chore(trivy): suppress @modelcontextprotocol/sdk CVE-2026-104850 (#12972)

Co-authored-by: StylusFrost <43682773+StylusFrost@users.noreply.github.com>
Co-authored-by: StylusFrost <pm.diaz.pena@gmail.com>
This commit is contained in:
authored and GitHub committed 2026-10-07 13:05:53 +02:00
1 parent 4328d92091
commit 0823f2146a
1 file changed
+7
+7
View File
@@ -77,6 +77,9 @@ vulnerabilities:
# exists in the image, only its purl inside that manifest. The UI lock lists proxy-addr 2.0.7
# through express, but the Next standalone output does not ship it, so the shared entry
# hides nothing real in the UI image either (checked on prowlercloud/prowler-ui:latest).
# @modelcontextprotocol/sdk 1.27.1 (CVE-2026-104850) is another: only its purl is in that
# manifest. The entry is pinned to 1.27.1 because the UI really depends on the SDK (1.26.0
# via @langchain/mcp-adapters), and a version-less purl would hide that finding too.
- id: CVE-2020-0606
purls:
- "pkg:nuget/Microsoft.WindowsDesktop.App.Ref"
@@ -173,6 +176,10 @@ vulnerabilities:
purls:
- "pkg:npm/proxy-addr"
expired_at: 2027-01-31
- id: CVE-2026-104850
purls:
- "pkg:npm/%40modelcontextprotocol%2Fsdk@1.27.1"
expired_at: 2027-01-31
# CVE-2026-84304 is a DoS in grpc-go <= 1.83.0: a peer fragments a gRPC stream into
# millions of tiny HTTP/2 DATA frames until the receiver runs out of heap. Fixed in