From 1e8454a3cb7645b5d7bed1e96e0393a44728cf96 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?C=C3=A9sar=20Arroba?= <19954079+cesararroba@users.noreply.github.com> Date: Wed, 9 Sep 2026 17:21:27 +0200 Subject: [PATCH] fix(mcp): patch the six high libuuid CVEs in the container image (#12780) --- mcp_server/Dockerfile | 5 ++++- mcp_server/changelog.d/mcp-image-libuuid-cves.security.md | 1 + 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 mcp_server/changelog.d/mcp-image-libuuid-cves.security.md diff --git a/mcp_server/Dockerfile b/mcp_server/Dockerfile index a2ba13ff6c..7dad9e1303 100644 --- a/mcp_server/Dockerfile +++ b/mcp_server/Dockerfile @@ -32,6 +32,8 @@ LABEL maintainer="https://github.com/prowler-cloud" # High CVEs fixed in Alpine 3.23 but not yet in the pinned base image: # sqlite-libs 3.53.4-r0 CVE-2026-11822, CVE-2026-11824 (image ships 3.51.2-r0) # libcrypto3/libssl3 3.5.8-r0 CVE-2026-14456 (image ships 3.5.7-r0) +# libuuid 2.41.6-r1 CVE-2026-53612, -53613, -53614, -76642, -78408, -78410 +# (image ships 2.41.4-r0; -78408 is the one that needs -r1 rather than -r0) # The base image pins python 3.13.14, which has not been rebuilt since those # packages were published, so the upgrade is taken here rather than by moving # the pin -- the newest published python:3.13-alpine3.23 carries the same @@ -43,7 +45,8 @@ LABEL maintainer="https://github.com/prowler-cloud" RUN apk add --no-cache --upgrade \ "sqlite-libs>=3.53.4-r0" \ "libcrypto3>=3.5.8-r0" \ - "libssl3>=3.5.8-r0" + "libssl3>=3.5.8-r0" \ + "libuuid>=2.41.6-r1" # Create non-root user for security # Using specific UID/GID for consistency across environments diff --git a/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md b/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md new file mode 100644 index 0000000000..602458c777 --- /dev/null +++ b/mcp_server/changelog.d/mcp-image-libuuid-cves.security.md @@ -0,0 +1 @@ +`libuuid` upgraded to 2.41.6-r1 in the container image, patching CVE-2026-53612, CVE-2026-53613, CVE-2026-53614, CVE-2026-76642, CVE-2026-78408 and CVE-2026-78410