.2K · ◷
Overview
Daily container scan findings for
ghcr.io/oraios/serena:1.7.0(pinnedsha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730), a Debian 13 (trixie)-based image bundling Node, Python, and Perl toolchains. This is the only scanned image with Critical findings.Key metrics
Critical (50, grouped by package)
Critical findings by package
Remediation: Debian 13 security updates for
curl/glibc/perl/opensshare the highest-priority fix — a singleapt-get upgradeon rebuild resolves the bulk of Critical findings.nodeandtarneed explicit version bumps (node ≥20.20.0/22.22.0/24.13.0/25.3.0; tar ≥7.5.19).High (128, grouped by package)
High findings by package
Remediation: same Debian 13 base-image rebuild resolves openssh/curl/glibc/wget/ncurses/sqlite/gzip/acl High findings. Upgrade
nodeto a patched LTS,pythonto 3.13/3.14 latest, and bump JS depsminimatch→9.0.7,brace-expansion→2.1.4,glob→10.5.0,picomatch→4.0.4,ip-address→10.3.1; Python depsjaraco-context→6.1.0,wheel→0.46.2,sigstore→4.1.1.Medium (148 unique pairs, 72 distinct CVE/GHSA IDs, grouped by package)
Medium findings by package
Low (35), Negligible (610), Unknown (36)
Low severity (35 findings)
Affected packages:
wget,python,node,openssh-*/ssh,libx11-6/libx11-data,libcairo2,libgd3,login/passwd,libncursesw6/libtinfo6/ncurses-*,git/git-man,libtiff6,dirmngr/gnupg/gpg*family,libgcrypt20,coreutils,libjpeg62-turbo,libsystemd0/libudev1. No Low-severity finding has a "no fix available" blocker beyond upstream Debian package timing.Negligible (610 unique CVE+package pairs)
Dominated by the GNU binutils toolchain:
binutils,binutils-common,libbinutils,libctf-nobfd0,libctf0,libgprofng0,libsframe1,binutils-x86-64-linux-gnu(8 packages) each carrying the same ~56 shared upstream CVE IDs (largely unresolved static-analysis findings against binutils' disassembler/linker internals with no active exploitation reported) — accounting for 448 of the 610 pairs.The remaining 162 pairs are spread across:
openssh-client/openssh-server/openssh-sftp-server/ssh(8 CVEs × 4 packages)libc6/libc-bin/libc-dev-bin/libc6-dev(7 CVEs × 4 packages)krb5-family (libgssapi-krb5-2,libkrb5-3,libkrb5support0,libk5crypto3) (4 CVEs × 4 packages)curl/libcurl3t64-gnutls/libcurl4t64(5 CVEs × 3 packages)systemd-family (libsystemd0,libudev1,systemd,systemd-sysv) (4 CVEs × 4 packages)sudo,git,patch,coreutils, and other Debian base utilities.None of these Negligible findings currently have exploit evidence; they represent low-priority defense-in-depth backlog rather than actionable urgent risk.
Unknown severity (36 findings)
Findings where Grype could not determine a CVSS-based severity rating, spread across the same Debian base-package set as the Negligible tier (binutils, krb5, systemd, and related toolchain packages awaiting upstream severity scoring).
License violations (661 total)
Genuine rejected/unrecognized licenses (112 packages)
Covers GPL/LGPL/Artistic/MPL/BSD-variant licenses flagged by policy across the Debian toolchain (
gcc,binutils,perl,openssh,systemdfamily packages) plus Python/JS libraries:pathspec,certifi,tqdm,pystray,python-xlib,autocommand,distro, and related dependencies. These are legitimate open-source licenses (largely GPL-2/3, LGPL-2.1, MPL-2.0) that are flagged because they are copyleft/restrictive under the current Grant policy rather than unknown or malformed licenses.No detectable license metadata (549 packages)
549 additional packages (primarily Rust crates, Python wheels, and Debian packages) report "no licenses found" — i.e. Grant could not extract SPDX/license-file metadata from the package, not necessarily an actual policy violation. Recommend running
grant listlocally against the image to enumerate the full package list before deciding on suppression vs. investigation.Next actions
serenaon a refreshed Debian 13 base — this alone resolves the majority of Critical/High findings incurl,glibc,perl,openssh,wget,ncurses, andsqlite3via standardaptsecurity updates.tarto ≥7.5.19 to close the CriticalGHSA-23hp-3jrh-7fpwand all other tar CVEs in one step.minimatch→9.0.7,brace-expansion→2.1.4,glob→10.5.0,picomatch→4.0.4,ip-address→10.3.1.jaraco-context→6.1.0,wheel→0.46.2,sigstore→4.1.1,setuptools→latest.gh aw compile --force-refresh-container-pinsjob — given the Critical findings here, prioritize an out-of-band pin refresh rather than waiting for the next scheduled run.binutilsat all in the runtime layer, or whether it can be moved to a build-only stage to shrink the attack surface.